Now accepting new Rhode Island clients for the coming quarter. Book a free consultation
Data security

How your financial information is protected

You're being asked to hand over bank statements, revenue figures, and sometimes tax identification numbers. You're entitled to know exactly how they're handled — so here it is in full.

Controls in place

The practical measures, not the marketing version

  • Multi-factor authentication, everywhere Every system that touches client data — email, QuickBooks Online, document storage, the domain registrar — requires a second factor beyond a password. Passwords alone are not a control.
  • Encryption in transit and at rest This website is served only over HTTPS with HTTP Strict Transport Security. Client documents are stored encrypted at rest in Microsoft 365, and email is transmitted over TLS.
  • Least-privilege access I request the minimum access needed to do the work: read-only bank feeds, and accountant-level access to your accounting file. I do not ask for and will not accept your online banking password or signing authority on your accounts.
  • Secure document exchange Sensitive documents move through access-controlled, expiring links — never as an unprotected email attachment, and never through a consumer messaging app.
  • Email authentication The farobookkeeping.com domain publishes SPF, DKIM and DMARC records, which make it substantially harder for someone to send an email that appears to come from Faro. If you receive a suspicious message claiming to be from us, forward it to info@farobookkeeping.com.
  • A written information security program Rhode Island law requires any business that stores personal information about a Rhode Island resident to maintain a risk-based information security program appropriate to its size and the sensitivity of the data (R.I. Gen. Laws § 11-49.3-2). Faro maintains one, reviewed at least annually.
  • Data retention limits Client records are retained for seven years after the engagement ends, matching the outer bound of the IRS record retention guidance, and then securely destroyed. Inquiry messages from people who never become clients are deleted within 24 months.
  • Breach notification If client personal information were ever compromised, affected individuals would be notified in accordance with R.I. Gen. Laws § 11-49.3-4, which requires notice in the most expedient time possible and no later than 45 calendar days after confirming the breach.
This website specifically

Built with almost nothing to attack

Most websites get compromised through a content management system, a database, an outdated plugin, or a login page. This site has none of those. It is a set of static files served from Cloudflare's network — there is no admin panel to break into, no database to inject, and no plugin to go unpatched.

The site loads no third-party scripts, no advertising trackers, no analytics beacons, and no external fonts. Nothing you do here is shared with anyone, because there is no one to share it with.

Security researchers: disclosure details are published at /.well-known/security.txt.

Website hardening

  • HTTPS enforced, with HSTS
  • Strict Content-Security-Policy, no inline scripts
  • Clickjacking blocked (frame-ancestors none)
  • MIME-type sniffing disabled
  • Camera, microphone and geolocation denied by policy
  • Contact form protected by Cloudflare Turnstile, verified server-side
  • Zero third-party trackers or advertising pixels
Regulatory posture

Which rules apply, and where Faro stands

Gramm-Leach-Bliley Act and the FTC Safeguards Rule

The FTC Safeguards Rule (16 C.F.R. Part 314) requires businesses that qualify as "financial institutions" to maintain a documented information security program. Tax return preparers are expressly covered. Whether a pure bookkeeping practice is covered is less settled — Faro operates as though it is, because the controls are the right ones regardless, and because they will unambiguously be required if and when tax services are added.

Rhode Island Identity Theft Protection Act of 2015

This is the rule that applies to Faro today. R.I. Gen. Laws § 11-49.3-2 requires a risk-based information security program, limits how long personal information may be retained, and requires that any third party receiving personal information be bound by written contract to protect it.

Rhode Island Data Transparency and Privacy Protection Act

Effective January 1, 2026, R.I. Gen. Laws § 6-48.1-3 requires any commercial website doing business in Rhode Island to designate a controller. Faro's designated controller is identified in the Privacy Notice. The statute's further disclosure obligations attach to websites that sell personal data. Faro does not sell personal data and never will.

What no website can promise

Any business that tells you its systems cannot be breached is either uninformed or being dishonest with you. Security is a set of controls that reduce risk and limit damage, not a guarantee. What Faro can commit to is this: the controls above are real and in place, they're reviewed at least annually, and if something ever goes wrong you'll hear it from me directly and quickly — not from a press release.

Questions about how your data is handled?

Ask them before you engage me, not after. That's the right time, and I'd rather answer them in detail.

Email us Free consultation