LUNA LUX FINANCIAL

Written Information Security Plan (WISP) — IRS Publication 5708 Compliant

Business Name: Luna Lux Financial

Location: Baton Rouge, Louisiana

Effective Date: September 2026

Next Annual Review: September 2027

Designated Security Coordinator (DSC): Keyauna Hart

DSC Contact: [email protected]

1. Purpose

Luna Lux Financial (“the Firm”) maintains this Written Information Security Plan (“WISP”) in compliance with IRS Publication 5708, the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314), and applicable IRS Publication 4557 requirements. This plan establishes administrative, physical, and technical safeguards to protect the confidentiality, integrity, and security of client taxpayer data.

2. Scope

This WISP applies to all employees, contractors, and third-party service providers who access, store, transmit, or process taxpayer data on behalf of Luna Lux Financial.

3. Designated Security Coordinator

The Designated Security Coordinator (DSC) is responsible for developing, implementing, training staff on, and maintaining this WISP.

DSC: Keyauna Hart  |  Email: [email protected]

4. Data and Systems Inventory

Types of Sensitive Data Maintained

  • Taxpayer names, dates of birth, addresses, Social Security Numbers (SSNs) and Individual Taxpayer Identification Numbers (ITINs)
  • Income source documents (W-2s, 1099s, K-1s, and related federal/state schedules)
  • Bank account and routing numbers (direct deposit information)
  • Prior-year federal and state tax returns
  • Business financial records and entity documentation
  • Electronic signature data and intake form submissions

Where Data is Stored

  • Cloud-based CRM platform (encrypted at rest, access-controlled)
  • IRS-authorized professional tax preparation software
  • Encrypted secure client intake portal (HTTPS)
  • Encrypted business email (data in transit)

5. Physical Security

  • All workstations accessing taxpayer data are password-protected and set to auto-lock after inactivity
  • Paper documents containing taxpayer information are stored in a locked area and cross-shredded when no longer needed
  • Physical access to workstations is limited to authorized personnel
  • Portable storage devices containing taxpayer data are encrypted

6. Electronic Security and Cybersecurity

  • Passwords: All accounts require strong passwords (minimum 12 characters, mixed case, numbers, special characters). Passwords are changed at least annually.
  • Multi-Factor Authentication (MFA): Required on all email, CRM, and tax software accounts.
  • Encryption: All data transmitted uses TLS/SSL encryption. Data at rest is stored on encrypted systems.
  • Antivirus / Anti-Malware: Up-to-date security software is installed and active on all preparation devices.
  • Firewall: Active firewall protection on all devices and network connections used for tax work.
  • Software Updates: Operating systems and tax software are kept current with security patches.
  • Data Backups: Client data is backed up regularly to an encrypted, cloud-based system.
  • Email Security: Taxpayer data is never transmitted via unencrypted email, text, or social media.

7. Employee and Contractor Procedures

  • All staff and contractors receive security awareness training before accessing taxpayer data
  • Data access is granted on a need-to-know basis only
  • Upon termination or role change, access credentials are revoked immediately
  • Staff are prohibited from accessing taxpayer data over public or unsecured Wi-Fi without a VPN
  • Staff are trained to identify phishing attempts and are instructed not to click suspicious links or open unexpected attachments

8. Third-Party Service Providers

Luna Lux Financial uses vetted third-party providers to support business operations. Providers with access to taxpayer data are required to maintain their own data security programs consistent with industry standards. Current provider categories include:

  • Cloud-based CRM and client communication platform
  • IRS-authorized tax preparation software
  • Encrypted business email provider
  • Electronic signature and document management provider

9. Incident Response Plan

In the event of a known or suspected data breach, the following steps will be taken:

  1. Contain: Immediately isolate affected systems from the network to prevent further exposure.
  2. Assess: Determine the scope — what data was accessed, by whom, and for how long.
  3. Notify: Report to the IRS via the Stakeholder Liaison or e-Services Help Desk. Notify affected clients and applicable state authorities as required by law.
  4. Remediate: Change all affected passwords, revoke unauthorized access, restore clean backups where necessary.
  5. Review: Conduct a post-incident review and update this WISP as needed.

IRS Identity Theft: www.irs.gov/identity-theft-central  |  FTC: reportfraud.ftc.gov

10. Client Responsibilities

  • Use only the secure intake portal or client portal to submit sensitive tax documents
  • Never send SSNs, bank account numbers, or tax documents via unencrypted email, text, or social media
  • Notify Luna Lux Financial immediately if you suspect your personal information or login credentials have been compromised

11. Annual Review and Updates

This WISP is reviewed and updated at least annually, or whenever a material change in business operations or a security incident occurs. The Designated Security Coordinator is responsible for ensuring the plan remains current, complete, and compliant. This plan was last reviewed in September 2026 and is next scheduled for review in September 2027.

© 2026 Luna Lux Financial. All Rights Reserved.  |  The Standard Is Excellence.
Return to Christina Minter’s Page