API and MCP

Build your WISP with an AI assistant

Connect Claude to DomainGuard and it interviews you, then hands you a finished written information security plan as a Word document.

Updated · 2 min read

The FTC Safeguards Rule requires tax preparers, accountants, bookkeepers and other firms that handle people's financial information to keep a written information security plan (a WISP). The IRS asks tax professionals for one too (Publications 4557 and 5708). Over MCP, writing it is a conversation.

How it works

  1. Ask your assistant for a WISP, or run /mcp__domainguard__build_wisp in Claude Code.
  2. It asks you about the firm in plain questions, a couple at a time: where the office is, whether you prepare returns, who is in charge of security, your devices, the software you use, how you back up, and who to call after a breach. Where DomainGuard already knows something (your e-mail, your name), it asks you to confirm rather than asking cold.
  3. When every required question is answered, it builds the plan and gives you a download link. The link works for seven days without signing in; ask for a fresh one any time.

You can stop and pick up later. The assistant calls list_wisps and continues where you left off.

What is in the plan

A Word document you can edit and sign: scope and legal basis, who is responsible, a risk assessment with a risk register, an inventory of your devices and software, the safeguards you follow, a controls checklist, training, how you oversee vendors, an incident response and breach notification plan with your state's rules and the right IRS contact, annual review, a signature page, and seven attachments (retention schedule, rules of behavior, a one-page breach checklist, staff acknowledgement, hardware and access roster, an AI consent log, and the annual review checklist).

Anything you told us is missing (no backup, no MFA on some systems, no VPN for remote work) is listed in Section 6.6, Open Items, with the fix and a due date. The plan records where you are; it does not pretend.

What you need

A DomainGuard API key with the compliance scope. Starting and answering a plan saves data, so it needs a key with write (Enterprise). A read-only key can list plans and fetch download links. See Connecting the MCP server.

The plan is built from your answers. It is not legal advice; have your attorney review it if you want a legal opinion.

Still stuck?

Ask the people who run the scanner.

Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.