Bookings[email protected] (956) 466-4299 San Antonio · Texas
FTC Safeguards Rule · Compliance

A federal rule requires it.
Most businesses aren't ready.

If you're an auto dealer, tax preparer, accountant, insurance agency or mortgage broker, federal law requires you to have a written information-security program. The fines reach about $53,000 per violation — and most owners haven't set it up. We handle the whole thing for a flat monthly fee.

Who must comply

You're probably covered — and may not know it.

The FTC Safeguards Rule covers ordinary local businesses that handle customers' financial information, not just banks.

Auto dealers

Any dealer that arranges financing or leasing — franchise, independent, and buy-here-pay-here.

Tax preparers

Covered by the Rule, and the IRS separately requires a written security plan (Pub 4557).

Accountants & CPAs

Firms that prepare taxes or hold client financial data.

Insurance agencies

Agencies and brokers handling customers' financial information.

Mortgage & lenders

Mortgage brokers, lenders and consumer-finance companies.

Finance companies

Payday, title and other businesses extending credit to consumers.

What the rule requires

Eight things you need in place.

In plain English, the program the FTC expects you to have and maintain.

  • A written security program, kept current
  • A named person responsible (a “Qualified Individual”)
  • A risk assessment of where customer data lives
  • Multi-factor sign-in and encryption
  • Access limited to who needs it, vendors overseen
  • A written breach-response plan
  • Staff security-awareness training
  • Secure disposal of old records
How we help

Compliant in three steps.

We do the work and stay on as your named security lead, so you don't have to become a security expert.

I

Free readiness check

A short questionnaire and a look at your public setup — a plain two-page summary of where you stand and what's missing. No obligation.

II

We build your program

We write the security program, name your Qualified Individual, turn on MFA and encryption, run the risk assessment and set up the breach plan.

III

We keep you covered

We stay on as your named security lead: monthly check-ins, the annual review, and we keep the evidence — so you're ready when someone asks.

Pricing

One setup, then a flat monthly fee.

Start here

Readiness check

Free· a 2-page “where you stand” summary
  • See exactly what's required
  • See what you're missing
  • A clear quote for the rest
  • No obligation
Get compliant & stay compliant

Program + monthly

$1,500–$7,000setup · then $1,200–$4,000/mo
  • We build your full written program
  • We're your named Qualified Individual
  • MFA, encryption, risk assessment, breach plan
  • Monthly check-ins and the annual review
Talk to us Priced by your size after the readiness check
Questions

Straight answers.

Does this really apply to a small business like mine?

Yes. The Rule has no size exemption for being covered — a one-person tax office or a small used-car lot is a “financial institution” under it. Firms with fewer than 5,000 records get a lighter version, but still need the written program, a named lead, MFA and encryption.

What are the penalties, really?

Fines run up to about $53,000 per violation, and the bigger risk for most owners is a data breach or a lawsuit where not having the program is the thing that sinks you. A breach of 500+ consumers' unencrypted data must be reported to the FTC within 30 days.

How much does it cost?

A one-time setup to build the program (typically $1,500–$7,000 by size), then a flat monthly fee to keep you compliant and be your named security lead — usually $1,200–$4,000/month. We quote you exactly after the free readiness check.

We already have an IT person.

Great — most IT handles the computers. The Safeguards program is a specific set of written documents and controls the FTC asks for. We check in minutes whether that paperwork exists; if it does, you're set.

Find out if you're compliant — free.

A two-page readiness check, no obligation. Then we make the problem go away.

Golden Rock builds and maintains your security program to the requirements of the FTC Safeguards Rule (16 CFR Part 314). This is a compliance and security service, not legal advice, and does not guarantee against enforcement or a breach.