You decide
- Whether the evidence meets your obligations
- Whether and how to notify clients
- Whether your firm is compliant
For firms that hold client financial information
Regulation S-P requires SEC-registered firms to protect client information, run a written incident response program, oversee the service providers who touch client data, and notify affected clients after unauthorized access. Compliance: Reg S-P gives you quarterly evidence that those safeguards are in place and working, without you having to ask.

It likely applies if your firm is one of these:
Have a written incident response program
Detection, a response runbook, and regular tests of it
The program, the test records, the incident log
Notify affected clients when sensitive information is exposed
The facts your notification decision needs: what was exposed, when, and whose
A timeline record for every incident
Oversee the service providers who touch client information
An inventory of those providers and a regular review of each
The provider list, with review dates
Safeguard client records and information
Access controls, multi-factor sign-in, encryption and access reviews
Control status and access review records
Keep records showing all of the above
Documentation, kept current
The Compliance Posture Report itself
Scoped to Regulation S-P, delivered every quarter without asking. The proof in your hands is never more than three months old.
Sample · Compliance Posture Report
ACME Corp · Quarter 3 · Reg S-P
Sample report for a fictional business. Example figures.
Bundle discounts available.

One question to ask yourself
In 30 minutes, we talk through your setup and you leave knowing which plan fits.
Book a callSee exactly what you'd receive each quarter, by email.
Get the sample Posture Report by email