Skip to main content

For accountants, bookkeepers & tax advisers

Evidence for the engagement letter, the PI renewal form, and the client questionnaire.

Vantyris scans what your firm shows the internet (email authentication, client-portal exposure, WordPress hardening, privacy compliance) and returns a plain-English report in three PDF layouts, including a compliance pack sized for your insurer or auditor. From $10€10£10A$15¥1,500AED 40. No contracts.

67Security score,
grade C
2Fixes for
today

Each panel mirrors a screen in your workspace, shown with our demo clinic. After your first scan, it's your sites and your findings.

The reality

What accounting partners worry about

Your engagement letter mentions security in vague terms, because nobody actually checks.

A larger client added a 'cyber hygiene scan in the past 12 months' line to their supplier questionnaire and you have no evidence to send.

Your PI renewal form added cyber questions this year. You've answered them, but you can't prove the answers.

It's tax season and a peer firm has just been phished. You can't say for sure the same route is closed on yours.

What a typical accountant scan surfaces

One finding, shown in plain English.

Every finding in your Vantyris report is shaped the same way: what it means for your business, how to fix it, who to ask, and the technical evidence one tap below.

medium

Some of your outgoing emails are silently landing in client spam folders

Your SPF record goes over the ten-lookup limit in RFC 7208. Receiving servers return a PermError and treat all your authenticated mail as failed, even from senders you've authorised. In practice, email from your firm to Gmail or Outlook users can go to spam with no bounce. The client never sees it, and you never learn it didn't arrive.

How to fix it

Flatten the SPF record by inlining one or two of the most expensive includes. The report names the exact change and the tools that automate it (autoSPF, Dmarcly's SPF flattener). About an hour. To re-test, send to a Gmail account and look for dkim=pass spf=pass dmarc=pass under 'Show original'.

What Vantyris gives accountants

What changes after the first scan.

Three PDF layouts, one of them a compliance pack

The same scan downloads as the full report, which opens with a one-page executive summary for the partners; a single-issue work order for your IT contractor; or a compliance pack for an auditor or insurer with the Cyber Essentials A1-A5 grid up front. All three carry a footer with the scan ID, the date and the methodology version, which is the detail a professional indemnity insurer looks for.

An executive summary the partner can read

Every verified report opens with a one-page summary for non-technical readers: the headline grade, the three biggest wins, the projected score after fixes, and a table mapping each finding to its business risk in plain English. The partner reads page two. The IT contractor starts at page seven.

A Fix Roadmap to hand to the IT contractor

Every finding lands in Today, This Week or Later, grouped by owner (web host, developer, DNS admin, email provider). The contractor opens the work-order PDF and sees one list. The partner sees the plan. Items that need a check rather than a fix go in an Acknowledged bucket, so the urgent list stays short.

Send a link, not a PDF

A time-limited share link lets your auditor or insurer open the report in their browser. Add a watermark with their name and the date if you like, and revoke the link whenever you want. You can see the view count, which helps when a partner asks whether the insurer opened it.

A public trust page for the firm

Switch on /trust/your-firm. It shows your current grade and the controls Vantyris has verified. Put the address in your engagement letter, your PI renewal form or a supplier questionnaire. The insurer or client checks it themselves, and nobody waits for last year's PDF.

Pay per scan, no annual seat licence

The 15-scan pack is a year's baseline for one firm, plus re-scans after the fixes. No subscription and no contract. Top up when you run low.

Long read

15-minute read

The 12 cyber questions on your PI renewal, decoded.

A plain-English playbook for accountants from the Vantyris editorial team. It takes positions, which a generic checklist won't.

Read the full playbook

FAQ for accountants

Common questions from accounting firms

Does this count for Cyber Essentials certification?
Vantyris isn't a certifying body. Every verified report has a Cyber Essentials A1-A5 section (the UK government's baseline scheme) mapping each finding to its five control areas. You can see which CE questions an external scan answers and which need internal evidence, such as endpoint posture, user access control and patching cadence. It gives you the starting checklist for a CE submission. The certificate itself comes from an assessor.
Will my client see anything?
No. Vantyris scans what your firm exposes to the internet: DNS records, response headers, reachable paths. It can't see your clients' data unless your firm has put it on the public internet, and that would be a finding you'd want to hear about straight away.
Can I scan a client's site on their behalf?
Yes, with their written authorisation. The client puts the verification token (DNS TXT, file, or meta tag) in place. That's the documented authorisation computer-misuse laws expect, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act. Email us for a template authorisation letter if you want a paper trail before they configure verification.
What if our IT contractor disagrees with a finding?
Every finding shows its technical evidence (raw header values, observed DNS records) and has a workflow status. If the contractor has a good reason, say 'a WAF rule blocks this path after three attempts', set the finding to 'Accepted as known risk' and write the reason down. The history records who decided what, when and why.
What about findings the scanner can't fully verify from outside?
Some findings, like a reachable login page or missing server-side rate limiting, sit at the edge of what a passive external scan can prove. Vantyris marks these Medium confidence and adds a caveats line to the evidence pack: it can confirm what's visible from outside, not that the controls behind it are missing. If you already have those controls, accept the finding and write down why.
Can my PI insurer just check our posture themselves?
Yes. Switch on a public trust page at /trust/your-firm showing your current grade and the controls Vantyris has verified, and put the address on the renewal form. It's a live view. Every re-scan updates it, so nobody works from a year-old PDF.
Full FAQ

Ready when you are.

Free account, free passive teaser, no card. A verified scan from $10€10£10A$15¥1,500AED 40. No contracts.