Skip to content
Lilly Financial Management Services
Financial management • tax planning • business systems
Who We HelpServicesAboutStart a Conversation
Home / Security and Data Handling

Policy • Information protection

Security and Data Handling Statement

This Statement explains the security principles and verified website controls used to protect information and identifies the channels that must—and must not—be used for sensitive client data.

Effective date: July 20, 2026Last updated: July 20, 2026Version: 1.1

Contents

  1. Purpose and scope
  2. Data channels
  3. Public contact form
  4. Website controls
  5. Security program
  6. Access and use
  7. Service providers
  8. Retention and disposal
  9. Incident response
  10. User responsibilities
  11. Limitations
  12. Security contact
The public contact form is not an approved channel for sensitive information.

Do not submit Social Security numbers, taxpayer-identification numbers, dates of birth, tax returns, financial statements, bank or payment information, credentials, medical information or identity documents through the Site. Lilly Financial will identify an approved delivery method when sensitive information is required for an accepted engagement.

1. Purpose and scope

This Security and Data Handling Statement describes the general security approach of Lilly Financial Management Services, Inc. (“Lilly Financial,” the “Company,” “we,” “us” or “our”) and specific controls associated with lillyfinancial.net. It supplements the Company’s Website and Inquiry Privacy Notice and does not replace an engagement-specific security requirement, client financial-privacy notice, tax-information consent, internal records policy, incident-response procedure or contractual obligation.

This public Statement does not disclose every safeguard, system configuration, vendor arrangement or internal procedure. Security controls may change as threats, technology, services, legal obligations and risk assessments change.

2. Data classifications and approved channels

Lilly Financial distinguishes between preliminary business inquiries and information requiring a protected client-delivery method.

  • Public inquiry information includes a name, business email address and a general description of the requested service. It may be submitted through the public contact form.
  • Sensitive client information includes taxpayer information, government identifiers, identity records, credentials, financial-account data, tax returns, financial statements, payroll records and other confidential business or personal records. It must be transmitted only through a method approved for the applicable engagement.
  • Restricted information includes credentials, authentication factors and information the Company has not requested or is not authorized to receive. It must not be transmitted unless an authorized Company representative provides specific written instructions and a suitable method.

An email address or channel used for ordinary correspondence is not automatically approved for every category of information. Users must follow the delivery instructions provided for the engagement.

3. Public contact-form data

The public form requests a name, email address and message. When a submission is accepted, the Site currently stores those fields together with the submitter’s Internet Protocol address and user-agent string in a Cloudflare D1 database. Technical and security providers may also process browser, device, network, request, token and event information needed to deliver and protect the Site.

The form is intended only to initiate a conversation. It is not a client portal, document repository, tax organizer, payment channel or credential-sharing system. Form submission does not create a professional engagement or cause the Company to assume a deadline or duty to act.

4. Verified public-website controls

The public Site currently uses the following technical measures:

  • Encrypted transport. The Site is delivered over HTTPS. Data transferred between Cloudflare Workers and D1, within the relevant Cloudflare network path, and through applicable Cloudflare APIs is protected using TLS/SSL as described in Cloudflare’s documentation.
  • Encrypted D1 storage. Cloudflare states that D1 objects, including metadata and database contents, are encrypted at rest using AES-256, with encryption keys managed by Cloudflare.
  • Bot and abuse detection. Cloudflare Turnstile evaluates technical and browser signals, issues a verification token and requires server-side validation before the contact workflow accepts a submission.
  • Limited public-form fields. The form asks only for the information needed to evaluate and respond to a preliminary inquiry and displays a warning against submitting sensitive records.

Additional technical information is available in Cloudflare’s D1 data-security documentation, Turnstile documentation and Turnstile Privacy Addendum. Those third-party documents are maintained by Cloudflare and may change independently of this Statement.

5. Security-program principles

Applicable requirements for covered tax-preparation firms include maintaining a written information-security program appropriate to the firm’s size, complexity, activities, information sensitivity and reasonably foreseeable risks. Such a program addresses assigned responsibility, risk assessment, workforce practices, access controls, authentication, service-provider oversight, secure configuration, backup and recovery, incident response, retention and secure disposal as applicable to the firm’s actual systems.

This public Statement is not Lilly Financial’s written information-security program, risk assessment, incident-response plan or vendor inventory and cannot be used to evaluate the design or operating effectiveness of internal controls. Relevant primary guidance includes the FTC Safeguards Rule, the FTC’s Safeguards Rule guidance and the IRS’s Protect Your Clients; Protect Yourself resources. Reference to a requirement, framework or publication does not constitute an independent certification, audit opinion or representation of complete conformity.

6. Access, use and confidentiality

Information should be accessed and used only by persons with a legitimate business or professional need and only for authorized purposes. Access may be restricted according to role, system capability, engagement responsibility and legal or contractual requirements. Individuals with access are expected to protect authentication information, use approved systems and report suspected loss, misuse or unauthorized access.

Tax-return information and other protected client information may be subject to additional use, disclosure and consent requirements. The Company does not treat this public Statement as a substitute for a consent required under Internal Revenue Code section 7216, related Treasury Regulations or another applicable law.

7. Service providers and external systems

Lilly Financial may use providers for hosting, database, bot detection, email, productivity, scheduling, records management, communications, backup, security and technical support. Providers may process information on the Company’s behalf subject to applicable contractual, confidentiality, security and legal requirements.

Provider selection and oversight are to be risk-based and appropriate to the information and function involved, including contractual and legal requirements that apply to covered information. No provider or external system is represented to be free from all vulnerabilities, outages, human error or unauthorized activity. A provider’s own terms, security documentation and privacy notice may also apply.

8. Retention, backup and disposal

Information is retained only for as long as reasonably necessary for the applicable business, professional, legal, tax, insurance, security, dispute-resolution or records-management purpose. Retention periods differ according to information type, engagement status, legal obligation, limitation period and operational need.

When information is no longer required, it may be deleted, destroyed, anonymized or placed in a restricted archive, subject to lawful preservation requirements and technically necessary backup cycles. Deletion from an active system may not immediately remove every residual copy from encrypted backups or provider systems.

9. Security-event assessment and response

The Company’s incident-response requirements call for suspected security events to be identified, assessed, contained, investigated and addressed according to the facts. Actions may include preserving evidence, restricting access, consulting technical or legal professionals, coordinating with providers, restoring operations, improving safeguards and making notifications required by applicable law.

A report of suspicious activity does not establish that a security incident or legally reportable breach occurred. The Company determines notification duties based on the facts, affected information, applicable law and advice of qualified professionals.

10. Client and user responsibilities

Security is a shared responsibility. Site users, prospective clients and clients should:

  • use only the delivery method approved for the information involved;
  • verify unusual requests for money, credentials, account changes or sensitive records through a known independent contact method;
  • protect passwords, authentication factors, devices and email accounts;
  • avoid sending sensitive information through public forms, ordinary text messages or unapproved email;
  • keep contact information current and promptly report suspected compromise, misdirected information or unauthorized access; and
  • comply with legal, contractual and organizational authority requirements before providing information about another person or entity.

11. Limitations; no security certification or guarantee

No administrative, technical or physical safeguard can eliminate every risk. Lilly Financial does not guarantee that a transmission, system, database, device, provider or security program will be completely secure, uninterrupted or error-free.

This Statement is not a service-level agreement, warranty, SOC report, penetration-test report, compliance certification, audit opinion or representation that the Company satisfies a particular security framework unless a separate current document expressly states otherwise. Detailed security information may be withheld when disclosure could increase risk or violate an obligation.

12. Reporting a suspected security issue

A person who believes Company information was sent to the wrong recipient, credentials may have been exposed, an account or communication may have been impersonated, or the Site may present a security concern should contact Lilly Financial promptly. Do not include passwords, authentication codes, full government identifiers or complete sensitive records in the initial report.

This contact method does not authorize security testing, vulnerability scanning, access attempts, disruption, social engineering or acquisition of another person’s information. Testing requires prior written authorization defining its scope.

Lilly Financial Management Services, Inc.
Email: hello@lillyfinancial.net
Subject line: Security Report
Lilly Financial
Management Services, Inc.

Financial management, tax preparation and planning, and practical business systems for owner-led companies.

hello@lillyfinancial.net

Industries

  • Real Estate
  • Construction & Trades
  • Technical Businesses

Company

  • Services
  • Process
  • About
  • Contact

Policies & Trust

  • Professional Scope
  • Website Privacy
  • Terms of Use
  • Accessibility
  • Security & Data Handling

© Lilly Financial Management Services, Inc. All rights reserved.

HomeBack to top