IT Services for CPA Firms in San Antonio

San Antonio CPA firms, tax practices, and bookkeeping offices with one to three CPAs and support staff

IT Services for CPA Firms in San Antonio

A CPA firm has two seasons: the one where the systems have to work, and the one where you fix what broke. ASAP Computer Services provides managed IT support for San Antonio CPA firms and tax practices that keeps tax software, QuickBooks, and client portals running from January through the October deadline, and that meets the security obligations the FTC Safeguards Rule and the IRS now put on every tax professional, including the written information security plan. Small accounting practices were among the first clients we ever supported, and we have run tax seasons alongside them since 1999.

  • Tax season uptime: a change freeze from January through April, verified nightly backups, and a help desk that answers on April 14
  • Tax and accounting software support for Lacerte, ProSeries, Drake, and QuickBooks, with direct vendor coordination with Intuit
  • FTC Safeguards Rule controls: MFA, encryption, access controls, logging, and the technical sections of your WISP
  • Breach readiness with a documented incident response plan and 4-hour incident notification in your agreement
Local San Antonio team since 1999
Safeguards Rule service provider agreements signed
Published per-user pricing

What a small CPA firm needs from its technology

A firm with one to three CPAs and a handful of staff does not have an IT department, and during filing season it does not have time to become one. What it needs is simple to describe and hard to keep consistent: workstations that open a return without a spinning cursor, a tax server or hosted environment that does not go down the week before a deadline, a client portal that clients can actually use, e-file that works, and backups that would survive a ransomware attack in March.

The failures we see are predictable. A Windows update installs mid-season and breaks the tax software’s printing. The QuickBooks file server fills up. The one person who knows the portal login leaves. A phishing email arrives dressed as an IRS notice, and a preparer clicks it. A practical support plan closes those gaps before January and holds them closed through October.

Tax, accounting, and client software we support

Whether your firm runs Lacerte or ProSeries from Intuit Professional, Drake, or another tax platform, plus QuickBooks Desktop or Online for bookkeeping clients, we support the workstations, servers, and network the software depends on, and we act as the technical point of contact with the vendor when a database, license, update, or printing problem needs solving. The same goes for client portals and secure file exchange such as SmartVault and ShareFile, e-signature, document management, payroll platforms, and the scanners that intake runs on.

On the client accounting side, we support QuickBooks Desktop and Enterprise (which needs careful server hosting for multi-user files), QuickBooks Online, and Xero, along with secure drive mapping and cloud folders so staff can reach client files safely from anywhere. Many firms also keep the books directly on a client’s own machine. For those, we set up secure remote access using Tailscale, so a CPA can open the client’s QuickBooks from the firm’s office without a VPN appliance at the client site and without exposing anything to the internet.

One test of an IT company’s accounting expertise is what happens at 4 PM on April 12 when a multi-user QuickBooks file locks up or reports a corrupted database and nobody can open it. We are well versed in QuickBooks multi-user environments, and we do not expect our clients to sit on hold with QuickBooks support, especially during tax season. Our help desk works those problems directly and brings in the vendor only when a case actually needs it.

Firms that need a server for tax software or multi-user QuickBooks Desktop or Enterprise have two good options: a properly sized server in your office, or a hosted server in ASAP’s own San Antonio rack with remote access from home during the season and no vendor hosting fee per user. Either way, the tax data is encrypted, backed up nightly, and restorable, and the environment is documented so a vendor call takes minutes instead of an afternoon.

What we manage for CPA firms

  • Help desk for the login, printing, software, and email problems that stall returns
  • Workstations and laptops sized for tax software, with full-disk encryption
  • Tax and QuickBooks servers, on site or hosted in our rack
  • Secure remote access to clients’ QuickBooks machines with Tailscale
  • Network monitoring, firewalls, switching, and WiFi
  • Microsoft 365, secure email, and identity with MFA
  • Unique user accounts, role-based permissions, and same-day deactivation for seasonal staff
  • A tax season change freeze, with updates tested and scheduled around deadlines
  • Encrypted, verified nightly backups with tested restores
  • Endpoint detection and response, email filtering, and 12-month security log retention
  • Vendor coordination for tax software, QuickBooks, portals, payroll, internet, and phones

Seasonal preparers get their own accounts in January and lose them in May. No shared “Tax1” login, and nothing left active over the summer.

How we protect filing season

From the first week of January through the April deadline, and again ahead of the September and October extension deadlines, we run a change freeze: no operating system updates, software upgrades, or network changes unless a vendor requires one, and then only tested and scheduled after hours. Backups are verified nightly, and we test a restore before the season starts, not during it.

When something breaks, managed plan clients in San Antonio proper get a 1-hour on-site response guarantee for emergencies during plan coverage hours, 7:30 AM to 7:30 PM, Monday through Friday. Remote tickets usually get a first response in minutes, and a live person answers the phone. Extended-hours coverage for the final week before a deadline can be arranged in advance.

Every managed plan includes a quarterly technology review, which for a CPA firm usually lands in the off season, where it belongs.

Request the CPA firm technology review

Local team. Clear next steps. Fast response.

The FTC Safeguards Rule, IRS Publication 4557, and your WISP

Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are financial institutions regardless of size, and the rule requires each firm to maintain a written information security plan. The IRS says it plainly in Publication 4557 and provides a WISP template in Publication 5708, and every PTIN renewal now includes an attestation that the preparer understands those obligations. A firm that has never written its WISP is out of compliance before it prepares a single return.

The firm’s designated qualified individual owns the plan. We build and document the technical safeguards it describes, and we supply the system inventory, risk assessment evidence, and control descriptions so the technical sections are accurate instead of aspirational.

  • The IRS Security Six, done: monitored endpoint protection, a managed firewall, MFA on email, remote access, and tax software, encrypted nightly backups, full-disk encryption on every workstation and laptop, and a VPN or hosted desktop for working from home during the season.
  • Access controls: unique user IDs for every preparer and staff member, role-based permissions, and access removed the day a seasonal employee leaves.
  • Monitoring and logging: security logs retained for 12 months, so the firm can show who accessed what if a question ever comes up.
  • Service provider oversight: the Safeguards Rule requires firms to hold their vendors to the same standards. We sign a service provider agreement committing to those safeguards before we begin work, and our technicians use named accounts with MFA.
  • Incident response: a documented plan to isolate affected systems, preserve evidence, restore from verified backups, and give the firm what it needs to report data theft to the IRS and, for incidents affecting 500 or more people, to notify the FTC within the required 30 days. Incident notification to the firm within 4 hours is written into our agreement.
  • Staff training: security awareness training for preparers and staff, because a fake IRS notice in January is still the most common way a tax firm gets breached.

For the full breakdown of Zero Trust controls and our 24/7 SOC as a Service coverage, see our computer security and cybersecurity page.

The Texas cybersecurity safe harbor (Senate Bill 2610)

Since September 1, 2025, Texas businesses with fewer than 250 employees that implement and maintain a documented cybersecurity program are shielded from exemplary damages in lawsuits following a data breach. A CPA firm holds exactly the sensitive personal information the statute covers: Social Security numbers, bank and account numbers, and financial records for every client. For a firm under 20 employees, the statute asks for password policies and staff training; for 20 to 99, a program aligned with CIS Controls Implementation Group 1. The safeguards your WISP already requires get you most of the way there, and we document them so the firm can show what was in place on the day it mattered. Whether the program satisfies the statute in a given case is a question for the firm’s own counsel.

Common CPA firm technology issues we fix

  • Tax software that stops printing or crashes after a Windows update in March
  • QuickBooks multi-user locks and database problems that stop everyone from opening the file
  • A QuickBooks or tax server that is slow, full, or unbacked up
  • Client portal and secure email problems that send clients back to attachments
  • Shared logins and seasonal accounts that never get turned off
  • Phishing emails posing as the IRS, a client, or a software vendor
  • Backups that run but have never been restored
  • Remote access for working from home that is either blocked or wide open
  • A WISP that exists on paper but does not match the systems actually in use
  • Vendor escalation where the firm becomes the middleman

Most of these come down to fundamentals done consistently, then left alone during the season.

Pricing for a firm of 4 to 20 users

A firm with one to three CPAs and support staff usually has 4 to 10 users. Practices of up to seven users start on a flat-rate plan at $500 per month, and larger firms are priced per user, with $85 per user per month as a typical figure, on an annual agreement. The Safeguards Rule controls above are included, not sold as add-ons. Full detail is on our managed IT services cost page. Firms with someone who handles the small stuff can use our co-managed IT option. Our Microsoft 365 management service covers email, identity, and retention. Moving offices? Our turnkey office IT build-out covers cabling, network, workstations, and phones, scheduled for the off season.

How an engagement typically starts

  1. Initial intake to confirm CPAs, staff, tax and accounting software, portals, and the issues that cost the most time last season.
  2. Technology and Safeguards review covering workstations, servers, access setup, encryption, backups, and the gaps between your WISP and your actual systems.
  3. Service plan with priorities, off-season fixes, and options for ongoing management before January.

If you already have an office manager who handles small tasks, we work alongside them. If you do not, we provide a structured support process so staff know who to call and the partners can see what is being improved.

Questions CPA firms often ask

Do we really need a written information security plan?

Yes. Under the FTC Safeguards Rule, tax and accounting professionals are financial institutions regardless of size and must maintain a written information security plan. IRS Publication 4557 states the requirement and Publication 5708 provides a template. We build and document the technical safeguards the plan describes for San Antonio CPA firms.

Can you write our WISP for us?

The firm’s designated qualified individual owns the plan, but we supply the system inventory, risk assessment evidence, and technical control descriptions so the plan matches the systems you actually run, and we keep the technical sections current as your environment changes.

Do you support our tax software?

Yes. We support the workstations, servers, and network for Lacerte, ProSeries, Drake, and QuickBooks Desktop and Online, and we act as the technical point of contact with Intuit or the vendor when a database, license, update, or printing problem needs solving.

Can your help desk handle QuickBooks multi-user problems without sending us to vendor support?

Yes. We are well versed in QuickBooks multi-user environments, including file locks and database problems, and we do not expect our clients to sit on hold with QuickBooks support, especially during tax season. Our help desk works those issues directly and involves the vendor only when a case actually needs it.

Will you make changes during tax season?

No. From January through the April deadline, and ahead of the extension deadlines, we run a change freeze. Updates happen only when a vendor requires them, tested and scheduled after hours.

Can our CPAs access clients’ QuickBooks files remotely?

Yes. For clients who keep QuickBooks on their own machine, we set up secure remote access with Tailscale so your CPA can work in the client’s file from the firm’s office. Nothing is exposed to the internet and no VPN appliance is needed at the client site.

Can you host our tax or QuickBooks server?

Yes. We can run a hosted server in ASAP’s own San Antonio rack with secure remote access, or size and manage a server in your office. Either way the data is encrypted, backed up nightly, and restorable.

What happens if our firm is hit with ransomware in March?

We follow a documented incident response plan: isolate affected systems, preserve evidence, restore from verified backups, and give the firm what it needs to report data theft to the IRS and, where required, notify the FTC. Incident notification to you within 4 hours is written into our agreement.

Do you provide on site service in San Antonio?

Yes. Many issues are handled remotely, but when hardware, cabling, or on site testing is needed, we respond locally. Managed plan clients in San Antonio proper have a 1-hour on-site response guarantee for emergencies during plan coverage hours.

What does IT support for a small CPA firm cost?

Firms of up to seven users start at $500 per month flat on an annual managed plan, and larger firms run about $85 per user per month, with security controls, backups, and the help desk included rather than sold as add-ons.

Ready for a tax season without technology surprises?

If you want a clear picture of what would break in March and where your WISP and your actual systems disagree, request the CPA firm technology and Safeguards review. We will confirm the basics, identify priority fixes, and get them done before January.  Privacy policy.

Call Now