You don't have an FTC Safeguards problem. You have a "prove it" problem.

Almost nobody discovers this rule by reading regulations. It arrives sideways — from an insurer, a client, a peer, or an engagement that suddenly won't move forward.

Knowing the rule exists is rarely the challenge. Completing the work that demonstrates it is.

The rule reaches further than most firms assume

The FTC Safeguards Rule sits under the Gramm-Leach-Bliley Act and applies to many non-bank financial institutions. The FTC's definition of "financial institution" is far broader than what most firms picture — which is why so many find out late.

WHAT KIND OF FIRM ARE YOU?

A practical rule of thumb

If your firm handles customer financial information, the FTC Safeguards Rule probably deserves your attention. Whether it strictly applies is a question for your counsel — but "we assumed it didn't" has not been a useful answer for any firm that later had to explain itself.

What FTC Safeguards actually requires

Most firms expect a policy requirement.

What it actually is:A security program requirement — written down, assigned to someone, and maintained.

1A written information security program
A documented program explaining how customer information is protected. Written, not assumed.
2A qualified individual
A named person responsible for overseeing and implementing the program. Someone owns it.
3Risk assessments
Written assessments identifying threats and evaluating whether your safeguards are adequate.
4Access controls
Limiting who can reach customer information, and reviewing that access periodically.
5Encryption
Protecting customer information in transit and at rest wherever appropriate.
6Multi-factor authentication
MFA on systems holding customer information — the control insurers ask about first.
7Service provider oversight
Reviewing your vendors and confirming they protect customer information adequately.
8Incident response planning
Documenting how your firm responds when something goes wrong, before it does.
9Ongoing reporting
Periodic reporting to management on the state of the program. It has to reach leadership.

Nine requirements, and not one of them is a document you file and forget. Every one has to be maintained, and every one has to be evidenced when an insurer, a client or a regulator asks.

FTC Safeguards is not a project. It's an ongoing program.

Here's a year of it. Every dot is work somebody has to do and evidence — pick a row to see what it involves.

CHECKLIST THINKING
Do it once
Store the document
Hope nobody asks again
PROGRAM THINKING
Assign the work
Complete the work
Collect the evidence
Review it
Repeat

How Greypike runs FTC Safeguards

Every requirement becomes one or more tasks. Instead of remembering what has to happen next quarter or next year, your team receives structured assignments and a documented record of completion.

WHO THIS USUALLY LANDS ON
Managing partnersFirm ownersControllersOperations managersOffice managersYour IT provider
A dedicated compliance manager, included Most firms have no compliance department. Greypike includes a named person who reviews completed work, answers the questions that come up, and keeps the program moving between busy seasons.

Implement once. Attest many.

Compliance obligations accumulate as firms grow. The worst outcome is rebuilding the same security program every time a new one appears.

The same work also answers
Client security questionnairesCyber insurance requirementsVendor reviewsSOC 2 initiativesInternal governance programs

Why firms choose Greypike

The hardest part of FTC Safeguards isn't understanding the rule. It's maintaining the work that demonstrates it, month after month, through a busy season and out the other side.

The traditional approach
Greypike
Spreadsheets and calendar reminders
Assigned recurring tasks
Policies sitting in a folder
Ongoing tracked work
Evidence scattered across email and drives
Centralized evidence management
One-time consulting projects
Continuous compliance workflows
Interpreting the rule yourself
A dedicated compliance manager
Duplicate effort for every new obligation
Framework reuse

Straightforward pricing

No sales process required to see the number. FTC Safeguards is one framework, and one framework is what the subscription covers.

FOUNDING CUSTOMER PRICE
$399per month

or $4,000 a year, saving $788

First 25 customers only. Standard pricing is higher. Founding customers keep this rate for 24 months. 12-month term, no setup fee.

Book a demo
WHAT'S INCLUDED
A dedicated compliance manager
FTC Safeguards converted into assigned tasks
Evidence management
Continuous monitoring
Framework mapping and reuse

Adding SOC 2 later? See framework pricing →

FTC Safeguards compliance that actually gets done

Assigned tasks, a dedicated compliance manager reviewing the work, and current evidence sitting ready when an insurer, a client or a regulator asks. Turn a binder of policies into a program that runs.