Keeping your portal secure

Your KFM client portal is where you see the status of your tax work, send us documents, and message us securely. Here is how to keep your account safe.

Your email is your key

You sign in with a secure link we send to your email address, so anyone who can read your email could open your portal. Protect your email account with a strong, unique password and turn on two-factor authentication (most email providers offer it under security settings).

We will never email you a password

Sign-in links come only from our portal at portal.kfmus.com. We will never ask for your password, Social Security number, or bank details by email. If an email claims to be from us and asks for any of those, don't click. Forward it to us and delete it.

Check the address bar

Before you sign in or type anything, make sure the address begins with https://portal.kfmus.com. If it doesn't, close the page.

Where you pay

The Pay button in your portal opens KFM's own checkout on our main site, kfmus.com. That is normal and safe. If a payment request points anywhere else, or arrives in an email you didn't expect, don't pay it. Message us first.

Don't share your sign-in links

The links we email you are for you alone and expire quickly. Never forward one to anyone, not even to us. We can always send you a fresh one.

If you set a password, make it strong

Use at least 12 characters and don't reuse a password from any other site. A password manager makes this easy.

On shared devices, sign out

If you use a computer that isn't yours, sign out when you're done and don't let the browser save your login.

See something odd? Tell us

If anything looks wrong (a sign-in you didn't request, a document you don't recognize, a suspicious email mentioning KFM), contact us right away at support@kfmus.com. Reporting early is the single most helpful thing you can do.

KFM protects your information with encrypted connections, strict access controls, and continuous monitoring. This page is part of our written security program.