{"id":7921,"date":"2026-08-12T06:09:00","date_gmt":"2026-08-12T10:09:00","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=7921"},"modified":"2026-08-17T10:43:28","modified_gmt":"2026-08-17T14:43:28","slug":"mfa-edr-encryption-irs-compliance","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/mfa-edr-encryption-irs-compliance\/","title":{"rendered":"What Do MFA, EDR, and Encryption Actually Do for IRS Compliance?"},"content":{"rendered":"\n<p><strong>MFA blocks a stolen password from becoming a login, EDR catches an attacker who gets in anyway, and encryption makes stolen data unreadable. IRS Publication 4557 treats all three as baseline controls a firm&#8217;s Written Information Security Plan (WISP) has to document, not optional extras.<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>Key takeaways<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Opting out of MFA in your tax software is an FTC Safeguards Rule violation, not a preference.<\/li>\n\n\n\n<li>EDR watches behavior and catches ransomware that antivirus alone misses.<\/li>\n\n\n\n<li>Encryption protects data in transit and at rest so a stolen device isn&#8217;t a readable breach.<\/li>\n\n\n\n<li>IRS Pub 4557 requires all three as documented <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/written-information-security-plan\" target=\"_blank\" rel=\"dofollow noopener\" title=\"WISP\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1359\">WISP<\/a> controls, not suggestions.<\/li>\n\n\n\n<li>VeritSpace and <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/veritcomplete\" target=\"_blank\" rel=\"dofollow noopener\" title=\"VeritComplete\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1360\">VeritComplete<\/a> include all three by default; VeritShield WISP documents them in 5 business days.<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#what-is-mfa-and-why-does-the-irs-require-it\">What Is MFA and Why Does the IRS Require It?<\/a><\/li><li><a href=\"#is-turning-off-mfa-in-your-tax-software-a-safeguards-violation\">Is Turning Off MFA in Your Tax Software a Safeguards Violation?<\/a><\/li><li><a href=\"#does-mfa-on-the-tax-app-count-or-does-the-workstation-need-it-too\">Does MFA on the Tax App Count, or Does the Workstation Need It Too?<\/a><\/li><li><a href=\"#what-is-edr-and-how-is-it-different-from-antivirus\">What Is EDR and How Is It Different From Antivirus?<\/a><\/li><li><a href=\"#what-does-encryption-protect-and-when-does-it-matter-most\">What Does Encryption Protect and When Does It Matter Most?<\/a><\/li><li><a href=\"#how-do-mfa-edr-and-encryption-work-together-in-a-wisp\">How Do MFA, EDR, and Encryption Work Together in a WISP?<\/a><\/li><li><a href=\"#sources\">Sources<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-mfa-and-why-does-the-irs-require-it\"><strong>What Is MFA and Why Does the IRS Require It?<\/strong><\/h2>\n\n\n\n<p><strong>Multi-factor authentication (MFA) requires a second proof of identity, usually a code sent to a phone or app, before anyone can log in. It matters because passwords get stolen constantly through phishing and data breaches, and MFA means a stolen password alone can&#8217;t get an attacker into your systems.<\/strong><\/p>\n\n\n\n<p>Credential theft is the single most common way tax preparers get breached. A password can leak from a phishing email, a breach at an unrelated site, or simple guessing, and none of that matters if the login also needs a code from a device the attacker doesn&#8217;t have.<\/p>\n\n\n\n<p>Publication 4557 lists MFA as one of the baseline controls a WISP must document. It&#8217;s not framed as a recommendation. An auditor or an insurer reviewing your WISP will ask whether MFA is enabled on email, remote access, and any system touching client data, not whether you&#8217;ve considered it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-1024x576.jpg\" alt=\"Second factor login for accounting firm systems cinematic visual | Verito\" class=\"wp-image-8014\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-mfa.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"is-turning-off-mfa-in-your-tax-software-a-safeguards-violation\">Is Turning Off MFA in Your Tax Software a Safeguards Violation?<\/h2>\n\n\n\n<p><strong>Yes. Turning off MFA in your tax software puts your firm in violation of the FTC Safeguards Rule. IRS Publication 4557 lists MFA as a baseline WISP control, and 16 CFR 314 goes further: since June 9, 2023, MFA is a federal requirement on any system, application, or device that touches customer information.<\/strong><\/p>\n\n\n\n<p>Professional tax preparers count as financial institutions under the Safeguards Rule, and <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">16 CFR 314.4(c)(5)<\/a> requires multi-factor authentication for anyone accessing any information system that holds customer data. Tax software vendors now build MFA into their products, and <a href=\"https:\/\/accountants.intuit.com\/taxprocenter\/tax-law-and-news\/ftc-safeguard-rule-now-requires-multi-factor-authentication\/\" target=\"_blank\" rel=\"nofollow noopener\">Intuit&#8217;s Tax Pro Center<\/a> spells out what that means for the opt-out screen: declining MFA inside the software is a violation of the rule, not a setting the firm is free to change.<\/p>\n\n\n\n<p>The Safeguards Rule allows exactly one alternative. Your firm&#8217;s designated Qualified Individual can approve, in writing, an access control that is reasonably equivalent to MFA or more secure. Wanting fewer login prompts during busy season doesn&#8217;t meet that bar. Without a documented equivalent control, leave MFA on and record it in your WISP as an implemented control under IRS Pub 4557.<\/p>\n\n\n\n<p>&#8220;I have found Verito&#8217;s cloud-based infrastructure to be incredibly beneficial, as it means I don&#8217;t have to worry about maintaining any software or dealing with security requirements.&#8221; Rizwan M., Owner, Riz &amp; Co Certified Public Accountants \u00b7 G2, Oct 2025<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"does-mfa-on-the-tax-app-count-or-does-the-workstation-need-it-too\">Does MFA on the Tax App Count, or Does the Workstation Need It Too?<\/h2>\n\n\n\n<p><strong>No, MFA on the tax app alone doesn&#8217;t cover you. The FTC Safeguards Rule (16 CFR 314) applies to any system holding customer information, so the workstation login, email, remote access, and file storage each need MFA too. Client data lives in all of those places, and the requirement follows the data.<\/strong><\/p>\n\n\n\n<p>The scope in <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">16 CFR 314<\/a> is &#8220;any information system,&#8221; not &#8220;the tax application,&#8221; and client data rarely stays inside the tax app. Returns get exported as PDFs to a desktop folder. Engagement letters and source documents sit in email. Staff sign in from home over remote desktop. The rule expects MFA in front of each of those sign-ins.<\/p>\n\n\n\n<p>Five logins carry client data in a typical firm:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Tax software.<\/strong> The built-in MFA, kept on. This is the one login most firms already have covered.<\/li>\n\n\n\n<li><strong>Workstation or hosted server sign-in.<\/strong> The Windows desktop where the tax app, exports, and client PDFs live. App-level MFA does nothing for a stolen Windows password.<\/li>\n\n\n\n<li><strong>Email.<\/strong> Client documents plus the password-reset links for every other account. An unprotected mailbox undoes MFA everywhere else.<\/li>\n\n\n\n<li><strong>Remote access.<\/strong> VPN and remote desktop connections from home or a client site.<\/li>\n\n\n\n<li><strong>File sharing and client portals.<\/strong> Anywhere returns and source documents get uploaded or stored.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>System<\/strong><\/th><th><strong>Does tax-app MFA cover it?<\/strong><\/th><th><strong>What needs its own MFA<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Tax software<\/td><td>Yes<\/td><td>The app&#8217;s built-in MFA, kept on<\/td><\/tr><tr><td>Workstation or hosted server<\/td><td>No<\/td><td>The Windows sign-in itself<\/td><\/tr><tr><td>Email<\/td><td>No<\/td><td>The mailbox login (Microsoft 365 or Google Workspace)<\/td><\/tr><tr><td>Remote access<\/td><td>No<\/td><td>The VPN or remote desktop connection<\/td><\/tr><tr><td>File sharing and client portals<\/td><td>No<\/td><td>Each portal or storage account<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Covering every login for every employee is exactly the kind of task that slips between tax seasons. VeritGuard enforces MFA across the devices it manages, so workstation coverage doesn&#8217;t depend on each employee remembering to opt in. VeritSpace puts MFA on the server login itself: the hosted desktop where Drake, UltraTax, or QuickBooks runs sits behind a second factor on every tier, next to 256-bit encryption. Both are designed to support IRS Pub 4557 and FTC Safeguards requirements, with the controls documented where a WISP review or an insurer&#8217;s questionnaire can see them.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;Verito has allowed my firm to maintain security and support remote work, featuring aspects such as a backup server and a central sign-in location for employees.&#8221; <\/em><\/p><cite>April W., Owner, AAA Business Services LLC \u00b7 G2, Oct 2025<\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-edr-and-how-is-it-different-from-antivirus\"><strong>What Is EDR and How Is It Different From Antivirus?<\/strong><\/h2>\n\n\n\n<p><strong>Endpoint Detection and Response (EDR) watches behavior instead of matching known malicious files. It flags a program doing something suspicious, like suddenly encrypting hundreds of files, even if that specific program has never been seen before. Antivirus can&#8217;t do that.<\/strong><\/p>\n\n\n\n<p>Ransomware increasingly uses techniques that don&#8217;t trip traditional antivirus, because antivirus is built to recognize known threats, not new behavior. EDR catches the pattern of an attack in progress, which is often the only way to stop it before it spreads across a network.<\/p>\n\n\n\n<p>Ransomware against tax preparers isn&#8217;t a hypothetical. It&#8217;s one of the most common breach types reported to the IRS Identity Theft office each year, and EDR is the control most likely to interrupt an attack mid-execution rather than after the damage is already done.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-encryption-protect-and-when-does-it-matter-most\"><strong>What Does Encryption Protect and When Does It Matter Most?<\/strong><\/h2>\n\n\n\n<p><strong>Encryption scrambles data so a stolen file, laptop, or backup is unreadable without the key. It matters in two states: encryption in transit, for data moving between systems, and encryption at rest, for data sitting on a server or backup drive.<\/strong><\/p>\n\n\n\n<p>A stolen laptop or a hacked backup only becomes a breach if the data on it is readable. Encrypted data that falls into the wrong hands is functionally useless to whoever took it, which is why encryption is one of the few controls that limits damage after something has already gone wrong.<\/p>\n\n\n\n<p>Client Social Security numbers, bank details, and tax records are exactly what encryption is built to protect. That&#8217;s also why it shows up in nearly every compliance framework a firm might face, not just the IRS&#8217;s.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-do-mfa-edr-and-encryption-work-together-in-a-wisp\"><strong>How Do MFA, EDR, and Encryption Work Together in a WISP?<\/strong><\/h2>\n\n\n\n<p><strong>None of the three controls works alone. MFA stops someone from getting in with a stolen password, EDR catches an attacker who gets in anyway, and encryption limits the damage if data is accessed or stolen despite both. A WISP that lists all three without implementing them fails an IRS audit or an insurer&#8217;s questionnaire.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-1024x576.jpg\" alt=\"Encrypted tax records with protected access key cinematic visual | Verito\" class=\"wp-image-8015\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/mfa-edr-encryption-irs-compliance-encryption.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Each control covers a different stage of an attack:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>MFA<\/strong> stops unauthorized login even when a password is compromised.<\/li>\n\n\n\n<li><strong>EDR<\/strong> detects and interrupts malicious behavior already inside the network.<\/li>\n\n\n\n<li><strong>Encryption<\/strong> limits exposure if data is accessed or removed regardless of the first two controls.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Control<\/strong><\/td><td><strong>Stage it protects<\/strong><\/td><td><strong>What it stops<\/strong><\/td><td><strong>IRS\/insurer relevance<\/strong><\/td><\/tr><tr><td>MFA<\/td><td>Login<\/td><td>Stolen or guessed passwords<\/td><td>Baseline WISP control under Pub 4557<\/td><\/tr><tr><td>EDR<\/td><td>In-network activity<\/td><td>Ransomware and novel attack behavior<\/td><td>Increasingly required on cyber insurance applications<\/td><\/tr><tr><td>Encryption<\/td><td>Data at rest and in transit<\/td><td>Readable data after theft<\/td><td>Protects SSNs, bank details, and tax records specifically<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>An insurer&#8217;s questionnaire increasingly asks about the same three controls the IRS requires in a WISP. Firms that treat them as three separate checkboxes instead of a stacked system tend to fail both reviews at once.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;I value the robust firewall that Verito provides, helping me maintain compliance with WISP and ensuring the protection of client data.&#8221;<\/em><\/p><cite><strong>Carrol G., Owner, Gatlin Tax, Ltd \u00b7 G2, Nov 2025<\/strong><\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<p><strong>Do <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/veritspace\" target=\"_blank\" rel=\"dofollow noopener\" title=\"VeritSpace\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1361\">VeritSpace<\/a> and VeritComplete Include MFA, EDR, and Encryption by Default?<\/strong><\/p>\n\n\n\n<p><strong>Yes. Firms hosted on VeritSpace or bundled under VeritComplete get MFA, EDR, and encryption built into the environment from day one, not a separate project the firm has to manage. VeritShield WISP produces audit-ready documentation of those controls in 5 business days.<\/strong><\/p>\n\n\n\n<p>That means a firm doesn&#8217;t configure these controls piecemeal across a patchwork of vendors. They&#8217;re part of the hosting environment itself, alongside 256-bit encryption, SOC 2 certification, and IRS Pub 4557 compliance built into every VeritSpace tier.<\/p>\n\n\n\n<p>If something does go wrong, support isn&#8217;t a ticket queue. Every request reaches a real person in under 60 seconds, with 92% resolved on the first touch.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;The customer support team at Verito is very quick to respond and consistently courteous, providing excellent support that enhances my overall experience.&#8221;<\/em><\/p><cite><strong>David C., Owner, David Cleaver-Bartholomew, EA \u00b7 G2, Oct 2025<\/strong><\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<p><strong>How Do I Know If My Firm&#8217;s Current Setup Would Pass an IRS or Insurer Review?<\/strong><\/p>\n\n\n\n<p><strong>The fastest check is matching your current MFA, EDR, and encryption setup against what Pub 4557 and a typical insurer questionnaire ask for by name, not by whether you have generic security software installed. A firm running all three, documented in a current WISP, passes both. A firm missing documentation, even with the controls in place, often doesn&#8217;t.<\/strong><\/p>\n\n\n\n<p>Not sure whether your firm&#8217;s current setup would hold up? <a href=\"https:\/\/verito.com\/contact\" target=\"_blank\" rel=\"dofollow\">Get a compliance check-in with Verito<\/a> and find out what an IRS review or an insurer&#8217;s questionnaire would actually flag.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"sources\"><strong>Sources<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\" target=\"_blank\" rel=\"nofollow noopener\">IRS Publication 4557, Safeguarding Taxpayer Data<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/privacy-security\/gramm-leach-bliley-act\" target=\"_blank\" rel=\"nofollow noopener\">FTC Safeguards Rule, 16 CFR Part 314<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/accountants.intuit.com\/taxprocenter\/tax-law-and-news\/ftc-safeguard-rule-now-requires-multi-factor-authentication\/\" target=\"_blank\" rel=\"nofollow noopener\">Intuit Tax Pro Center: FTC Safeguards Rule now requires multi-factor authentication<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">FTC Safeguards Rule, 16 CFR Part 314 (eCFR)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"MFA blocks a stolen password from becoming a login, EDR catches an attacker who gets in anyway, and&hellip;\n","protected":false},"author":12,"featured_media":8012,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-7921","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/7921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=7921"}],"version-history":[{"count":7,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/7921\/revisions"}],"predecessor-version":[{"id":8062,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/7921\/revisions\/8062"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/8012"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=7921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=7921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=7921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}