Trust & Security

Your tax data is
safe with us

TaxEye handles sensitive financial and legal data for thousands of professionals. We treat security as a product feature, not an afterthought — with enterprise-grade architecture, rigorous compliance, and full transparency.

ISO 27001 Aligned DPDP Act 2023 AES-256 Encryption
Our Approach

Security built into every layer

From infrastructure to application to people — TaxEye enforces security at every level.

Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Encryption keys are managed using AWS KMS with automatic rotation.

Cloud Infrastructure

Hosted on AWS India (ap-south-1) region. Data residency in India. Redundant availability zones with automated failover for 99.9% uptime SLA.

Access Controls

Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication (MFA) enforced for all accounts. Single sign-on (SSO) available on enterprise plans.

Security Monitoring

24/7 automated threat detection with AWS GuardDuty and CloudTrail. Anomaly detection alerts, intrusion prevention, and real-time incident response.

Audit Trails

Comprehensive, tamper-evident audit logs for all user actions, data access, and system events. Retained for 7 years in compliance with tax record-keeping requirements.

Backup & Recovery

Automated daily backups with point-in-time recovery. Cross-region backup replication. Recovery Time Objective (RTO) of 4 hours; Recovery Point Objective (RPO) of 1 hour.

Compliance

Built for regulatory compliance

TaxEye is designed to meet the strictest data protection requirements applicable to Indian tax professionals.

DPDP Act 2023

Fully aligned with India's Digital Personal Data Protection Act 2023. Consent-based processing, data principal rights, and designated Grievance Officer in place.

ISO 27001 Aligned

Our information security management system follows ISO 27001 standards for risk assessment, asset management, access controls, and incident response.

PCI-DSS Payments

Payment processing via Razorpay — a PCI-DSS Level 1 certified processor. Card data is never stored on TaxEye servers.

Indian Data Residency

All data is stored and processed within India (AWS ap-south-1 Mumbai). We do not transfer personal data outside India without appropriate safeguards.

Application Security

Secure by design

Security is embedded in our software development lifecycle, not bolted on after. Every release undergoes security review before it reaches production.

  • OWASP Top 10 protection: SQL injection, XSS, CSRF, IDOR prevention
  • Automated static code analysis (SAST) in CI/CD pipeline
  • Annual third-party penetration testing
  • Dependency vulnerability scanning (Snyk, Dependabot)
  • Secure secrets management (AWS Secrets Manager)
  • Zero-trust network architecture with VPC isolation
  • Web Application Firewall (WAF) with rate limiting and DDoS protection
Pen Testing

Annual penetration tests by certified third-party security firms. Reports shared with enterprise customers on request.

VAPT Reports

Vulnerability Assessment and Penetration Testing reports available under NDA for enterprise customers performing due diligence.

Responsible Disclosure

Security researchers can report vulnerabilities to [email protected]. We acknowledge all reports within 48 hours.

Security Training

All TaxEye employees undergo mandatory security awareness training. Engineers complete secure coding training annually.

Data Handling

How we handle your data

Consent-Based Access

Client data is accessible only to users within your authorised workspace. TaxEye staff do not access client data unless explicitly authorised for support purposes, with full audit logging.

Data Deletion

You can delete your data at any time. Account data is purged within 90 days of account closure. Backups containing deleted data are fully purged within 30 days.

Data Portability

Export all your data at any time in standard formats (CSV, PDF, JSON). No lock-in — your data belongs to you.

Breach Notification

In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware, in accordance with DPDP Act 2023 requirements.

Security Questions?

Have security requirements? Let's talk.

For enterprise security reviews, VAPT reports, data processing agreements, or custom compliance questions, contact our security team.

[email protected] · Responds within 48 hours