Security & Data Protection
Handling sensitive financial data is our core responsibility. This page explains the controls we run at Taxpex Consultancy to keep your data safe.
Transport & storage
All traffic between your browser and Taxpex is encrypted with TLS 1.3. Client documents and financial data are stored in a managed PostgreSQL database with AES-256 at-rest encryption, hosted on ISO 27001 / SOC 2 certified infrastructure with India-region residency.
Access control
Role-based access control (RBAC) with least privilege. Multi-factor authentication is mandatory on every admin and CA account. All access is logged with an immutable audit trail.
Application security
Row-Level Security (RLS) on every database table, parameterised queries, CSRF-safe forms, HTTP security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) and dependency scanning via automated CI.
Operational security
Secrets are never committed to code — all credentials live in a managed vault. Backups run daily with 30-day retention. Incident response playbooks are tested quarterly.
Client-side hygiene
We recommend clients (a) share documents only via our secure upload links or WhatsApp Business number, never public channels, (b) enable 2FA on their GST/ITR/MCA portals, (c) rotate DSC PINs periodically.
Report a vulnerability
Responsible disclosure is welcomed. Email contact@taxpex.in with details — we respond within 48 hours and credit reporters in a public hall-of-fame with permission.