Legal · Last updated 5 July 2026

    Security & Data Protection

    Handling sensitive financial data is our core responsibility. This page explains the controls we run at Taxpex Consultancy to keep your data safe.

    Transport & storage

    All traffic between your browser and Taxpex is encrypted with TLS 1.3. Client documents and financial data are stored in a managed PostgreSQL database with AES-256 at-rest encryption, hosted on ISO 27001 / SOC 2 certified infrastructure with India-region residency.

    Access control

    Role-based access control (RBAC) with least privilege. Multi-factor authentication is mandatory on every admin and CA account. All access is logged with an immutable audit trail.

    Application security

    Row-Level Security (RLS) on every database table, parameterised queries, CSRF-safe forms, HTTP security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) and dependency scanning via automated CI.

    Operational security

    Secrets are never committed to code — all credentials live in a managed vault. Backups run daily with 30-day retention. Incident response playbooks are tested quarterly.

    Client-side hygiene

    We recommend clients (a) share documents only via our secure upload links or WhatsApp Business number, never public channels, (b) enable 2FA on their GST/ITR/MCA portals, (c) rotate DSC PINs periodically.

    Report a vulnerability

    Responsible disclosure is welcomed. Email contact@taxpex.in with details — we respond within 48 hours and credit reporters in a public hall-of-fame with permission.