Security Practices
Your financial data deserves enterprise-grade protection. Learn how we keep it safe.
Last updated: December 1, 2025
At TaxScout, security is not an afterthought—it's foundational to everything we build. We understand that you're trusting us with sensitive financial and property information, and we take that responsibility seriously. Our security program is designed to meet or exceed industry standards for financial services platforms.
Data Encryption
- AES-256 encryption for all data at rest
- TLS 1.3 encryption for all data in transit
- End-to-end encryption for sensitive financial data
- Secure key management with regular rotation
- Hardware security modules (HSM) for cryptographic operations
Infrastructure Security
- SOC 2 Type II certified cloud infrastructure
- Multi-region data redundancy and backups
- DDoS protection and web application firewall
- Network segmentation and access controls
- 24/7 infrastructure monitoring and alerting
Access Controls
- Multi-factor authentication (MFA) for all accounts
- Role-based access control (RBAC)
- Session management with automatic timeouts
- IP allowlisting for sensitive operations
- Audit logging of all access and changes
Employee Security
- Background checks for all employees
- Regular security awareness training
- Principle of least privilege access
- Secure development lifecycle practices
- Confidentiality agreements and policies
Responsible Disclosure Program
We believe in working with security researchers to keep our platform safe. If you discover a vulnerability, please report it responsibly.
- Email security issues to support@taxscout.app
- We aim to respond within 24 hours
- We offer recognition for valid reports
Security Questions?
If you have questions about our security practices or want to request our SOC 2 report, please contact our security team.
Email: support@taxscout.app
Our Security Commitment
We continuously invest in security improvements and regularly engage third-party auditors to validate our controls. Our team includes security professionals with experience at leading financial institutions and technology companies. We are committed to transparency and will notify affected users promptly in the unlikely event of a security incident.