These measures describe the safeguards maintained by TaxRouter for processing covered by the Data Processing Addendum. They are risk-based and may be updated without materially reducing the overall protection level.
The current approved version is published at https://taxrouter.com/legal/technical-organizational-measures.
1. Governance and risk management
- Assigned accountability for security and data protection.
- Documented security, access, incident, backup, vulnerability, and change-management procedures.
- Periodic risk review and tracking of remediation actions.
- Confidentiality obligations and security awareness for relevant personnel.
- Review of material service providers before and during use.
2. Physical access control
TaxRouter primarily uses managed hosting providers rather than operating its own data centres. Physical controls for hosted infrastructure are provided by the applicable hosting and facility providers. TaxRouter office and endpoint access is restricted to authorized persons.
3. Logical access control
- Unique user and administrative identities.
- Role-based application authorization and least-privilege access.
- Multi-factor authentication for all TaxRouter application accounts and privileged systems where supported.
- Passwords of at least 12 characters with mixed case, number, and special character requirements; identity-fragment checks; history of 10; 24-hour minimum age; 365-day maximum age; and lockout after no more than 10 failed attempts.
- Controlled provisioning, modification, and removal of access.
- Quarterly personnel and service access reviews and revocation within 24 hours after role or employment changes.
- Logging of material administrative and customer-data access where technically appropriate.
4. Data access and tenant separation
- Authorization checks restrict workspace data to permitted users and service functions.
- Organization and role context is enforced in application and server-side access paths.
- Production access by personnel is limited to documented support, security, or operational need.
- Test data should be synthetic or appropriately minimized and protected.
5. Transmission and encryption
- HTTPS/TLS protects supported external data transmission.
- Managed production storage uses encryption at rest where supported and configured.
- Credentials, API tokens, and secrets are stored separately from source code with restricted access.
- Sensitive transfers use authenticated interfaces and scoped authorizations.
6. Input, change, and audit controls
- Material account, integration, workflow, and security events are logged where appropriate.
- Security events for systems processing Amazon PII are retained for at least 12 months, excluded from ordinary user modification, and reviewed at least bi-weekly.
- Source changes are version controlled and subject to review and automated checks.
- Deployments use controlled identities and environment-specific configuration.
- Production changes and incidents can be correlated to available audit evidence.
7. Availability and resilience
- Managed infrastructure includes redundancy appropriate to the selected services.
- Backups are maintained for systems requiring recovery and protected from ordinary application access.
- Monitoring and alerting cover material service failures and security conditions.
- Recovery and incident procedures define responsibilities and escalation.
- Capacity and dependency risks are reviewed as the service grows.
8. Integrity and secure processing
- Validation and authorization are applied to sensitive operations.
- Dependency, code, and infrastructure risks are assessed through automated and manual controls.
- Vulnerabilities are tracked and prioritized according to risk.
- Malware and unsafe-file handling controls are applied where relevant to uploaded content.
9. Separation by purpose and data minimization
- Customer data is processed only for configured services, documented instructions, security, support, and legal compliance.
- Production, development, and test environments use separate configuration and access boundaries.
- Collection and retention are limited according to documented purpose and operational need.
- Amazon buyer PII and source records covered by documented tax or accounting retention obligations are retained only for those legal purposes, with access restricted for the applicable statutory period.
- Marketplace data is not used for advertising, resale, unrelated profiling, or fulfilment operations.
10. Deletion, return, and media handling
- Application deletion and export functions are provided where defined by the service.
- Contract-end deletion follows the DPA and documented operational process.
- Backup copies expire through controlled retention cycles and remain restricted from ordinary use.
- Company devices and storage media are securely erased or cryptographically sanitized before reuse or disposal where applicable.
11. Incident management
- A documented process covers identification, triage, containment, investigation, remediation, recovery, communication, and lessons learned.
- The incident response plan is reviewed every six months, after material changes, and after significant incidents; it is exercised at least annually.
- Security and privacy incidents are recorded and escalated according to severity.
- Personal data breaches are assessed for notification obligations and reported to affected controllers without undue delay as required by the DPA.
- Amazon is notified within 24 hours after detection of a security incident involving the application or Amazon information.
- Evidence is preserved where appropriate.
12. Subprocessor management
- Subprocessors are selected based on service, security, privacy, location, and contractual requirements.
- Processing agreements and transfer safeguards are completed before covered processing begins.
- Material changes are tracked and notified under the DPA.
13. Marketplace and regulatory control mapping
Applicable marketplace and regulatory duties are mapped to owned controls and evidence rather than treated as satisfied by this document alone. The mapping covers Amazon SP-API requirements applicable to the granted roles. TaxRouter periodically assesses whether German BSIG requirements implementing NIS2 apply based on company size, service classification, group relationships, and special inclusion rules.