Security program
TaxRouter maintains a risk-based security program intended to protect the confidentiality, integrity, availability, and resilience of customer data and the TaxRouter service. The Managing Director is accountable for the program and assigns technical responsibilities to designated personnel. Controls, risks, access, and remediation records are reviewed at their documented cadence and after material service, threat, legal, or contractual changes.
Identity and access
Access to production systems and customer data is restricted according to business need and least-privilege principles. TaxRouter application accounts require multi-factor authentication; administrative access uses individual accounts and multi-factor authentication where supported. Application workspaces use role-based permissions, and sensitive access is logged and reviewed. Personnel and service access is reviewed quarterly and changed or revoked within 24 hours after a role or engagement changes. Emergency access is limited, documented, and reviewed after use.
Encryption and secrets
TaxRouter uses HTTPS/TLS for data in transit. Managed production databases, object storage, and backups use encryption at rest. Secrets are kept outside source code, restricted to the services and personnel that require them, scanned for accidental disclosure, and rotated when exposure or operational risk requires it.
Secure development
Source changes are version controlled and reviewed. Automated code-quality, production-dependency, static-analysis, secret-scanning, and build checks support release decisions. Production and non-production configuration and credentials are separated. Production changes follow controlled deployment processes, and security-sensitive findings are prioritized according to risk.
Infrastructure, monitoring, and resilience
TaxRouter uses Vercel for hosting and object storage and PlanetScale for the production PostgreSQL database, configured in Frankfurt. Provider and application monitoring detect material service failures and security-relevant events. Managed database backups and documented recovery procedures are maintained for systems requiring restoration. Security events are stored separately from ordinary application users, excluded from customer-facing modification, retained for at least 12 months where Amazon PII is processed, and reviewed at least bi-weekly. Managed capacity, redundancy, and network protections supplement TaxRouter's application controls.
Vulnerability management
Security findings may be identified through automated production-dependency audits, static source analysis, secret scanning, code review, infrastructure checks, provider notifications, and responsible reports. Findings are assessed using severity, exploitability, exposure, and data impact. Critical findings are targeted for remediation within seven days and high findings within 30 days. A risk-based exception must be documented, time-limited, and approved by the Managing Director. Findings may be reported to info@taxrouter.com.
Incident response
TaxRouter maintains procedures to identify, contain, investigate, remediate, document, and learn from security incidents. The Managing Director coordinates response with designated technical responders and relevant providers. The plan is reviewed every six months and after material changes or significant incidents, and the response process is exercised at least annually. Amazon is notified within 24 hours after detection of a security incident involving the application or Amazon information. Affected customers are notified through their registered contact address without undue delay; for a personal data breach, TaxRouter targets an initial notice within 24 hours after becoming aware. Evidence is preserved where appropriate, forensic support is engaged where needed, and corrective actions are tracked after significant incidents.
Marketplace data
Authorized marketplace data is processed only for enabled TaxRouter workflows and is not used for advertising, resale, unrelated customer profiling, or direct-to-consumer fulfilment. Access is limited to authorized users, service components, and personnel with a documented operational need. Amazon buyer PII and source records subject to documented tax or accounting retention obligations are retained only for those legal purposes, tenant-scoped and access-restricted for the applicable statutory period. Revoking authorization removes the connection and credentials but does not destroy records that must be retained by law. Retention, deletion, logging, and vulnerability controls are mapped to the requirements of each enabled marketplace integration.
Contact
Security concerns and suspected vulnerabilities may be reported to the monitored address info@taxrouter.com or through the contact form. Reports should include enough detail to reproduce and assess the issue, avoid unnecessary access to or alteration of data, and allow reasonable time for remediation before public disclosure. We acknowledge good-faith reports and coordinate follow-up through the reporting channel. No public encryption key is currently provided; reporters should request a secure exchange method before sending sensitive evidence.