Our commitment
If we confirm unauthorized access to a firm’s client data, we notify that firm within 72 hours of confirmation, give it the information it reasonably needs to assess the incident, cooperate on any notification the law requires it to make, and bear the direct costs of a breach caused by TaxSQR. This commitment is contractual for firms with a signed services agreement.
How we detect and contain
The platform keeps an immutable audit log of access to client data, access is role-based with multi-factor authentication, and infrastructure alerts flag unusual activity. When an alert fires, we isolate the affected account or system first, then investigate — containment before analysis.
What a notification includes
- What happened and when we confirmed it.
- Whose data was involved, and which kinds of data.
- What we have done to contain it, and what we are still doing.
- A named contact for follow-up questions.
After the incident
Every confirmed incident gets a written post-incident review: root cause, what we changed, and what we will monitor. Firms affected by the incident can request a copy of the review’s summary.
Reporting a concern
If you believe you’ve found a security problem in TaxSQR — as a firm, a taxpayer, or a researcher — email contact@taxsqr.com with the details. We acknowledge reports within one business day and don’t take action against good-faith reporters.