5,300+ tax returns filed in the last 4 seasons — two-EA reviewed, on one platform. Talk to us

§ Legal

Incident response.

What TaxSQR does if something goes wrong with your data — how we detect, contain, and tell you about security incidents.

Last updated 20 July 2026

Our commitment

If we confirm unauthorized access to a firm’s client data, we notify that firm within 72 hours of confirmation, give it the information it reasonably needs to assess the incident, cooperate on any notification the law requires it to make, and bear the direct costs of a breach caused by TaxSQR. This commitment is contractual for firms with a signed services agreement.

How we detect and contain

The platform keeps an immutable audit log of access to client data, access is role-based with multi-factor authentication, and infrastructure alerts flag unusual activity. When an alert fires, we isolate the affected account or system first, then investigate — containment before analysis.

What a notification includes

  • What happened and when we confirmed it.
  • Whose data was involved, and which kinds of data.
  • What we have done to contain it, and what we are still doing.
  • A named contact for follow-up questions.

After the incident

Every confirmed incident gets a written post-incident review: root cause, what we changed, and what we will monitor. Firms affected by the incident can request a copy of the review’s summary.

Reporting a concern

If you believe you’ve found a security problem in TaxSQR — as a firm, a taxpayer, or a researcher — email contact@taxsqr.com with the details. We acknowledge reports within one business day and don’t take action against good-faith reporters.