Taxomind · Security
The Security Brief
We take security seriously, and we describe only what actually ships. Your data is protected by practical, layered security measures — each independent, so a single failure is never a single point of exposure.
Defense in Depth
Six layers of protection to keep your data safe
From the infrastructure outward to continuous monitoring — each layer stands on its own.
Managed Hosting
The ground we stand on — managed infrastructure with encryption at the edge.
- Hosted on Railway with managed PostgreSQL
- HTTPS / TLS enforced at the network edge
- Automated, reproducible deployments
Privacy by Design
Privacy considerations built into the application from the first line.
- Built with GDPR and CCPA principles in mind
- Data minimization — we collect only what the product needs
Encryption & Payment Isolation
Your data is encrypted in motion, and we never handle your card details.
- Encrypted in transit using TLS
- Passwords hashed with bcrypt — never stored in plain text
- Payments processed by Stripe; card data never reaches our servers
Access Controls
Separate admin and learner authentication, on a least-privilege model.
- Role-based access control (ADMIN / USER separation)
- Multi-factor authentication for admin accounts
Dependency & Health Checks
Defenses maintained, not assumed.
- Automated dependency vulnerability scanning
- Application health checks on the database and core services
Data Subject Rights
You stay in control — export or delete your data whenever you want.
- Self-service data export
- Self-service account and data deletion
The Specs · Encryption & Transport
The protections, in plain technical terms
On the Record · Certifications
Compliance & Data Rights
We’re an early-stage product, so here’s exactly where we stand — the data rights that ship today, and the formal audits we haven’t completed yet. No badges we haven’t earned.
- GDPR data rights (export / deletion)Available
- CCPA data rightsAvailable
- SOC 2 Type II auditNot yet
- ISO 27001 certificationNot yet
Responsible Disclosure
Report a Vulnerability
We appreciate security researchers who help keep Taxomind safe. If you discover a vulnerability, please report it responsibly.