Security

How AudiTax protects your clients' data

You hold other people's tax affairs. This page describes what the platform actually does to protect them — and, at the bottom, what it does not do yet.

Security measures

  • Documents can be sealed with a password

    A document in the firm's vault can be protected with a password that is never stored. The file is encrypted with AES-256-GCM in 1 MiB frames, each frame carrying its own nonce and authentication tag, so every byte is verified before it is handed to you rather than after the whole file has been read.

    The framing also closes the three attacks that splitting a file introduces: a frame moved out of position fails its tag, a truncated stream is refused because the final frame is marked, and nonces are counters rather than random values so a key and nonce pair cannot repeat.

  • Your firm decides whether a lost password is recoverable

    The key that encrypts a document is itself wrapped — always under a key derived from the password with scrypt, and optionally under the organization's own key as well.

    Keep the second wrap and an administrator can recover the file. Decline it and the document is zero-knowledge: nobody, including us, can open it, and a forgotten password destroys it permanently. That is the firm's choice to make, not ours, so it is offered rather than decided.

  • Two-factor secrets are encrypted at rest

    When a user turns on two-factor authentication, the TOTP secret is sealed with AES-256-GCM under a fresh nonce before it is written. The raw code is never stored.

  • Access is scoped by role, and roles are deliberately few

    Every record belongs to one organization and is read through that scope. Within a firm there is exactly one administrator — the person who created it — and the only role that administrator can hand out is Staff.

    A firm cannot grow a second administrator, which keeps the question of who can change what answerable at any moment rather than after an investigation.

  • Records carry their own history

    Creation, update, deletion, activation, deactivation, moves, exports and onboarding completion are each written to an activity trail against the record they happened to, with the user who did it and the organization it belongs to.

    Moving a document is recorded as its own action rather than as a field change, because a move is the one edit that leaves no trace on the file itself — it is byte-for-byte identical afterwards, and the trail is the only evidence it was ever somewhere else.

  • Where your data is stored

    Documents are stored in Amazon S3 in the ap-south-1 region, which is Mumbai, India. Data is not currently held inside the UAE.

    We state the region plainly because a firm with a data-residency requirement in its own client engagements needs to know before it signs, not during an audit. If UAE residency is a condition for your practice, tell us and we will say honestly whether and when we can meet it.

What we do not claim

A security page is worth reading only if it is willing to say what is absent.

  • AudiTax holds no security certification. There is no SOC 2 report, no ISO 27001 certificate, and no completed third-party penetration test. When one exists it will be named here with its date and its scope, and not before.
  • Document encryption is a per-document choice, not a blanket guarantee. Files that have not been password-protected are stored without that additional layer.
  • AudiTax is not an Accredited Service Provider and transmits nothing to the Federal Tax Authority on your behalf.

Reporting a vulnerability

If you have found a security problem, write to us directly and we will acknowledge it. Please do not disclose it publicly until it is fixed.

Email the team

See also our Privacy Policy and Terms of Service.

See it on your own filing calendar.

Thirty minutes, your entities, your deadlines — not a generic demo.