- The content of your receipts: vendor names, amounts, line items, categories
- Your bank transactions (counterparty, IBAN, reference text)
- Your tax IDs (VAT numbers, personal tax numbers)
- Your 2-factor authentication secret
- Your passwords (we never store them; only a one-way hash)
Your tax data,
locked from us too.
We don't see your receipts. We don't read your bank transactions. The data is locked from us too: even if an employee opened the database directly, they'd see encrypted gibberish, because the keys live separately from the data and a dump alone is unreadable. Plain English first. Tech depth below.
What we see, and what we don't.
Tax data is the most sensitive data you own. So our default isn't "trust us". Our default is "we built it so you don't have to".
- How many receipts you have (so we can enforce plan limits)
- Your email address + login times (account management)
- Which bank you connected (NOT what's on it)
- Error logs with PII scrubbed (so we can fix bugs)
- Your billing & subscription state (handled by Stripe)
If we receive a legally binding court order, we cooperate to the minimum extent the law requires, and we notify you unless that order legally prohibits us from doing so. Every such request is recorded internally. We will publish a Transparency Report once we have meaningful numbers.
Your receipt's journey, in 4 steps.
You photograph a receipt with the mobile app, drag a PDF into the browser, or forward an invoice email to your private TaxItEasy address.
Before it lands in our database, it's encrypted with a key that belongs only to your account. That key is itself encrypted and stored separately from your data. A stolen database dump alone is unreadable.
Sent over an encrypted connection (HTTPS) to our servers in Frankfurt, Germany. Your data at rest never leaves the EU (see the AI extraction exception below).
The server stores the encrypted file. It stays locked, and is decrypted only to serve you: when you open a document, or while the extraction runs. Every access is recorded in the audit log.
Click "Delete account". A 30-day window. Then your content is gone, mathematically.
You click "Delete account". Your account is locked the same second. Nobody can log in, including you. We send you a restore link by email.
For 30 days you can change your mind: click the restore link, your account is back as if nothing happened. After 30 days, the restore link expires.
On day 31, your encryption key is deleted. Every receipt, invoice, bank transaction, OCR output, 2FA secret and email-integration token tied to your account becomes mathematically unreadable: for us, for our backups, forever. Your email address is anonymised so no one can connect old records to you.
What stays: a small audit trail ("user X deleted account on date Y") for legally required retention periods. The trail contains no financial content, only timestamped action records. We're required to keep this by tax law. After the retention period (see card below) it's removed automatically.
Tax law requires us to keep certain records even after you delete your account. We keep the bare minimum, with no financial content.
| Document & invoice audit entries | 10 years |
|---|---|
| Bank-transaction audit entries | 10 years |
| Account / login / share audit entries | 2 years |
| General system audit entries | 6 months |
| IP addresses in audit log | Anonymised after 90 days |
| Stripe billing records | Per Stripe's retention policy (legally required for tax) |
Where your data lives
Your data lives in a data center operated by DigitalOcean in Frankfurt, Germany (FRA1 region). It does not leave the European Union. We do not transfer storage to the United States.
The exception is the AI extraction step: when we read what's on your document (vendor, amount, VAT, etc.), we send it to the Anthropic Claude API in the United States for the few seconds of processing, under EU-U.S. Data Privacy Framework + Standard Contractual Clauses. Retention follows Anthropic's commercial default (up to 30 days for safety monitoring); we are in active negotiation for a contractual zero-retention addendum. After extraction, your data goes back to Frankfurt and stays there.
Separately: the AI assistant on this public website is not part of your account and never touches your documents, but what you type into it does go to Anthropic in the United States on those same terms, and to Mistral in France for the search step. Details are in the Privacy Policy.
For the technical reader: how the encryption works
If you're a CISO, IT lead, data-protection officer or just curious, here's what's under the hood.
- Master Key: lives outside the database, in our secrets vault. We use it only to unlock the next layer.
- Account Key: one per company, encrypted with the Master Key, stored in the database.
- File Key: one per receipt or invoice, encrypted with the Account Key. The actual document content is encrypted with this key.
All encryption uses AES-256-GCM, the same standard banks and governments use.
If we ever need to delete a customer's data permanently (a GDPR right-to-erase request, for example), we delete their Account Key. The instant that key is gone, every receipt, every invoice, every transaction belonging to that company becomes mathematically unrecoverable. We don't have to track down every database row. The data is shredded by losing its key.
Beyond document content, we encrypt sensitive individual fields directly in the database:
- Tax IDs (VAT numbers, personal tax numbers)
- Bank account numbers (IBAN)
- Counterparty names and references on bank transactions
- Raw OCR text and structured extraction results
- 2-factor authentication secrets
Even if someone gained read-only access to the database, these fields would be unreadable without the per-account keys.
Search works without ever storing your documents' text in readable form. Instead of a plaintext search index, we build a blind index: every word is reduced to an irreversible HMAC fingerprint under a secret key unique to your company. Your search terms are fingerprinted the same way and matched against those fingerprints. We search fingerprints, never plaintext. The document content itself stays encrypted at rest, and the index is useless without your company's key.
- 2-factor authentication (TOTP) available on every account, free or paid.
- Session rotation: refresh tokens rotate on every use; if one is stolen and replayed, we detect it and invalidate the entire session family.
- Rate limiting on all authentication endpoints, plus account lockout: 10 failed login attempts lock the account for 30 minutes.
- Optional Google Sign-In with verified ID tokens.
- GDPR. We process data under Articles 6(1)(b) and 6(1)(c). DPA available on request to [email protected] and published at taxiteasy.org/dpa.
- Right to erase. Triggered by you in the app. Crypto-shredding completes in seconds, not days.
- Breach notification. If we detect a breach affecting your data, you and the relevant authority are notified within 72 hours.
- Audit log. Every read, write, export and deletion is recorded with timestamp, IP, user agent. Retained up to 10 years (tax-relevant entries, see the retention table above). Append-only: entries cannot be edited.
Certifications & assessments: the roadmap
We hold Google CASA Tier 2 verification (May 2026). Beyond that, here's where we are on broader industry assessments and where we're going. Honest dates, not aspirational ones.
Pre-submission hardening shipped 27 April 2026 (token revocation on disconnect, Svix-signed webhooks, SPF/DKIM verification, fail-closed encryption requirements). Formal CASA Tier 2 verification was completed in May 2026, ahead of the original Q2 2026 target. Annual re-verification follows the standard Google OAuth schedule.
Verified · May 2026We are evaluating whether to pursue SOC 2 Type I in late 2026. SOC 2 is primarily relevant for US enterprise buyers; our current focus is EU mid-market. We will publish a firm date if and when we engage an auditor. No date yet.
Decision in H2 2026ISO 27001 typically takes 9–18 months and €30–80k. We will not pursue it in 2026. We may revisit in 2027 once revenue justifies the spend. We will publish a clear plan if and when this changes.
Not in 2026 roadmapMost recent internal security hardening pass: April 2026 (Sprint 1-4 fail-closed semantics, virus scanner, webhook signatures, encryption requirements). First independent third-party pentest is scheduled for Q4 2026. Findings summary will be published on this page (raw report on request to enterprise customers under NDA).
Independent pentest Q4 2026Email security
Every inbound email to your private TaxItEasy address is verified with SPF or DKIM (forwarding-safe, because forwarding legitimately breaks SPF while preserving DKIM) before we open it. Inbound deliveries are cryptographically signed (Ed25519) by our inbound email provider and verified before processing. Unsigned or invalid requests are rejected. Attachments are virus-scanned with ClamAV before they touch your account.
Bank connections
Today we offer PDF statement upload that works with any bank. The statement is read by the same document pipeline as your receipts (a CSV import endpoint exists for edge cases). Multi-bank Open Banking via a pan-EU PSD2 aggregator is on the 2026 roadmap. When automated bank connections become available, access tokens will be encrypted with your Account Key, and we never store bank login credentials.
Bank accounts can be removed at any time, and specific IBANs can be blocked per company, so a mis-read or mis-forwarded statement cannot silently recreate an account you deleted.
Sub-processors
We use a small, named set of sub-processors. The canonical list lives on our Sub-processors page, with purposes, data processed, locations and transfer mechanisms. That page is also where changes are announced: customers get at least 30 days' notice and a 14-day objection window before any new sub-processor is added.
Summary of categories in use today:
- DigitalOcean: primary infrastructure (DOKS, Postgres, Spaces) in Frankfurt (FRA1). Application-layer envelope encryption (MEK/UEK/DEK) keeps plaintext documents invisible to the host.
- Anthropic: Claude API for document reading, and for answering questions in the public website assistant. United States. Retention per Anthropic's commercial default (≤30 days for safety monitoring); zero-retention addendum in negotiation.
- Mistral AI: text embeddings for the public website assistant, so it can find the right help article. France (EU); we pin the EU endpoint explicitly. Receives only what a visitor types into the website chat: no account, document, banking or tax data.
- Stripe: payment processing. United States.
- Resend: outbound transactional email. United States.
- MailPace (OhMySMTP Ltd): inbound email receiving (receipt forwarding). United Kingdom; email data hosted in France and Germany (EU).
- Sentry: error monitoring with PII scrubbing. United States.
- Cloudflare: CDN, DDoS, WAF. Global edge with EU presence.
The full list with locations, data processed and transfer mechanisms is on our sub-processors page. Customers are notified at least 30 days before any new sub-processor is added (14-day objection window).
Data protection impact assessment (DPIA)
Available on request to [email protected]. We document categories of data, lawful bases, retention periods, sub-processors, encryption design and breach procedures.
Responsible disclosure & vulnerability reporting
If you've found a security issue, we want to hear about it. We follow the RFC 9116 security.txt standard. Our machine-readable contact lives at /.well-known/security.txt.
- Email: [email protected]
- Languages: English, German
- PGP key: available on request
- First reply within 48 hours.
- Severity classification within 5 business days (CVSS 3.1).
- Fix or mitigation timeline within 10 business days of triage.
- Credit on our Hall of Fame when you follow responsible disclosure (see below).
- No legal action against good-faith researchers who follow this policy.
taxiteasy.organd all sub-domainsapp.taxiteasy.org(web app)api.taxiteasy.org(REST API)in.taxiteasy.org(inbound email)- Mobile apps (iOS, Android)
- Vendor-side issues on our sub-processors (Anthropic, Stripe, DigitalOcean, Cloudflare, Resend, MailPace). Please report those directly to the vendor.
- Social engineering against staff.
- Physical security.
- Volumetric DDoS without proof of bypass.
- Issues already known and tracked.
We do not currently run a paid bug bounty programme. We may launch one once independent pentesting is in place (Q4 2026). For now we offer public credit (Hall of Fame) and direct communication with the team.
Hall of Fame
We thank the following researchers for responsibly reporting security issues:
This list is empty so far, and we'd love to add you. Email [email protected].