Security Policy

Security Policy

Effective Date: April 20, 2026

1. Our Security Commitment

Tax Lens AI ("Tax Lens," "we," "our," or "us") is committed to maintaining the confidentiality, integrity, and availability of all data entrusted to our platform. This Security Policy describes the administrative, technical, and organizational measures we implement to protect your data. Given the sensitive nature of financial and tax-related information processed through our platform, we apply security controls that meet or exceed industry standards for financial data protection.

2. Infrastructure Security

Our platform is hosted on enterprise-grade cloud infrastructure with the following protections:

  • Geographically distributed data centers with physical security controls, including biometric access, 24/7 surveillance, and environmental protections
  • Network segmentation and isolation to prevent lateral movement between services
  • Distributed denial-of-service (DDoS) mitigation at the network edge
  • Automated scaling and redundancy to ensure high availability
  • Regular infrastructure patching and vulnerability management

3. Data Encryption

  • In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and employ HTTP Strict Transport Security (HSTS) headers
  • At Rest: All stored data, including database records, file storage, and backups, is encrypted using AES-256 encryption
  • Key Management: Encryption keys are managed through dedicated key management services with automatic rotation policies and strict access controls

4. Access Control

We enforce the principle of least privilege across all systems:

  • Role-based access control (RBAC) ensures that personnel access only the data and systems necessary for their specific responsibilities
  • Multi-factor authentication (MFA) is required for all administrative access to production systems
  • Access permissions are reviewed quarterly and revoked immediately upon role change or termination
  • All administrative actions are logged and auditable
  • Privileged access sessions are monitored and time-limited

5. Application Security

Our application security practices include:

  • Secure Development Lifecycle: Security is integrated into every phase of our software development process, from design through deployment
  • Input Validation: All user inputs are validated and sanitized to prevent injection attacks, cross-site scripting (XSS), and other common vulnerabilities
  • Authentication: Secure OAuth-based authentication with session management, token rotation, and automatic session expiration
  • API Security: All API endpoints are authenticated, rate-limited, and monitored for anomalous activity
  • Dependency Management: Automated scanning of third-party dependencies for known vulnerabilities with prompt patching

6. AI and Machine Learning Security

Given our reliance on AI-powered analysis, we implement additional security measures specific to our AI systems:

  • Data Isolation: Analysis queries and results are processed in isolated environments to prevent data leakage between users
  • Prompt Security: Input sanitization and guardrails are applied to prevent prompt injection and adversarial manipulation of AI outputs
  • Output Validation: AI-generated outputs are subject to validation checks before delivery to users
  • No Training on User Data: Your submitted data is not used to train or improve our AI models without your explicit consent

7. Incident Response

We maintain a documented incident response plan that includes:

  • Detection: Continuous monitoring and automated alerting for security anomalies across all systems
  • Containment: Immediate isolation of affected systems to prevent further exposure
  • Investigation: Thorough forensic analysis to determine the scope, cause, and impact of the incident
  • Notification: Affected users and relevant regulatory authorities will be notified within 72 hours of a confirmed data breach, or sooner as required by applicable law (including GDPR Article 33 and applicable US state breach notification laws)
  • Remediation: Implementation of corrective measures to prevent recurrence
  • Post-Incident Review: Documented lessons learned and process improvements

8. Business Continuity and Disaster Recovery

  • Automated database backups with point-in-time recovery capability
  • Geographically distributed redundancy to protect against regional outages
  • Documented disaster recovery procedures with defined recovery time objectives (RTO) and recovery point objectives (RPO)
  • Regular testing of backup restoration and failover procedures

9. Compliance and Standards

Our security practices are designed to align with the following frameworks and regulations:

  • GDPR: General Data Protection Regulation for the protection of EEA and UK residents' personal data
  • CCPA/CPRA: California Consumer Privacy Act and California Privacy Rights Act for California residents
  • SOC 2 Type II: Our infrastructure providers maintain SOC 2 Type II compliance for security, availability, and confidentiality
  • OWASP Top 10: Our application security practices address the OWASP Top 10 web application security risks

10. Limitation of Liability

While we implement commercially reasonable security measures, no system is completely immune to all threats. To the maximum extent permitted by applicable law, Tax Lens shall not be liable for any unauthorized access to, alteration of, or destruction of data resulting from: (a) factors beyond our reasonable control; (b) your failure to maintain the security of your account credentials; or (c) vulnerabilities in third-party software or services. Our total liability for security-related claims is subject to the limitations set forth in our Terms of Service.

11. Security Vulnerability Reporting

We encourage responsible disclosure of security vulnerabilities. If you discover a potential security issue affecting the Platform, please report it through our Contact page with the subject "Security Vulnerability Report." We commit to:

  • Acknowledging receipt of your report within 48 hours
  • Providing an initial assessment within 5 business days
  • Working in good faith to resolve confirmed vulnerabilities promptly
  • Not pursuing legal action against researchers who report vulnerabilities in good faith and in compliance with responsible disclosure practices

12. Updates to This Policy

We review and update this Security Policy periodically to reflect changes in our security practices, technology, and regulatory requirements. When we make material changes, we will update the "Effective Date" at the top of this page. We encourage you to review this Policy regularly.