Security

At Taxly, security is not an afterthought — it's built into every layer of our platform. We understand that you're trusting us with sensitive financial data, government portal credentials, and personal documents. Here's exactly how we protect them.

✓ Encrypted at Rest ✓ Encrypted in Transit ✓ Tenant Isolated ✓ KMS Credential Protection ✓ WAF Protected

Overview

🔒

Encryption at Rest

All data stored in our databases and file storage is encrypted using AES-256 encryption with AWS-managed keys. Your TaxProMax credentials receive additional KMS encryption with per-user context.

🔐

Encryption in Transit

All connections use TLS 1.2 or higher. HTTPS is enforced on every endpoint. HTTP Strict Transport Security (HSTS) prevents downgrade attacks.

🛡

Data Isolation

Each user's data is isolated at the infrastructure level using IAM-enforced partition keys. Even if application code had a bug, the cloud infrastructure physically prevents cross-user data access.

💪

Access Control

Every API request is authenticated via Cognito JWT tokens. Authorisation is enforced by AWS STS-scoped credentials that restrict each session to the user's own data partition.

Credential Protection

When you provide your TaxProMax username and password, we take extra precautions:

Infrastructure Security

Application Security

Authentication & Access

Data Isolation Architecture

Taxly uses a single-table DynamoDB design with IAM-enforced tenant isolation:

Monitoring & Incident Response

Compliance

Responsible Disclosure

If you discover a security vulnerability in Taxly, we encourage responsible disclosure. Please report it to:

We ask that you:

We commit to acknowledging your report within 48 hours and providing a resolution timeline within 7 days.

Questions

For security-related questions or concerns, contact us at security@taxlytech.com.