Security
How TaxDesk protects your tax record.
A tax workspace holds sensitive records. This page states what protects them today, and what we are still working on.
Only the people you invite, with the role you give them.
Every request is signed in and checked against your workspace before a record is read or changed.
Checked on every request.
Sign-in runs through Clerk. Each request is then checked against your workspace membership and role before TaxDesk reads or changes anything.
Removal takes effect right away.
Workspace access isn’t cached, so removing someone stops their access on their next request.
Roles decide who can change records.
Viewing and changing are separate permissions. Changing a record needs a role with edit access and an active subscription.
Files stay private to the workspace.
Uploaded documents are never published. They download only through a signed-in, workspace-checked link.
Private storage.
Files are stored in a private Cloudflare R2 bucket with no public address.
Checked at upload.
An upload must be an allowed file type, with an extension and file signature that match, up to 50 MB.
Kept with their workspace.
Each file is filed under its workspace, and the download checks that you belong to it.
Encrypted, and clear about where it goes.
Connections are encrypted, stored data is encrypted by our providers, and the privacy policy lists every provider that processes it.
Encrypted in transit and at rest.
Connections use HTTPS. Our database provider (Neon) and file storage provider (Cloudflare R2) encrypt stored data.
Where it’s processed.
Our providers may process data outside Canada, including in the United States. We don’t promise Canadian-only storage.
Yours to take with you.
Org charts and ledgers export from the app, and a full export of your workspace is available on request.
AI proposes. People decide.
AI reads documents and answers questions, but it doesn’t change your tax record on its own.
Suggestions wait for a person.
Facts read from documents and other AI suggestions wait for someone on your team to apply them. A fact that conflicts with your record never overwrites it.
Analytics don’t see your content.
Product analytics record that an AI request happened, how long it took, and whether it worked. They don’t record prompts, documents, or answers.
Connected assistants act as you.
An assistant connected to TaxDesk signs in as you, with permissions you choose. Each change it makes is logged with the previous version and can be reversed.
Built on hardened, managed infrastructure.
TaxDesk runs on Cloudflare, with security headers, rate limits, and signed integrations.
Security headers.
A content security policy, HSTS, and frame and content-type protections apply to the app.
Signed integrations.
Payment and account events from Stripe and Clerk are accepted only with a valid signature.
Payment details stay with Stripe.
Card details are entered with and held by Stripe. TaxDesk never sees them.
Reviewed and recorded.
We review the code for security issues and keep a record of each finding and its fix.
Still to come
Independent testing, published here.
TaxDesk doesn’t hold a SOC 2 report yet. As independent security testing and certifications are completed, we’ll publish them on this page.
Report a concern
Found a security issue? Tell us.
Email hello@taxdesk.ca with “Security” in the subject. Describe the issue, but don’t send passwords or sensitive documents in the first message.