Security

Your sales data and tax credentials, protected by design.

Encryption in transit and at rest, an immutable audit trail, and a filing flow where nothing is ever submitted without your approval. This page describes what is in place today; planned work is listed separately in the roadmap.

TLS
Encryption at rest
Immutable audit trail
Approval before filing
What's in production today

How we protect your business

🔐

Encryption

  • All traffic to salestax50.com and the app uses HTTPS / TLS.
  • Sensitive fields are encrypted at rest with AES-256-GCM before they reach the database: state portal logins, sales-channel API tokens, Federal Tax ID (EIN), and the state tax remittance account you provide for AutoFile.
  • Passwords are stored only as salted one-way hashes; SalesTax50 staff cannot read them.
  • After you save them, EIN and bank details are masked in the app and never shown again in full.
👤

Access control

  • Customer accounts use owner / member / accountant roles; only owners can change channels, states, payment details or approve a return.
  • Two-factor authentication (TOTP with backup codes) is available for customer accounts.
  • Access to administrative systems is restricted by role and authorization, with least-privilege access controls applied to internal operations.
  • State portal credentials are decrypted only when required for an authorized filing operation, and every credential access is recorded in the audit trail.
📜

Audit trail

  • Important account, filing, credential and billing actions are recorded in an append-only audit trail — entries are never edited, and are retained in line with our data-retention policy.
  • You can review the relevant activity for your own organization from the app at any time.

Nothing filed without your approval

  • AutoFile prepares each return; a human at your company must approve it before anything is submitted — every time, for every period.
  • Each approval is stored as an immutable snapshot: the exact figures you saw, the data-through timestamp, approving user, IP and device, and the Terms version in force.
  • Every completed filing keeps the portal confirmation number and receipt PDF on record, downloadable from the app.
🏦

We never hold your money

  • State tax payments are drawn by the taxing authority directly from the remittance account you designate — SalesTax50 never takes custody of tax funds.
  • SalesTax50 fees are collected through a PCI-compliant payment processor (CSG Forte); card and bank details for our fees are tokenized by the processor, and we keep only the token and last four digits.
🔌

Read-only, minimal data

  • Connected sales channels are accessed read-only where the platform supports it: orders, refunds and marketplace-collected tax. We never change products, customers, checkout, payouts or store settings.
  • We import only what a sales tax return needs. Buyer payment-card numbers are never requested; card security codes are never stored.
  • You can unlink any channel, remove the remittance account, or replace credentials at any time from Settings.
🛠

Secure development

  • We use code review, automated security checks, secure session controls and protected configuration practices as part of our development and deployment process.
  • If we learn of a security incident affecting your data, we investigate it and notify affected customers as required by applicable law.
🧾

Records & retention

  • Imported transactions are kept per import job (removable and restorable by you), and filing receipts and approval snapshots are retained so that any filed return can be reconstructed and re-checked later.
  • Backups are currently maintained as part of our hosting operations. Daily encrypted off-site backups and scheduled restore testing are planned before public launch.
  • Support-ticket attachments are limited by type and size, and you are asked never to send passwords, MFA codes, SSNs or bank details through support.

Your part

  • Enable two-factor authentication (Settings → Security).
  • Don't share passwords — give teammates and accountants their own logins with the right role.
  • Remove former users promptly; update a state portal password in Settings → States & permits if it changes.
  • Don't send passwords, MFA codes, SSNs or bank details through support tickets or email.

Report a vulnerability

If you believe you've found a security issue in SalesTax50, email security@salestax50.com with steps to reproduce. We acknowledge reports within two business days, keep you informed while we fix, and don't pursue good-faith researchers who avoid privacy violations, data destruction and service disruption.

For account or filing questions use Support instead — it reaches the filing team faster.

Security Roadmap

What's next

Independent penetration testing

Before public launch

Dedicated infrastructure and enhanced network protection

Before public launch

SOC 2 program

After launch

This page is a plain-language description of current practice and is updated as controls change. The binding terms are in the Security Notice, Privacy Policy and Data Processing Addendum, which form part of the Terms of Service. Last updated August 18, 2026.

See it for yourself.

Free nexus check · no credit card · nothing filed without your approval
Check My Nexus — Free