Trust centre
Security at TaxReady
Last updated September 25, 2026
Financial records need confidentiality, integrity and a reliable way back after failure. TaxReady builds those requirements into the bookkeeping workflow and its operations.
Access
Every person has an individual account. Passwords are one-way hashed, sessions use opaque tokens in secure cookies, and sign-in attempts are rate limited.
Separation
Every organization-owned query is authorized on the server. Roles limit who can post, change settings, control periods or delete an organization.
Book integrity
Posted journals must balance. Posted entries are immutable and corrections preserve linked reversals. Control-account subledgers are checked against the ledger.
Recovery
Owners can export complete organization backups. Production operations support encrypted database backups and restore drills.
Traceability
Material bookkeeping and access changes create audit records with the actor and UTC time. Operational failures receive lookup references.
Data minimization
Bank credentials are never requested. CSV, spreadsheet and PDF files are parsed in the browser rather than uploaded as source documents.
Reporting a security concern
Email hello@taxreadybooks.ca with a description and a safe way to reproduce the issue. Do not include passwords, bank credentials, live payroll details or another person’s financial records.