Trust · Security

Secure & sovereign by design.

Taxmarc is built for the integrity tax teams demand: AI that runs on our own hardware and never trains on your data, single sign-on for every admin action, encryption on the wire, and ISO 27001-certified controls.
The four pillars

ISO 27001 certified

Independent auditors verify our security controls annually against ISO 27001, giving your compliance and legal teams documented assurance that Taxmarc meets the international standard for information security management.

Encrypted in transit

TLS to the browser and an encrypted WireGuard tunnel between the application and the AI hardware — plaintext never crosses the open internet.

Identity & access

Admin features sit behind Microsoft Entra ID single sign-on with server-side, role-based authorization checked on every request.

Sovereign AI

Prompts are processed on Taxmarc-owned GPU hardware, never sent to an external AI provider, and never used to train a model.

SAP-native security

Built inside SAP — your tax data never leaves your landscape.

  • Taxmarc is an SAP-certified indirect tax engine (add-on), certified for both SAP ECC and S/4HANA — built to SAP's own development principles and guidelines.
  • Tax determination runs natively inside your SAP system; all relevant indirect tax data is stored separately in the SAP database owned by you, so it never leaves your landscape for a per-transaction call to an external tax engine.
  • Access is governed by your existing SAP authorizations and segregation-of-duties roles — no separate identity store to provision or audit.
  • Changes ship through standard SAP transports (CTS), so every update is version-controlled, reviewable, and reversible under your change-control process.
  • Data residency follows your SAP landscape — on-premise, RISE with SAP, or cloud — with no new region or sub-processor introduced for determination.
  • Every determination is logged in SAP with its inputs and rationale, giving an audit-ready trail in your system of record.
Sovereign AI

Your data is never used to train a model — and never leaves Taxmarc.

  • The assistant runs against Taxmarc's own sovereign GPU; there is no call to OpenAI, Anthropic, Google, or any third-party model.
  • Prompts and replies are processed in memory for a single inference and are not persisted on the AI hardware.
  • Public visitors only ever receive Taxmarc's published product information — no internal or customer data is in scope for them.
Identity & access

Authenticated, role-based, and verified server-side.

  • Administrative areas require Microsoft Entra ID (Azure AD) single sign-on restricted to the @taxmarc.com domain.
  • Roles (admin / viewer) are derived from the signed session on the server — never trusted from the browser.
  • Every admin API independently re-checks the role before returning data (defense in depth).
Data protection

Encrypted in transit, minimized at rest.

  • HTTPS (Let's Encrypt) for all browser traffic; an encrypted Tailscale / WireGuard tunnel between the app and the AI compute.
  • Secrets (mail, API tokens) are stored server-side with restricted file permissions and are never exposed to the browser or the model.
  • Captured contact details are kept out of version control and masked before they enter any AI context.
Abuse prevention

Throttled, gated, and monitored.

  • Per-IP rate limiting on the public assistant and the contact form protects against automated abuse.
  • A hidden honeypot field silently drops bot submissions on the contact form.
  • Inputs are validated, and AI output is rendered as text — never as executable markup — so a crafted reply can't inject code into the page.
Compliance & data handling

Built around the principle of least data, well guarded.

Taxmarc handles indirect-tax data for SAP and other ERPs, so privacy and data protection are first-class concerns. Our platform is designed in line with GDPR principles — purpose limitation, data minimization, and access control. Due-diligence materials and details of our hosting and sub-processors are available to customers and prospects on request.

Frequently asked

Do you use my data to train AI models?

No. The assistant is inference-only on Taxmarc-owned hardware. Your prompts, messages, and any captured data are never used to train or fine-tune a model.

Where is the AI processed?

On Taxmarc's own sovereign GPU, reached over an encrypted private network. Nothing is sent to a third-party AI provider, and prompts are not persisted on the GPU.

How is access to admin features controlled?

Through Microsoft Entra ID single sign-on, limited to the @taxmarc.com domain, with role-based permissions enforced on the server for every request.

How is my contact information handled?

It's captured server-side with restricted permissions, kept out of source control, and forwarded to Taxmarc over a secure mail path. Personal identifiers are masked before they reach the assistant.

How do I report a security issue?

Email info@taxmarc.com with “Security” in the subject. We welcome responsible disclosure and will acknowledge legitimate reports.

Security questions?

We're happy to walk your team through our controls and answer due-diligence requests.

Get in touch →