Taxza is built for firms that handle sensitive client data — CNICs, financial records and government-portal credentials. Access control and accountability are core to how the platform works, not add-ons. This page describes the security practices in place today.
How Taxza protects your firm’s data
Role-based access control
Every user sees only what their role permits. Staff work their assigned tasks and can look up portal credentials without ever seeing client financials.
Access-logged credential vault
Client portal usernames, passwords and PINs are stored with reveal, copy and visibility controls, and every access is recorded.
Full audit trail
Meaningful actions across clients, invoices, orders, tasks and credentials are logged and filterable, so you can always see who did what and when.
Verified client portal access
Clients log in with email verification and can see only their own invoices, orders, documents and tasks.
Locked accounting vouchers
Posted receipt, payment and expense vouchers lock, protecting the integrity of your books.
Local or AWS S3 storage
Documents are stored on local or AWS S3 cloud storage, with role-based access to what each user can open.
Separation of duties
Taxza is designed around least privilege. Agents, staff, supervisors, admins and clients each get a tailored experience, so people can do their work without being exposed to data they should not see — for example, staff using a stored credential to file a return without access to the client’s financials.
Accountability by design
Because meaningful actions are logged and posted vouchers lock, the record you keep is trustworthy. If a figure is questioned or a credential is used, the audit trail shows who was responsible and when — supporting internal reviews without relying on memory.
A note on certifications
Taxza does not currently claim formal certifications such as ISO 27001 or SOC 2. The practices described on this page reflect how the platform is genuinely built and operated. If your firm needs specific assurances, talk to us and we will tell you exactly what is and is not in place.
Responsible disclosure
If you believe you have found a security issue in Taxza, please email taxza@rascodex.com. We take reports seriously and will respond.
Security — questions & answers
No. Role-based access control means staff see only their assigned work and can look up portal credentials by CNIC or phone without ever seeing private financials — and every access is logged.
Yes. Every access to a stored client credential is recorded, so you always know who revealed or used it.
Not currently. Taxza does not claim formal certifications; the security page describes the practices genuinely in place. Contact us if your firm needs specific assurances.
Stop running your firm across ten disconnected tools
Run it on one platform that sells, invoices, assigns, collects and accounts — automatically. Start your free trial today.
Start Trial