Back to FiscEdge
    Last updated: April 11, 2026
    Legal Documents

    Security

    We take the security of your data seriously. This page provides transparency into how FiscEdge approaches platform security, data protection, and your account safety.

    Effective date: April 11, 2026Last updated: April 11, 2026

    Security Overview

    Protecting your personal and business data is a core responsibility we take seriously at FiscEdge. We have implemented technical and organisational measures designed to safeguard your information against unauthorised access, disclosure, alteration, and destruction.

    This page provides a transparent, high-level overview of our security practices. It is intended to give you the information you need to understand how your data is protected — without overstating or misrepresenting our security posture.

    Security is a continuous effort. We regularly review and improve our practices as the threat landscape and industry standards evolve.

    Infrastructure and Hosting

    FiscEdge is hosted on industry-standard cloud infrastructure. We rely on established, reputable cloud and infrastructure providers that maintain their own rigorous security certifications and controls.

    • Our platform is hosted in data centres with physical access controls, redundancy, and availability guarantees
    • We leverage managed cloud services that are designed for reliability, scalability, and security
    • Infrastructure is isolated and access is restricted to authorised personnel only
    • Regular infrastructure maintenance and patching is performed to address known vulnerabilities

    Note: We do not publish specific infrastructure provider names in this public document. This information is available to enterprise clients under NDA on request.

    Data Protection Approach

    We apply a data minimisation approach — we collect only the data necessary to provide our Services. We have structured our internal data handling to reduce unnecessary exposure of personal information.

    • Data is categorised by sensitivity and handled according to its classification
    • Access to user data by internal team members is restricted to those with a legitimate operational need
    • User data is logically separated to prevent cross-account access
    • Data deletion processes are in place to honour user requests and our retention policy

    Encryption

    Data in Transit

    All data transmitted between your browser and the FiscEdge platform is encrypted using Transport Layer Security (TLS). We enforce HTTPS across all platform endpoints. Connections using outdated or insecure protocols are rejected.

    Data at Rest

    Data stored on our platform infrastructure is protected at rest using encryption mechanisms provided by our cloud infrastructure provider. Encryption at rest is applied to databases and storage volumes containing user data.

    Passwords

    User passwords are never stored in plain text. We use modern, industry-standard hashing algorithms (with appropriate salting) to store credentials securely.

    Access Controls

    We maintain strict access control policies governing who can access platform systems, data, and infrastructure:

    • Access to production systems is restricted to authorised engineering and operations personnel
    • Role-based access control (RBAC) is applied to limit access based on operational need
    • Access privileges are reviewed regularly and revoked promptly when no longer required
    • Administrative access requires additional authentication factors
    • All access to sensitive systems is logged for audit purposes

    Authentication and Account Protection

    We implement the following measures to protect user accounts:

    • Secure session management with automatic expiry after inactivity
    • CSRF (Cross-Site Request Forgery) protection on all sensitive operations
    • Rate limiting on authentication endpoints to mitigate brute-force attacks
    • Email verification required for new account registration
    • Secure password reset flows using time-limited, single-use tokens

    Your Role in Account Security

    You are responsible for protecting access to your FiscEdge account. We recommend:

    • Using a strong, unique password for your FiscEdge account
    • Not sharing your login credentials with others
    • Logging out of the platform when using shared or public devices
    • Contacting us immediately if you suspect unauthorised access

    Monitoring and Incident Response

    We maintain logging and monitoring systems to detect anomalous behaviour, security events, and platform errors. Our approach includes:

    • Logging of access and key operations across platform systems
    • Alerting on patterns that may indicate security threats or abuse
    • An internal incident response process for identifying, containing, and remediating security events
    • Notification procedures for affected users in the event of a data breach, in accordance with applicable law

    In the event of a security incident that affects your data, we will notify you within the timeframes required by applicable law and take appropriate steps to mitigate harm.

    Third-Party Subprocessors and Infrastructure

    We rely on third-party service providers to deliver parts of our platform infrastructure, including hosting, database management, email delivery, AI processing, and analytics. These subprocessors are selected for their security standards and are contractually obligated to protect data processed on our behalf.

    We maintain a list of key subprocessors. Enterprise clients may request details of our subprocessor relationships under a data processing agreement.

    Responsible Disclosure / Vulnerability Reporting

    We welcome responsible disclosure of security vulnerabilities. If you believe you have discovered a security issue in the FiscEdge platform, please report it to us as soon as possible.

    • Email: security@fiscedge.com
    • Please provide a clear description of the issue, steps to reproduce, and potential impact
    • Do not attempt to access other users' accounts or data as part of your research
    • Do not disclose the vulnerability publicly before we have had a reasonable opportunity to investigate and remediate

    We will acknowledge valid reports and work with you in good faith to understand and address the issue. We do not currently operate a formal bug bounty programme, but we value responsible disclosure and will recognise significant contributions at our discretion.

    Shared Responsibility Model

    Security is a shared responsibility. While FiscEdge works to protect platform infrastructure and our systems, users also play a critical role:

    FiscEdge is responsible for:

    • Securing platform infrastructure, code, and data storage
    • Maintaining encryption and access controls
    • Monitoring for threats and responding to incidents
    • Keeping dependencies and infrastructure up to date

    You are responsible for:

    • Securing your account credentials and not sharing them
    • Ensuring that data you input is appropriately authorised by you
    • Using the platform on secure networks and devices
    • Reporting suspicious activity or potential vulnerabilities to us

    Security Updates and Page Changes

    This page is updated periodically to reflect changes in our security practices, tooling, or policies. The "Last Updated" date at the top indicates when this page was last revised.

    We do not guarantee that all information herein is current at any given moment, but we commit to reviewing and updating this page at least annually or following material changes to our security posture.

    Contact Us

    For security-related matters, please reach us at:

    • Security vulnerabilities: security@fiscedge.com
    • General security questions: info@fiscedge.com
    • Data protection inquiries: privacy@fiscedge.com
    • Address: [Registered Address]

    We use cookies

    We use essential cookies to operate the platform and optional cookies to improve your experience and analyse usage. You can customise your preferences or read our Cookie Policy.