Trust · Security

Secure & sovereign by design.

Taxmarc is built for the integrity tax teams demand: single sign-on for every admin action, encryption on the wire, and an information security management system built on ISO 27001.
The three pillars

ISO 27001-security controls

Taxmarc has implemented an information security management system (ISMS) built on the ISO 27001 framework. We follow its controls and processes across our organization in alignment with SAP-ISO 27001 practices. This gives your compliance and legal teams visibility into a structured, internationally recognized approach to information security.

Encrypted in transit

TLS to the browser, and encrypted transport on every connection the application makes.

Identity & access

Admin features sit behind Microsoft Entra ID single sign-on with server-side, role-based authorization checked on every request.

SAP-native security

Built inside SAP: your tax data stays in your SAP landscape.

  • Taxmarc is an SAP-certified indirect tax engine (add-on), certified for both SAP ECC and S/4HANA, built to SAP's own development principles and guidelines. Our latest developments are all based on clean-core principles.
  • Tax determination runs natively inside your SAP system; all relevant indirect tax data is stored separately in the SAP database owned by you, so it stays within your landscape rather than being sent out for a per-transaction call to an external tax engine.
  • Access is governed by your existing SAP authorizations and segregation-of-duties roles; no separate identity store to provision or audit.
  • Changes ship through standard SAP transports (CTS), so every update is version-controlled, reviewable, and reversible under your change-control process.
  • Data residency follows your SAP landscape, on-premise, RISE with SAP, or private cloud,  with no new region or sub-processor introduced for determination. SAP BTP/BAIP deployment is available for Taxmarc Core.
  • Every determination is logged in SAP with its inputs and rationale, giving an audit-ready trail in your system of record.
Identity & access

Authenticated, role-based, and verified server-side.

  • Administrative areas require Microsoft Entra ID (Azure AD) single sign-on restricted to the @taxmarc.com domain.
  • Roles (admin / viewer) are derived from the signed session on the server — never trusted from the browser.
  • Every admin API independently re-checks the role before returning data (defense in depth).
Data protection

Encrypted in transit, controlled at rest.

  • HTTPS (Let's Encrypt) for all browser traffic, and encrypted transport on every outbound connection the application makes.
  • Secrets (mail, API tokens) are stored server-side with restricted file permissions and are never exposed to the browser or the model.
  • Captured contact details are kept out of version control and masked before they are analysed.
Abuse prevention

Gated and monitored.

  • Per-IP rate limiting on the public assistant and the contact form protects against automated abuse.
  • A hidden honeypot field silently drops bot submissions on the contact form.
  • Inputs are validated, and AI output is rendered as text,  never as executable markup. A reply can not inject code into the page.
Compliance & data handling

Built around the principle of least data, well guarded.

Taxmarc handles indirect-tax data for SAP and other ERPs, so privacy and data protection are first-class concerns. Our platform is designed in line with GDPR principles — purpose limitation, data minimization, and access control. Due-diligence materials and details of our hosting and sub-processors are available to customers and prospects on request.

Frequently asked

How is access to admin features controlled?

Through Microsoft Entra ID single sign-on, limited to the @taxmarc.com domain, with role-based permissions enforced on the server for every request.

How is my contact information handled?

It's captured server-side with restricted permissions, kept out of source control, and forwarded to Taxmarc over a secure mail path. Personal identifiers are masked before they reach the assistant.

How do I report a security issue?

Email info@taxmarc.com with “Security” in the subject. We welcome responsible disclosure and will acknowledge legitimate reports.

Security questions?

We're happy to walk your team through our controls and answer due-diligence requests.

Get in touch →
Security · Taxmarc