Install Monetraxapp
Add to home screen for quick access
Add to your home screen for quick access and offline support
Report vulnerabilities and learn about our security practices
If you discover a security vulnerability in Monetraxapp, please report it responsibly. We take all security reports seriously and will respond promptly.
Security Contact
security@monetraxapp.comFor urgent security issues, include "URGENT" in the subject line.
We ask that security researchers follow these guidelines:
In the event of a data breach, we follow a structured incident response process:
Detection & Assessment
Automated monitoring and manual review to identify and classify the incident.
Containment
Isolate affected systems, revoke compromised credentials, and prevent further damage.
Notification
Notify HMRC and the ICO within 72 hours. Notify affected users without undue delay.
Remediation
Patch the vulnerability, restore systems, and verify data integrity.
Post-Incident Review
Document lessons learned and update security controls.
Encryption at Rest
All sensitive data (passwords, API tokens, tax identifiers) encrypted using Fernet/AES and bcrypt
Encryption in Transit
All connections secured with TLS 1.2+ (HTTPS enforced)
Access Control
Role-based access control with least-privilege principle. All admin access audited.
Multi-Factor Authentication
Email OTP, WhatsApp OTP, and Trusted Device verification
Session Security
Cryptographic session tokens with automatic expiry and IP tracking
Data Isolation
Complete per-user data isolation. No cross-tenant data access.
Fraud Prevention
HMRC-compliant fraud prevention headers on all tax API interactions
Regular Audits
Quarterly security assessments and dependency vulnerability scanning