Security & trust

Confidential until publication. Accountable after.

An annual report is strictly confidential until the moment it is published — and has to be accountable down to the figure afterwards. Taxxor Disclosure Manager is built for that: ISO 27001-certified, a choice of shared, dedicated or on-premise hosting, access control down to section level and a full audit trail.

ISO 27001-certified

Three hosting models: SaaS, dedicated or on-premise. SSO via the organisation’s own identity provider, granular access, a full audit trail and data lineage.

Full security documentation on request under NDA.

The security reviewer’s questions, answered

The standard questions from a vendor assessment, answered directly. Where an answer requires documentation, it says which — and how to get it.

Where does the data live?

That depends on the hosting model. In the shared SaaS environment, the platform runs in AWS data centres in Frankfurt, Germany — the data stays inside the EU. A dedicated environment runs isolated from other customers. With on-premise, the data never leaves the organisation’s own network.

Who can access it, and how is that managed?

Sign-in runs through single sign-on against the organisation’s own identity provider: accounts are created and revoked in its own directory, not in a separate user list at a vendor. Inside the platform, access is configurable per project, per output channel and per section.

Is the data encrypted?

Yes, both ways. In transit: TLS 1.2 as the minimum, with TLS 1.3 where the client supports it; an unencrypted connection is redirected to HTTPS. At rest: AES-256 — the volumes holding the application and the reporting data are encrypted through AWS KMS, and object storage is encrypted by default. The full description, including key management, is in the security documentation shared under NDA.

What is logged?

Every change to the report: what was changed, by whom and when, down to section level. In addition, data-lineage reports connect every figure in the XBRL output to its source — recorded for the audit, not just for the security review.

Which subprocessors are involved?

Two, both named in the data processing agreement: Amazon Web Services (hosting, Frankfurt — inside the EU) and Microsoft Office 365. No new subprocessor is engaged without the client’s prior written consent, so the list does not change without the client knowing.

What happens to the data when the contract ends?

The client chooses. At the end of the agreement all personal data is either deleted, or returned in a generally readable and properly documented file format. Until that choice is made the data stays put — Taxxor deletes nothing without an explicit instruction. The only exception is data that law requires be kept. That is the standard from the data processing agreement; other arrangements are possible by agreement.

Is the platform tested for vulnerabilities?

Yes — continuously in-house, and additionally by an independent third party. Automated scanning with OWASP ZAP runs inside the development process: passive scans at set points and periodically an active scan with simulated attacks. On top of that, Taxxor DM is assessed by an independent, qualified party, including penetration testing. Those reports are available on request to clients and prospects. A customer-initiated penetration test is welcome too: scheduled by agreement and run in two rounds, so findings can be fixed in between. Findings are scored with CVSS; severity sets the priority, with critical findings taking precedence over other work. Reports from outside fall under the responsible disclosure policy.

Documentation for the review

  • Available under NDA: the ISO 27001 certificate with its Statement of Applicability, the security documentation (architecture, encryption, subprocessors), the data processing agreement, and the reports from the security scans and the independent technical security assessment.
  • A security questionnaire in the organisation’s own format is completed too.
  • Deliberately no standard turnaround time: it would be a promise that does not hold at the busiest end of the year. What does stand: questions land with the people who build the platform, not in a ticket queue.

Built in, not bolted on

  • SSO via the organisation’s own identity provider

    Authentication runs through the organisation’s own IdP; account management — creation, changes, revocation — stays in its own directory. Supported: Microsoft Entra ID, Google Workspace, SAML 2.0 and OAuth 2.0 / OpenID Connect — in practice any identity provider that speaks SAML 2.0 or OpenID Connect.

  • Granular access control

    Permissions per project, per output channel and per section. A reviewer who needs to read one chapter sees exactly that chapter.

  • Audit trail

    Every change recorded: what, who, when — viewable per section, and exportable as track-changes output for review rounds.

  • Data lineage

    Reports that connect every figure in the XBRL output to its source data. The auditor sees where each figure comes from — which saves tracing work during the audit.

Hosting is a choice, not a given

Which environment is acceptable differs per organisation — and sometimes per regulator. That is why hosting for Taxxor DM is a choice of three models, not a workaround.

  • SaaS — shared

    The standard model: start fast on Taxxor’s shared environment — AWS Frankfurt, Germany, inside the EU.

  • SaaS — dedicated

    A separate, isolated environment — for organisations that require isolation from other customers, without having to host it themselves.

  • On-premise

    The full platform on the organisation’s own infrastructure, with reporting data never leaving its own network — an option that is rare in disclosure management, and for some organisations the only viable one.

All three models run the same application: the hosting choice determines where it runs, not what it can do.

Certifications & listings

ISO 27001 — certified information security management system against NEN-EN-ISO/IEC 27001:2023/A1:2024, certified by DigiTrust B.V. under accreditation of the Dutch Accreditation Council (RvA). Scope: information security related to the development, sales, implementation and support of reporting software solutions.

KvK Groot — listed as a provider in the XBRL Nederland overview, supporting all five NBA Alert 50 scenarios (A: ESEF, B: SBR instance direct, C: SBR instance conversion, D: SBR Report Package conversion, E: SBR Report Package direct). View the listing at XBRL Nederland

  • Member of XBRL Nederland
  • Active in XBRL International

Start the assessment

  1. Request the documentation — under NDA, including the ISO 27001 certificate.
  2. See the platform in a demo — with the IT reviewer at the table.
  3. Pick the hosting model that fits: shared, dedicated or on-premise.