Security

How we protect your account and your data, the services we rely on, and how to report a problem.

Last updated: August 2026

Authentication & access

The MCP endpoint is protected by OAuth 2.0: your AI client connects with a scoped access token, and we validate the request origin to guard against DNS-rebinding. Dashboard accounts use email and password with required email verification, and logins are rate-limited. Passwords are hashed, and API keys are stored only as a hash. We never keep the plaintext key after it's shown to you once.

Your data

We store your account details and limited request metadata needed for billing, rate limits, security, and service analytics. For MCP calls, that metadata consists of the associated account, timestamp, tool called, and response time; it does not include MCP tool arguments or conversation history. Direct REST API usage records include the endpoint path, which may contain a requested public citation, section, publication, ruling, or case identifier. Traffic is encrypted in transit over TLS, and TaxMCP application data is encrypted at rest.

You can request deletion of your account data at any time. See our Privacy Policy for details.

Research questions & client data

taxmcp.io is a research service for retrieving public tax authority and does not require tax returns, source documents, or personally identifiable client information. TaxMCP sends search text to OpenAI's API to generate a search embedding. When semantic reranking is used, it also sends the search text and short excerpts and metadata from candidate authorities to OpenAI to order the results. TaxMCP does not persist MCP research-query text in its own application database or usage log.

OpenAI states that data sent through its API is not used to train models unless the API customer explicitly opts in. Under OpenAI's default controls, abuse-monitoring logs may retain customer content for up to 30 days; approved Modified Abuse Monitoring or Zero Data Retention controls may reduce that retention. See OpenAI's data-controls documentation.

taxmcp.io cannot control or make representations about information you enter elsewhere in Claude, ChatGPT, or another AI client. That information is handled under the provider, plan, settings, and agreements your firm selects. Use abstract or de-identified facts when appropriate, and follow your firm's approved data-handling procedures.

Services we rely on

We use OpenAI to generate search embeddings and, when enabled, rerank candidate results. We use Stripe for payments: card details go straight to Stripe, so we never see or store them. A small number of standard service providers handle email delivery and hosting, and the tax authority itself comes from public government sources.

Reporting a vulnerability

Found a security issue? Email security@taxmcp.io with steps to reproduce. We'll acknowledge it quickly and keep you posted as we fix it. A machine-readable contact lives at /.well-known/security.txt.

Please give us a reasonable window before disclosing publicly, and don't access data that isn't yours. We won't pursue legal action against good-faith research, and we're happy to credit you once the issue is resolved.