Security

Your data, protected.

TaxSignal connects to your financial accounts, so security isn't a feature — it's the foundation. Here's exactly how we protect your data.

Read-only by design

We only ever request read-only access. TaxSignal can never move money, make payments, submit anything without your approval, or alter your books. Our permissions don't allow it.

Encryption, everywhere

In transit: all data over TLS. At rest: data encrypted in our database; connection tokens encrypted separately with Supabase Vault, never in plain text, never exposed to your browser, decrypted only server-side during a sync.

Hosted in the UK

Stored in a UK (London) data centre on Supabase infrastructure (built on AWS); your data doesn't leave UK/EU jurisdiction for storage.

Never sold, never used to train AI

We never sell your data or share it for marketing. Figures are analysed via Anthropic and OpenAI commercial APIs; under those terms your data is not used to train their models.

Sub-processors

To run TaxSignal we use a small number of trusted providers, sharing only what's needed:

Supabase
Database & hosting (UK)
Anthropic & OpenAI
AI analysis — not used to train their models
Resend
Email delivery
Xero / accounting software
Read-only source you authorise

You're in control

Disconnect any time. You can request a full export or permanent deletion of your data whenever you want — contact security@taxsignal.co.uk or hello@taxsignal.co.uk.

Responsible disclosure

Found a security issue? Email security@taxsignal.co.uk — we take every report seriously.

TaxSignal provides informational tax analysis based on HMRC guidance and is not regulated financial advice. Last updated 7 July 2026.