Security
How Certifitax protects the data it holds
A tax certificate carries a name, a Tax Identification Number, and an income figure. Everything below describes what is actually in place to protect that data. Each statement is also made, in fuller form, in our Data Privacy Policy, which governs.
Encryption
Data moving to and from the platform is encrypted in transit using transport layer security. Data stored by the platform, including every issued certificate, is encrypted at rest. Account passwords are stored only in hashed form and cannot be recovered by Medtax personnel.
Where data is stored
The platform runs on Amazon Web Services, which stores data on our instruction and may not use it for any purpose of its own. The region in use is published on our Service Providers page and updated when it changes. AWS stores the platform's data. Two other services support it: an email delivery service that sends your messages, and Anthropic, which answers the help chat.
Who can see a certificate
The organization that issued it and the person named on it. Certificates are not visible to other organizations on the platform, and Medtax personnel access is restricted to what operating the service requires. Certificates are retained for five years in restricted access, in line with Section 235 of the Tax Code, as amended by the Ease of Paying Taxes Act (Republic Act 11976), and are released only to those two parties or as required by law.
No trackers
The platform sets only the cookies it needs to function: a session cookie and cross-site request forgery protection. There are no advertising, analytics, or third-party tracking scripts, and we do not track users across other websites.
Testing without your data
We do not use real user data to test, develop, or study our systems. Development and testing run on generated seed data. Production records are not copied into staging or development environments.
If something goes wrong
In the event of a personal data breach affecting the platform, Medtax notifies the affected organization without undue delay so it can meet its own obligations, and notifies the National Privacy Commission and affected individuals within the period the Commission prescribes where required. We contain, assess, and mitigate first, and tell you what happened.
Report a security issue
If you believe you have found a vulnerability in Certifitax, write to security@certifi.tax. Include what you found and how to reproduce it. We will acknowledge your report and keep you informed until it is resolved. Please do not access, alter, or retain data that is not yours while investigating.
Data protection questions
Questions about how personal data is handled, or requests to exercise your rights under the Data Privacy Act of 2012, go to our Data Protection Officer at dpo@certifi.tax.
Certifitax does not hold a third-party security certification, and this page does not claim one. What is described here is what is in place.