Security & Trust

Last updated: July 28, 2026 · Operated by Call The IT Dude LLC (d/b/a Sefro)
Trust documents: Data Processing Addendum Data Accuracy System Status Privacy Terms

Sefro provides U.S. sales-tax rate and calculation data over an API. We hold very little personal data — no payment cards, and only what a customer sends us (addresses on lookups, and buyer name/email/EIN on exemption certificates). This page describes how we protect it and how to report a security issue.

Compliance status

Sefro is not yet SOC 2 certified. We build and operate to the SOC 2 Trust Services Criteria (security, availability, confidentiality) and can share our security documentation — this policy, our DPA, and our incident-response plan — with enterprise customers under NDA during procurement. A formal third-party audit is on our roadmap; we will publish the report here when it is complete.

Data protection

Application & infrastructure security

Subprocessors

We use a small, U.S.-based set of subprocessors. We give notice of changes and allow a reasonable objection period (see the DPA).

SubprocessorPurposeLocation
RailwayApplication hosting & managed PostgreSQLUnited States
StripePayment processingUnited States
CloudflareDNS, WAF & edge networkGlobal (US-operated)

Incident response

We maintain a documented incident-response process — detect, contain, eradicate, recover, review — with defined severity levels. For any incident involving personal data, we notify affected customers without undue delay and within any legally required window, as described in our DPA.

Reporting a vulnerability

Email [email protected] with a description of the issue and its impact, steps to reproduce, and the affected endpoint(s). Please do not open a public issue, and do not run automated scanners against production beyond what is needed to demonstrate a finding. We aim to acknowledge reports within 2 business days and to provide a remediation timeline after triage. We are glad to credit reporters once a fix has shipped.

← Back to Sefro