User Guide

Security & Trust

TaxTrace is designed so that you never have to take our word for it. This page explains, in plain terms, exactly what the public product can and cannot do.

The short version

Key principles

What TaxTrace cannot do

The protections built in

ProtectionWhat it prevents
Read-only designAny path that would hold or move customer funds on the public product.
No trade executionUnexpected swaps, trade proposals, or signature requests.
No keys requiredSeed-phrase or private-key phishing surface for reporting.
No protocol tokenSurprise on-chain charges tied to a utility token.
Merkle anchors (Reporter)Silent alteration of a finalized report after export.
Basis-confidence labelsTreating uncertain cost basis as if it were oracle-attested.

Verifiability

Because report hashes are anchored on-chain by the Reporter, your records are independently verifiable — see Verifying Your Reports.

Responsible disclosure

Found a security issue? Please report it responsibly via the contact in our security.txt rather than opening a public issue.