Security Disclosure Policy

DeterminedVAT, operated by DeterminedAI, LLC (a Delaware limited liability company), processes tax data on behalf of businesses. Reporting a security issue privately, before disclosing it publicly, helps us protect those customers.

How to report a vulnerability

Email security@determinedai.co with:

You should receive an acknowledgement within 2 business days.

What we ask of reporters

Researchers acting in good faith and within the bounds above will not be pursued legally, and we will publicly credit you (with permission) once the issue is remediated.

What's in scope

What's out of scope

Security incident response process

DeterminedVAT follows the timeline below for any confirmed or strongly-suspected security incident affecting customer or personal data.

Breach contact for regulators

Phase 0: Detection (T+0)

Phase 1: Containment (T+0 to T+4 hours)

Phase 2: Scope assessment (T+4 to T+24 hours)

Phase 3: Regulator notification (T+24 to T+72 hours)

Phase 4: Customer notification (T+72 hours onward)

Phase 5: Root cause and remediation

Drills

Contact