Security Disclosure Policy
Last updated: August 2026
Report a potential issue
If you believe you found a security vulnerability affecting https://www.monacocpa.cpa, email taxhelp@monacocpa.cpa with the affected URL, a concise description, and reproducible steps. Do not include tax returns, Social Security numbers, passwords, API keys, client records, or other sensitive information in your report.
Good-faith testing
Limit testing to what is necessary to demonstrate a potential issue. Do not access, alter, retain, or disclose another person's data; interrupt service; use automated high-volume testing; or attempt to bypass authentication or payment controls. We may ask for additional details to understand a report. Submitting a report does not create a CPA-client relationship, engagement, or promise of a particular response or outcome.
Scope and routing
This policy covers this website and its first-party web endpoints. It does not grant permission to test third-party services, client portals, vendors, or any system you do not own. For a client-service or accessibility issue, use the written contact form or email taxhelp@MonacoCPA.CPA; do not use a security report to submit client data.
Machine-readable policy
The machine-readable disclosure file is available at https://www.monacocpa.cpa/.well-known/security.txt. It is scheduled for review before 2027-08-07.