Skip to main content

Security Disclosure Policy

Last updated: August 2026

Report a potential issue

If you believe you found a security vulnerability affecting https://www.monacocpa.cpa, email taxhelp@monacocpa.cpa with the affected URL, a concise description, and reproducible steps. Do not include tax returns, Social Security numbers, passwords, API keys, client records, or other sensitive information in your report.

Good-faith testing

Limit testing to what is necessary to demonstrate a potential issue. Do not access, alter, retain, or disclose another person's data; interrupt service; use automated high-volume testing; or attempt to bypass authentication or payment controls. We may ask for additional details to understand a report. Submitting a report does not create a CPA-client relationship, engagement, or promise of a particular response or outcome.

Scope and routing

This policy covers this website and its first-party web endpoints. It does not grant permission to test third-party services, client portals, vendors, or any system you do not own. For a client-service or accessibility issue, use the written contact form or email taxhelp@MonacoCPA.CPA; do not use a security report to submit client data.

Machine-readable policy

The machine-readable disclosure file is available at https://www.monacocpa.cpa/.well-known/security.txt. It is scheduled for review before 2027-08-07.