Skip to content
Trust

Security program & incident reporting

NEXACC LLC is an IRS Authorized e-file Provider (EFIN 868369). The controls below are the ones the IRS asks online providers to certify each year, stated plainly so clients, partners, and the IRS can see exactly what is in place. Supporting documentation — the written Information Security Plan, scan reports, and incident records — is available on request.

Extended Validation SSL Certificate

Encrypted transport on every page

www.nexacc.com is served exclusively over HTTPS with a valid, publicly trusted TLS certificate covering the apex and www hosts. HTTP requests are redirected to HTTPS, certificates renew automatically before expiry, and the site is monitored for certificate validity. Form submissions, file uploads, and the client onboarding flow are never transmitted in the clear. Certificate details are verifiable in any browser via the padlock, or through a public certificate-transparency lookup for nexacc.com.

External vulnerability scan

Recurring external scanning

Our public web properties are scanned for external vulnerabilities on a recurring schedule and after significant releases. Scanning covers TLS configuration, exposed services, common web application weaknesses, and dependency-level vulnerabilities in the application's software bill of materials. Findings are triaged by severity, remediated, and re-tested; critical items are treated as same-day work. Scan reports and remediation records are retained and available to the IRS on request. Most recent scan: 2026-08-31 — 0 open high or critical findings.

Information privacy and safeguard policies

Written Information Security Plan

NEXACC maintains a written Information Security Plan built on IRS Publication 4557, IRS Publication 1345, and the FTC Safeguards Rule, with a named security lead, an annual risk assessment, least-privilege access with multi-factor authentication, encryption in transit and at rest, row-level database access controls, vendor due-diligence terms, secure disposal procedures, and annual staff security training. Our public-facing privacy commitments, including IRC §7216 handling of tax return information and HIPAA Business Associate obligations, are published on the privacy page.

Read the Privacy & Safeguards Policy

Web site challenge-response test

Challenge-response on public forms

Every public form that collects contact details — contact, estimator, scheduling, and onboarding entry — requires a challenge-response test that a human can complete and an automated script cannot trivially pass. The challenge is accessible: it uses plain text, works with a screen reader and keyboard only, and requires no image recognition. It is paired with silent bot traps (also used on the single-field newsletter signup) and server-side validation, and repeated failures are rejected before any data is stored or emailed.

Public domain name registration

Publicly registered domain

nexacc.com is registered through GoDaddy.com, LLC and its registration data is publicly viewable through ICANN's registration data lookup: registrar, creation date (2021-08-21), expiry (2027-08-21), registry status codes, and authoritative name servers. Registrant contact details are currently served through the registrar's privacy service; we are switching that off so the registrant organization publishes as NEXACC LLC. Ownership is independently confirmable today through this site's published business details, EFIN listing, and BBB profile.

Look up nexacc.com in ICANN registration data

Security incidents reporting

Incident response and reporting

We maintain a documented incident response procedure: detect and contain, assess scope, preserve evidence, notify, remediate, and complete a written post-incident review. Any confirmed or suspected incident involving taxpayer data is reported to the IRS Stakeholder Liaison and, where applicable, to the appropriate IRS e-Help Desk, the FTC, state tax agencies, state attorneys general, and affected clients — within the timeframes those authorities require and without delay. HIPAA-covered incidents follow Breach Notification Rule timelines under our Business Associate Agreements.

Report a security incident

If you believe client data, taxpayer data, or a NEXACC account has been exposed, phished, or misused, tell us immediately. Reports are welcome from clients, partners, staff, and independent security researchers.

  1. 1Email info@nexacc.com with the subject line "SECURITY INCIDENT" or call +1 (443) 739-9197. Include what you observed, when, and any affected accounts or files.
  2. 2We acknowledge every report within one business day and open a tracked incident record immediately.
  3. 3We contain, investigate, and determine whether taxpayer data or protected health information was involved.
  4. 4Where taxpayer data is involved, we notify the IRS Stakeholder Liaison and other required authorities, and we notify affected clients directly.
  5. 5We deliver a written summary of cause, impact, and corrective action to affected clients once the incident is closed.

Taxpayers who suspect tax-related identity theft should also contact the IRS directly and review IRS Publication 4557 and the IRS Identity Theft Central guidance. Do not include Social Security numbers, bank credentials, or protected health information in your report.

Text us on WhatsApp
TextInstagram