Skip to Content

Radar Fiscal / Security

Security at Radar Fiscal

Your CFDIs, your e.firma and your tax filings are sensitive. Here is what we do to protect them, with no fine print, and what you can do too.

Your e.firma, encrypted

It is never displayed and cannot be downloaded from the portal.

Three strikes

The account waits 15 minutes and we email you.

Two-step verification

A code from your phone, on top of your password.

Every sign-in, visible

Including those of our support team.

Your data, kept apart

Every week we check that nobody can see another company's data.

Everything travels encrypted

The portal only works over HTTPS.

Your e.firma

It is the most sensitive asset your company has, and we treat it that way. The three pieces you upload are stored encrypted:

certificate.cerencrypted private-key.keyencrypted key passwordencrypted
  • It is never shown on screen and cannot be downloaded from the portal: it can only be uploaded.
  • We use it only to read your information at the SAT: your CFDIs, your Constancia de Situación Fiscal, your Opinión de Cumplimiento (32-D) and the filings you already submitted.
  • Radar Fiscal does not file tax returns and does not sign documents on your behalf.

Your account

Anyone trying to guess your password runs into limits, and you find out.

SituationWhat the portal does
Three wrong passwords or codes in a rowThe account waits 15 minutes and we email you.
Ten failed attempts within 24 hoursThe account is locked for up to 24 hours; to get in sooner, reset your password.
Many attempts from the same connectionThat connection is blocked for a while.
Thirty minutes without using the portalThe session closes by itself.
You change your passwordYour sessions on other devices are closed and we email you.
You sign in from a new device or browserWe email you.

Those emails only inform you: none of them asks for your password. When you create or change a password we require at least 10 characters and reject the most common ones (such as password123) and those containing your email address.

Two-step verification

Optional and strongly recommended. On top of your password we ask for a 6-digit code that your phone generates every 30 seconds, with Google Authenticator or Microsoft Authenticator. Even if someone knows your password, without your phone they cannot get in.

  1. In the portal, open Seguridad (button at the top right).
  2. Click Activar la verificación en dos pasos and scan the QR code with the app.
  3. Type the code to confirm and save your 8 backup codes: they let you in if you lose your phone.
482 913
Example · changes every 30 s

Every sign-in, visible

The Seguridad section of the portal holds your access log: every sign-in, every failed attempt, every session closed for inactivity and every password change, with date, device and IP address. Whoever administers your company sees the log for all of its accounts.

If our support team needs to look at your account to help you, they come in with a single-use access that expires in 2 minutes and in read-only mode: they can look, not change anything. That entry also shows up in your log.

DateWhat happenedDeviceIP address
11/09/2026 09:14Sign-inChrome on Windows203.0.113.24
11/09/2026 09:13Wrong passwordChrome on Windows203.0.113.24
10/09/2026 18:02ANFEPI support access read-onlyFirefox on Mac198.51.100.7
10/09/2026 17:40Session closed for inactivitySafari on iPhone198.51.100.61
09/09/2026 08:55Two-step verification enabledSafari on iPhone198.51.100.61

Example with fictitious data.

Your data, kept apart

Each user only sees the companies they have access to. And we do not take that for granted: every week an automated test walks through every screen of the portal to check that none of them opens without signing in and that none shows another company's data. If it ever finds something, it tells us right away.

Where your data lives

  • Everything travels encrypted: the portal only works over HTTPS, with TLS 1.2 or above.
  • The database is not exposed to the internet.
  • Administrative access to the server requires cryptographic keys, and connections trying to guess passwords are blocked automatically.
  • Your information is backed up every day and every backup is verified automatically.

What you can do

Turn on two-step verification. It is the best defense against a stolen password.

Use a password you do not use anywhere else. A phrase of several words is easy to remember and hard to guess.

Check your access log now and then in the Seguridad section.

If you get an alert you do not recognize, change your password and write to us.

On shared computers, sign out when you are done.

Questions, or something that does not look right? Write to info@anfepi.com. The portal lives at xmlsat.anfepi.com/portal.

Not using Radar Fiscal yet?

Preventive tax monitoring over your CFDIs, every day.