Security
Less data to hold. Less to worry about.
Security in a compliance tool starts with collecting less. We chose to store the minimum FilingKeeper needs to do its job, keep it in the UK, and isolate every practice's data from every other.
Minimal by design
We deliberately store client names, dates and filing flags — nothing more. No financial figures, no HMRC or Companies House credentials, no personal tax records. The product is built not to need them.
Reached through the app only
Business data is never queried directly from the browser. Every request goes through our application layer, which enforces who can see what.
Isolated per firm
Every query is scoped to your practice, with database-level row isolation behind it. One firm can never see another firm's data.
Every change is traceable
Submission timestamps and a full audit trail stay with each filing, so you always know who marked something submitted and when.
Data residency & processing
Application data is stored in the United Kingdom. Attachments are held with our cloud storage provider. Payments are handled by Paddle, our merchant of record, under their own security and privacy terms — we never see your full card number.
Your rights under UK GDPR
You can ask us to access, correct, export or delete your personal data at any time. Full detail is in our privacy policy, and the specific cookies we set are listed in our cookie policy.
Reporting a vulnerability
If you believe you have found a security issue, please email Contact us. We investigate every report and will keep you updated. See our security.txt for contact details.