Report a security problem

How to tell us, and what happens next

URL: /security · Last updated: 18 September 2026

Email [email protected]. You do not need an account, a contract, or a prior relationship with us — if you found something, we want to hear it.

aihtax is UK bookkeeping software that holds tax records and files Making Tax Digital submissions to HMRC on customers' behalf. Two things we treat as urgent above all others:

  • one customer being able to reach another customer's data
  • anything touching HMRC credentials, OAuth tokens, or submissions

Say so in the subject line if your report is one of those, and we will treat it as urgent.

What to include

Enough to reproduce it: the URL or endpoint, what you sent, what came back, and the account you used. A short screen recording is fine.

What we will do

  • Acknowledge within 3 working days. We are a small team, so that is a promise we can keep rather than an ambitious one we cannot.
  • Tell you our assessment, and what we intend to do about it.
  • Keep you informed while we fix it, and confirm when it is done.
  • Credit you if you want it, and not if you do not.

What we ask

  • Give us a reasonable chance to fix it before telling anyone else.
  • Do not access, change or delete other people's data. If you can demonstrate the problem with your own account, please do.
  • No denial of service, no spam, no social engineering of our staff or customers.
  • Stay within UK law.

We do not run a paid bug bounty.

Scope

In scope: app.aihtax.co.uk and the API behind it.

Out of scope: the providers we build on (Cloudflare, Fly.io, Stripe, GoCardless, HMRC) — report those to them directly. Findings from automated scanners with no demonstrated impact are usually not worth either of our time.

Our own testing

We run static analysis, dependency vulnerability checks and cross-tenant isolation tests on every change and weekly. We have not yet had an independent penetration test, and we would rather say so here than imply otherwise.

This page is the policy referenced by /.well-known/security.txt.