How to tell us, and what happens next
URL: /security · Last updated: 18 September 2026
Email [email protected]. You do not need an account, a contract, or a prior relationship with us — if you found something, we want to hear it.
aihtax is UK bookkeeping software that holds tax records and files Making Tax Digital submissions to HMRC on customers' behalf. Two things we treat as urgent above all others:
Say so in the subject line if your report is one of those, and we will treat it as urgent.
Enough to reproduce it: the URL or endpoint, what you sent, what came back, and the account you used. A short screen recording is fine.
We do not run a paid bug bounty.
In scope: app.aihtax.co.uk and the API behind it.
Out of scope: the providers we build on (Cloudflare, Fly.io, Stripe, GoCardless, HMRC) — report those to them directly. Findings from automated scanners with no demonstrated impact are usually not worth either of our time.
We run static analysis, dependency vulnerability checks and cross-tenant isolation tests on every change and weekly. We have not yet had an independent penetration test, and we would rather say so here than imply otherwise.
This page is the policy referenced by /.well-known/security.txt.