Skip to main content
TaxQuay
How it worksFeaturesLog inCreate account
Trust centre

Security at TaxQuay

Tax information is sensitive. TaxQuay is designed to minimise exposure, enforce access at the server and keep important actions traceable.

Last updated: 17 August 2026
ArchitectureIdentityHMRC accessData protectionOperationsReport an issue

Security architecture

TaxQuay runs behind HTTPS and a reverse proxy. Sensitive application operations are performed server-side. API routes validate the signed-in user, active organisation and required role before accessing VAT or ledger records.

Accounts and organisation isolation

  • Passwords are salted and hashed rather than stored in readable form.
  • Email verification is required for new accounts.
  • Authenticator-app two-factor authentication and recovery codes are available.
  • Sessions use HTTP-only cookies with secure settings on HTTPS.
  • Owner, accountant, staff and client permissions are enforced by server routes, not only by screen controls.
  • Organisation identifiers scope HMRC, ledger and submission access.

HMRC authorisation

Customers authenticate directly with HMRC through OAuth 2.0. TaxQuay does not collect or store Government Gateway passwords. HMRC access and refresh tokens are encrypted server-side, tied to the authorised organisation and refreshed only when required.

Tax records and audit data

Transport encryption protects data in transit. Digital-link records connect imported transactions to the prepared VAT figures and submitted snapshot. The organisation activity log records selected security and filing actions while deliberately excluding OAuth tokens, full tax records and return amounts.

Operational controls

Production preparation includes restricted container permissions, service health checks, database and source backups, dependency checks, incident response procedures and security testing. TaxQuay is completing independent security and compliance assurance before requesting HMRC production credentials.

Responsible disclosure: Please report a suspected vulnerability privately. Do not include live credentials, OAuth tokens, Government Gateway details or unnecessary customer information.

Report a security issue

Email admin@taxquay.com with a clear description, affected URL, steps to reproduce and your preferred contact details. We will acknowledge genuine reports and prioritise issues based on risk.

If you believe an account is being actively misused, sign out, change the password, enable two-factor authentication and contact us immediately.

Confidential security contact

Use a concise subject line and share the minimum data needed to investigate.

Report an issue privately →
© TaxQuay.Privacy · Terms · Accessibility