Security and trust
You are about to give a piece of software access to your VAT records. Here is exactly what that means in our case.
What we do not claim
VATBridge has not yet been granted HMRC software recognition and is not listed on HMRC’s software search. We will not describe the product as “HMRC recognised” until it is. We hold no security certification such as ISO 27001 or SOC 2, and we will not imply otherwise.
Your Government Gateway credentials never reach us
Authorisation happens on HMRC’s own website. You sign in there, HMRC asks whether you want to grant VATBridge access, and HMRC sends us an access token. There is no screen anywhere in VATBridge that asks for your Government Gateway user ID or password. If you are ever shown one, it is not us.
Access tokens are encrypted before they are stored
The tokens HMRC issues are encrypted with AES-256-GCM, tied to the specific record they belong to, and decrypted only at the moment a request to HMRC is made. Encryption keys are held outside the database and outside source control.
You can disconnect at any time
Disconnecting a business removes the tokens stored by VATBridge. A request already in progress may still complete. You can also remove the software authorisation in your HMRC account.
Every significant action is recorded
Sign-ins, HMRC connections, imports and filing actions are recorded in a hash-chained audit log. This helps detect changes; operational access controls and independent backups are also needed to protect the evidence.
Customer access is checked on the server
Every record belongs to exactly one organisation, and every query is filtered by it on the server. Hiding a button is never how access is controlled.
Nothing is filed without you
A VAT return is transmitted to HMRC only after you have read the final figures and made the declaration yourself. There is no automatic submission, no scheduled submission, and no way for us to submit on your behalf.
Reporting a vulnerability
If you believe you have found a security problem, contact us before disclosing it publicly. We will confirm receipt, keep you updated, and will not pursue anyone who reports a genuine issue in good faith.