Sees only its own clients and returns. Every application query is scoped to that organisation.
Home / Security
Security
Self Assessment Software security — data isolation
Each organisation’s Self Assessment data is isolated. Sensitive identifiers are encrypted. How we protect taxpayer information in the workspace.
In short
Self Assessment Software scopes every workspace query to the signed-in organisation. Passwords are hashed. NINO and UTR are encrypted at rest. HMRC software keys stay in server configuration, not the browser. Public marketing pages never load a taxpayer record.
A separate workspace. Super-admin impersonation is a controlled support path — not a shared password — and does not rewrite the subscriber’s last-login clock.
NINO and UTR encrypted at rest. Database and HMRC keys in server environment config. Public pages never load taxpayer data.
How we protect the desk
Application queries are scoped to the current organisation. One practice cannot read another practice’s clients. Individuals cannot see other people’s returns.
Passwords are hashed. Sessions are required to access the workspace. You should use a strong unique password for every login in the organisation.
National Insurance numbers and Unique Taxpayer References are encrypted at rest. We do not sell taxpayer lists.
HMRC software keys and related secrets live in server environment configuration. They are not embedded in the public site or shipped to the browser.
Platform super admins may impersonate a subscriber organisation to investigate faults. That is a support workflow with a visible bar in the product — not silent access with your password.
Marketing pages, guides and the contact form do not load live taxpayer records. Client data stays behind authentication in the workspace.
What you should still do
Only invite staff who need access. Remove leavers promptly.
Keep OS and browsers updated. Do not share passwords.
Review calculation and status before submit. You remain responsible for figures sent to HMRC.
Email info@selfassessmentsoftware.co.uk if you suspect unauthorised access.
Related
Related
What data we process and your rights.
Licence and responsibilities.
Security or product questions.
FAQs
Security — questions answered
Can one organisation see another’s clients?
No. Queries are scoped to the signed-in organisation. That is the core isolation model of the product.
Are NINO and UTR encrypted?
Yes. Sensitive identifiers such as National Insurance number and Unique Taxpayer Reference are encrypted at rest.
Do public pages expose taxpayer data?
No. Public marketing and guide pages never load a taxpayer record. Data sits in the authenticated workspace.
How do I raise a security concern?
Email info@selfassessmentsoftware.co.uk with as much detail as you can. We aim to reply within one business day.
Prepare free
Ready to work in an isolated desk?
Create an organisation free. Prepare returns with no card, and pay only when you file.