Online Self Assessment deadline 31 January

Prepare free — from £39 when you file, ex VAT

Get started

Home / Security

Security

Self Assessment Software security — data isolation

Each organisation’s Self Assessment data is isolated. Sensitive identifiers are encrypted. How we protect taxpayer information in the workspace.

In short

Self Assessment Software scopes every workspace query to the signed-in organisation. Passwords are hashed. NINO and UTR are encrypted at rest. HMRC software keys stay in server configuration, not the browser. Public marketing pages never load a taxpayer record.

A Organisation A

Sees only its own clients and returns. Every application query is scoped to that organisation.

B Organisation B

A separate workspace. Super-admin impersonation is a controlled support path — not a shared password — and does not rewrite the subscriber’s last-login clock.

S Secrets

NINO and UTR encrypted at rest. Database and HMRC keys in server environment config. Public pages never load taxpayer data.

How we protect the desk

Tenant isolation

Application queries are scoped to the current organisation. One practice cannot read another practice’s clients. Individuals cannot see other people’s returns.

Authentication

Passwords are hashed. Sessions are required to access the workspace. You should use a strong unique password for every login in the organisation.

Sensitive identifiers

National Insurance numbers and Unique Taxpayer References are encrypted at rest. We do not sell taxpayer lists.

HMRC credentials

HMRC software keys and related secrets live in server environment configuration. They are not embedded in the public site or shipped to the browser.

Support access

Platform super admins may impersonate a subscriber organisation to investigate faults. That is a support workflow with a visible bar in the product — not silent access with your password.

Public site boundary

Marketing pages, guides and the contact form do not load live taxpayer records. Client data stays behind authentication in the workspace.

What you should still do

Control who logs in

Only invite staff who need access. Remove leavers promptly.

Protect devices

Keep OS and browsers updated. Do not share passwords.

Check before you file

Review calculation and status before submit. You remain responsible for figures sent to HMRC.

Report concerns

Email info@selfassessmentsoftware.co.uk if you suspect unauthorised access.

Related

Related

Contact

Security or product questions.

FAQs

Security — questions answered

Can one organisation see another’s clients?

No. Queries are scoped to the signed-in organisation. That is the core isolation model of the product.

Are NINO and UTR encrypted?

Yes. Sensitive identifiers such as National Insurance number and Unique Taxpayer Reference are encrypted at rest.

Do public pages expose taxpayer data?

No. Public marketing and guide pages never load a taxpayer record. Data sits in the authenticated workspace.

How do I raise a security concern?

Email info@selfassessmentsoftware.co.uk with as much detail as you can. We aim to reply within one business day.

Prepare free

Ready to work in an isolated desk?

Create an organisation free. Prepare returns with no card, and pay only when you file.