Security

You are trusting us with a list of your clients and their filing deadlines. Here is exactly how that is protected, and where it is held.

Two-factor authentication, mandatory

Not a setting an owner can forget to switch on. Every account requires a second factor, and until one is set up nothing beyond the billing, support and settings pages will open. Recovery codes are single use and stored only as scrypt hashes.

Passkeys

Sign in with Face ID, Touch ID, Windows Hello or a hardware key instead of a password and a code. A passkey is tied to this domain, so it cannot be handed to a convincing copy of our sign-in page. It counts as the second factor on its own.

Isolation enforced at the database

Every table carries row-level security, so a query can only return rows belonging to the account that asked. It is not a filter in the application that someone could forget to write: the database refuses.

Plan limits enforced on the server

The same applies to what your plan allows. Limits are checked in the action that adds a company, not hidden in the interface, so what you are shown and what is possible are the same thing.

We only read the public register

Company data comes from the Companies House public data API, which we read and never write to. We hold no filing credentials, no authentication codes and no agent authorisations, so there is nothing there to lose.

No card details, ever

Payments go through Stripe Checkout and the Stripe Customer Portal. Card numbers are entered on Stripe, not here, and never reach our servers or our logs.

Least data, not most

We do not enrich, sell or share your data, and we set no advertising or analytics cookies. Our public pages count visits with Google Analytics in a cookieless mode that stores nothing on your device, and it is not loaded once you sign in. Contact form submissions store a salted SHA-256 of the sender IP for rate limiting rather than the address itself.

Client portal access is revocable

Portal links use long random tokens, are scoped to one client, and can be revoked instantly. Your clients never get an account on our system, and never see another of your clients.

Who processes your data, and where

A short list on purpose. Each one handles data only to deliver the service.

ProviderWhat it doesWhere
VercelHosting and page renderingLondon
SupabaseDatabase and sign-inIreland
Amazon SESSending your reminder emailsLondon
Companies HousePublic register, read onlyUnited Kingdom
Google AnalyticsPublic page visits, cookielessUnited States
StripeSubscription billing onlyUnited States, India

Your client data does not leave the UK and Ireland

The companies you track, their deadlines, your officers and their verification status live in the first four rows only. Neither Google nor Stripe is loaded or contacted from the signed-in pages at all. Pages are rendered in London, the database is in Ireland, reminders are sent from London, and Companies House is the UK register we read from. Ireland is covered by UK adequacy, so no transfer mechanism is needed for it.

Stripe is the one exception, and only for billing

Stripe receives three things: the email address you sign in with, your practice name, and an internal reference number. That is all. No company you track, no deadline and no officer is ever sent to Stripe. Card details are entered on Stripe's own checkout and never reach our servers or our logs.

Stripe's own privacy notice states it may process data in the United States and India. That transfer is covered by the UK International Data Transfer Addendum issued by the ICO, and Stripe is certified under the EU-US Data Privacy Framework. We would rather name it than describe our billing provider as a UK one.

What we are not

FiledOnTime is a reminder service. It does not carry out identity verification under ECCTA, and it does not submit anything to Companies House, HMRC or anyone else on your behalf. That is a deliberate limit, and it is also a security property: we hold no credential that could be used to file in your name.

Responsibility for making a filing, on time and correctly, stays with you. Do not rely on us as your only record of a deadline.

Registration and reporting

RWB Digital, a trading name of Christopher Goodchild, of 35 Farne Way, Royal Wootton Bassett, SN4 8LX. Registered with the Information Commissioner's Office under number ZC054835.

If you believe you have found a security problem, email support@filedontime.co.uk with enough detail to reproduce it. We will confirm receipt and tell you what we are doing about it. Please give us a reasonable chance to fix it before publishing.

Our privacy notice sets out what personal data we hold, why, and for how long.

Questions before you sign off a new tool?

Ask. A real person replies, usually within one working day.