Security
You are trusting us with a list of your clients and their filing deadlines. Here is exactly how that is protected, and where it is held.
Two-factor authentication, mandatory
Not a setting an owner can forget to switch on. Every account requires a second factor, and until one is set up nothing beyond the billing, support and settings pages will open. Recovery codes are single use and stored only as scrypt hashes.
Passkeys
Sign in with Face ID, Touch ID, Windows Hello or a hardware key instead of a password and a code. A passkey is tied to this domain, so it cannot be handed to a convincing copy of our sign-in page. It counts as the second factor on its own.
Isolation enforced at the database
Every table carries row-level security, so a query can only return rows belonging to the account that asked. It is not a filter in the application that someone could forget to write: the database refuses.
Plan limits enforced on the server
The same applies to what your plan allows. Limits are checked in the action that adds a company, not hidden in the interface, so what you are shown and what is possible are the same thing.
We only read the public register
Company data comes from the Companies House public data API, which we read and never write to. We hold no filing credentials, no authentication codes and no agent authorisations, so there is nothing there to lose.
No card details, ever
Payments go through Stripe Checkout and the Stripe Customer Portal. Card numbers are entered on Stripe, not here, and never reach our servers or our logs.
Least data, not most
We do not enrich, sell or share your data, and we set no advertising or analytics cookies. Our public pages count visits with Google Analytics in a cookieless mode that stores nothing on your device, and it is not loaded once you sign in. Contact form submissions store a salted SHA-256 of the sender IP for rate limiting rather than the address itself.
Client portal access is revocable
Portal links use long random tokens, are scoped to one client, and can be revoked instantly. Your clients never get an account on our system, and never see another of your clients.
Who processes your data, and where
A short list on purpose. Each one handles data only to deliver the service.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Hosting and page rendering | London |
| Supabase | Database and sign-in | Ireland |
| Amazon SES | Sending your reminder emails | London |
| Companies House | Public register, read only | United Kingdom |
| Google Analytics | Public page visits, cookieless | United States |
| Stripe | Subscription billing only | United States, India |
Your client data does not leave the UK and Ireland
The companies you track, their deadlines, your officers and their verification status live in the first four rows only. Neither Google nor Stripe is loaded or contacted from the signed-in pages at all. Pages are rendered in London, the database is in Ireland, reminders are sent from London, and Companies House is the UK register we read from. Ireland is covered by UK adequacy, so no transfer mechanism is needed for it.
Stripe is the one exception, and only for billing
Stripe receives three things: the email address you sign in with, your practice name, and an internal reference number. That is all. No company you track, no deadline and no officer is ever sent to Stripe. Card details are entered on Stripe's own checkout and never reach our servers or our logs.
Stripe's own privacy notice states it may process data in the United States and India. That transfer is covered by the UK International Data Transfer Addendum issued by the ICO, and Stripe is certified under the EU-US Data Privacy Framework. We would rather name it than describe our billing provider as a UK one.
What we are not
FiledOnTime is a reminder service. It does not carry out identity verification under ECCTA, and it does not submit anything to Companies House, HMRC or anyone else on your behalf. That is a deliberate limit, and it is also a security property: we hold no credential that could be used to file in your name.
Responsibility for making a filing, on time and correctly, stays with you. Do not rely on us as your only record of a deadline.
Registration and reporting
RWB Digital, a trading name of Christopher Goodchild, of 35 Farne Way, Royal Wootton Bassett, SN4 8LX. Registered with the Information Commissioner's Office under number ZC054835.
If you believe you have found a security problem, email support@filedontime.co.uk with enough detail to reproduce it. We will confirm receipt and tell you what we are doing about it. Please give us a reasonable chance to fix it before publishing.
Our privacy notice sets out what personal data we hold, why, and for how long.
Questions before you sign off a new tool?
Ask. A real person replies, usually within one working day.