- LAST REVIEWED
- 7 September 2026
- REPORT A SECURITY PROBLEM
- security@fastmtd.app
Every statement on this page is checked against the running system, and the page changes in the same release as the behaviour it describes.
Where your data lives
- Your records, figures, messages and account
Our database, on infrastructure we operate in the UK. Encrypted at rest: the host’s disk is encrypted with LUKS2 (AES-XTS, 512-bit key).
- Receipt photographs
Microsoft Azure Blob Storage, UK South. Encrypted at rest by Azure.
- Database backups
Microsoft Azure Blob Storage, UK South. Encrypted twice: by us before they leave our infrastructure, and by Azure.
- HMRC connection tokens
Our database, encrypted with a key held separately from it.
Who processes it for us
Each acts only on our instructions and may not use the data for its own purposes. We update this list before adding a processor.
- Microsoft Azure Blob Storage UK SOUTH
Receipt photographs; encrypted database backups.
- Microsoft Azure OpenAI Service UK SOUTH
Reading receipts into figures; understanding spoken instructions. Receives the text read from a receipt, the photograph when the first reading is unclear, and the transcript of what you said. Microsoft do not use this data to train models.
- Google MAY BE OUTSIDE THE UK
Google Sign-In; Firebase Cloud Messaging for notifications; Android speech recognition. Notifications carry no figures, no supplier and no receipt, only that there is something to see.
- Apple MAY BE OUTSIDE THE UK
Sign in with Apple; notification delivery; iOS speech recognition. Notifications carry no figures, no supplier and no receipt.
- Cloudflare GLOBAL NETWORK, INCLUDING OUTSIDE THE UK
Serving this website. Cloudflare sees what any web host sees of a visitor: IP address, page requested, browser headers. The site is static, sets no cookies, runs no scripts and loads nothing from any third party; its typefaces are served from the site itself. Nothing from the app or from FastMTD Practice passes through Cloudflare.
- HM Revenue & Customs UK · SEPARATE CONTROLLER
Recipient of your quarterly updates and of the fraud prevention data they require by law. A separate data controller, not a processor.
How we keep traders apart
Every table that holds a trader’s data carries a database policy that returns only that trader’s rows to the connection acting for them. A query written without the trader in mind returns nothing, rather than someone else’s data. An accountant sees only the clients whose engagement codes they hold, and only for as long as the engagement lasts.
Authentication
You sign in with Google or Apple. We never hold a password for you.
Your session is a short-lived token that is rotated on use and revoked when you sign out.
HMRC access is granted by you at Government Gateway and held as encrypted tokens. We never see your Government Gateway credentials, and you can revoke the grant in the app or at HMRC at any time.
If you enable Face ID or fingerprint, your handset creates a key pair and we keep only the public half. Your biometric data never leaves the handset. We use the key to tell HMRC that a second factor was used, which their fraud prevention rules ask for.
Accountants sign in with their practice’s Microsoft Entra directory; there are no separate passwords for FastMTD Practice.
Encryption
In transit: TLS 1.2 or later everywhere, including between our own services and to HMRC, Azure, Apple and Google.
Backups: encrypted with AES-256 on our infrastructure before upload, with the passphrase held in Azure Key Vault, separately from the storage account. Azure encrypts the stored objects again.
Receipt photographs: encrypted at rest by Azure Storage.
Database volume: full-disk encryption on the host, LUKS2 with AES-XTS and a 512-bit key, covering the database, the cluster’s local storage and swap. Verified against the host on 7 September 2026.
Backups and recovery
Continuous: every change to the database is archived to Azure Blob Storage as it happens, so the database can be restored to any point in time within the retention window.
Weekly full backup and nightly differential backup.
Weekly rehearsal: the newest backup is restored into a scratch environment, started, and checked against expected row counts, so we know the backup restores rather than hoping it does. Plus a weekly integrity check of every file in the repository against its checksum.
Retention: point-in-time recovery to any moment in the last six weeks. Deleted backup storage can be recovered for a further 14 days.
Logging and monitoring
We log, per request: the endpoint, time, result, response size, your IP address, your app’s version string and an internal trader identifier. We do not log request bodies, receipt contents or figures.
Access to production systems and logs is limited to named individuals with their own credentials.
The AI model
Reading a receipt and understanding a voice instruction use a language model hosted in Microsoft Azure OpenAI Service in the UK. What is sent: the text your handset read from the receipt; the photograph itself if the first reading does not add up; the transcript of what you said, which your handset produced. What is not sent: your name, your National Insurance number, your HMRC tokens, or anything about other traders. The model does not learn from your data. What it returns is shown to you as a suggestion, with a plain statement of how it read the receipt, and you confirm or correct it before it becomes part of your records.
What we send HMRC, and why
UK law requires every piece of Making Tax Digital software to send HMRC “fraud prevention headers” with each request to their Income Tax APIs. HMRC use them to detect and prosecute fraud against the tax system. We send exactly what we can truthfully collect and omit what we cannot, rather than inventing a value; HMRC have been told which ones we omit and why.
For a request from the FastMTD app: the app’s version; your handset’s model and operating system; its screen sizes and timezone; the network addresses it holds; the public address and port your connection reached us from, when it is genuinely public; a per-install device identifier; whether a biometric second factor was used, when it was; the time of each of these; and, from our side, our own product name, version and server address. HMRC publish the full specification at developer.service.hmrc.gov.uk/guides/fraud-prevention.
Reporting a security problem
Email security@fastmtd.app. We acknowledge within two working days and tell you what we did. If you have found a way to reach data that is not yours, please stop at the proof and do not retrieve more than you need to show it; we will not pursue anyone who reports in good faith and does not misuse what they found.
If something goes wrong
If we discover a security incident affecting your data we will tell you, and where the law requires it the Information Commissioner’s Office, within 72 hours of confirming it, saying what happened, what data was involved and what we have done. HMRC are notified where their systems or data are affected, under our terms of use with them.
Where we stand
- Independent penetration test
- Not yet carried out; planned before launch.
- Certifications
- None yet.
- HMRC production credentials
- Not yet applied for. HMRC are no longer accepting production access requests for new 2026-27 quarterly update products, and we had not applied when that window closed. We are seeking access for the 2027-28 tax year and will say here when it is granted.