Security
QTRLY is Making Tax Digital for Income Tax software for UK sole traders and landlords. It holds the income and expense records behind your account, and your National Insurance number once you have given it. Filing is still being built, so nothing has been submitted to HMRC through QTRLY and there is no submission history to hold yet. This page explains the measures that keep what we do hold safe.
Account isolation and row-level security
Your account's data is isolated at the database with row-level security, enforced at the data layer rather than only in the interface, so it cannot be read by another account.
Encryption
Traffic between your device and QTRLY is encrypted in transit (HTTPS), and data is stored on reputable, managed infrastructure.
Least-privilege access
Named staff can only see what a support request needs, access is time-limited, and every access is recorded in an append-only audit trail with who did what and when.
Your HMRC connection
QTRLY does not hold a live HMRC production connection yet, so there is no connection to make today and nothing can be filed for real. The rest of this section describes how that connection is designed to work, and it applies from the day it goes live.
When you connect QTRLY to HMRC, the access and refresh tokens for that connection are encrypted at rest, in the same way as our other integration tokens. Nothing is submitted to HMRC on your behalf without you reviewing and confirming it first.
Withdrawing that authority. You can take the connection back at any time. Disconnecting deletes the access and refresh tokens we hold and marks the connection as disconnected, so no further call can be made to HMRC in your name. It deliberately leaves your own records alone: your businesses, your income and expense entries and the history of what has already been filed all stay, because they are yours and because the submission history is the evidence of a filing. Deleting data is a separate request, described in the privacy notice. Disconnecting also takes effect at our end only, so we would encourage you to remove QTRLY from the authorised software in your HMRC online account as well. Email security@getmanifold.co.uk to disconnect.
Abuse protection
Requests are rate-limited and validated, and sensitive settings, such as integration tokens, are encrypted at rest.
Reporting an issue
If you believe you have found a security problem, please email security@getmanifold.co.uk and we will look into it promptly.