Skip to content

Building control for software

Your developers built it.
Who checked it?

We review UK tax and accounting software that somebody else built. We do not build the thing we check, and that is the whole point.

6
surfaces tested
2 wks
start to report
£2,500
one off review
What a review covers6 surfaces
  • 01Customer separationCan one of your customers reach another customer's records
  • 02Payment gatesCan an account that has not paid reach paid features
  • 03HMRC integrationFraud prevention headers, token storage, agent authority
  • 04Injection and uploadsWhat reaches your database or disk unescaped
  • 05Sessions and authPassword reset, lockout, how long a token stays alive
  • 06What leaksStack traces, versions and internal paths in error pages

Two reports: plain English for you, a fix list for your developers. Re-test included.

Scope

Someone filed a real tax return without paying.

Not a demo. A live UK tax platform, a real submission, from an account that had never paid. It had been live for months. Their developers were competent and had no idea.

Live for
6 mths
Found in
1 day

Four questions about your own platform.

  1. 01

    Who was the last person outside your dev team to look at your code?

    Nobody

  2. 02

    Can an account that cancelled last month still reach its old data?

    I would have to ask them

  3. 03

    When were your fraud prevention headers last checked against HMRC's validator?

    When we got approved

  4. 04

    Your developers say it is fixed. How would you know if it was not?

    I would not

If you answered like that, nothing is wrong with your company. It just means nobody independent has ever looked.

Book a call

HMRC requires a penetration test. It has never checked yours.

Getting production API access means agreeing to HMRC's terms, and those terms say you must test for security vulnerabilities before going live, including regular penetration testing. At approval HMRC reads your sandbox logs to confirm your fraud prevention headers are right. It asks nothing about the testing.

BEFORE HMRC LETS YOUR SOFTWARE GO LIVEHMRC REQUIRESHMRC CHECKSYour API calls are formed correctlyYesYour fraud prevention headers are sent, and accurateYesYou tested for security vulnerabilities before go liveNoYou do regular penetration testingNoYour security controls still workNoSOURCE: HMRC DEVELOPER HUB TERMS OF USE, AND THE MTD PRODUCTION APPROVAL PROCESS

The full breakdown, with HMRC's own wording and sources

Anyone can find it once.

THEY SHIPLIVE TO YOUR CUSTOMERSCHECKFOUNDFIXEDVERIFIED
01FoundA way in, day one.
02FixedClosed in 72 hours.
03VerifiedWe proved the fix was real.
04Found againFive more, alongside it.

Steps three and four are the ones nobody sells you.

Read the full sequence

Two services

One tells you where you stand. One keeps it that way.

Build Review

£2,500one off

An independent read on what your developers actually delivered.

  • Customer separation
  • Payment gates
  • HMRC integration
  • Injection and uploads
  • Sessions and auth
  • What leaks
What a review covers

How it is actually tested.

Customer separation and payment gates come first. That is where real money moves, and they are the two most often enforced only in the interface.

Can one of your customers reach another customer's records

What we do

  • Swap the customer identifier in every request that carries one
  • Re-use one customer's token against another customer's records
  • Confirm list endpoints return only the caller's rows
  • Test export and report paths, which are the ones usually missed
CriticalWhat a failure looks like

Changing one identifier in the URL returned another company's client list and its filed returns.

Failure examples describe the class of problem, not extracts from a client report. The payment gate one is real: it is the engagement described further up this page, published with permission.

Testing follows

OWASP Testing GuideWeb application coverage

PTESPenetration Testing Execution Standard

NIST SP 800-115Technical assessment methodology

This is for you.

  • You handle regulated financial data
  • An outside agency built it, or still maintains it
  • No in house security
  • Someone has started asking

This is not

  • You are a practice using Xero or Sage
  • You want it fixed as well as found
  • You need it finished this week

Free, and genuinely useful

We will check your fraud prevention headers.

HMRC checked yours once, at approval, on sandbox traffic. It has not looked since. Sending them correctly is a legal requirement, and it is a different question from handling them safely.

If the headers are wrong
£3,000
for failing the data transmission requirement.
If it continues
HMRC can block your software from their APIs.
Legal basis
S.I. 2019/360, in force since 1 April 2019.

Book a call.

Twenty minutes, no charge. Tell us who built your platform and what your customers have started asking for. If we are not the right fit we will say so on the call.

Optional, but it is the first thing we would ask.

We reply from a real address and we do not add you to a mailing list.