Build Review
£2,500one off
An independent read on what your developers actually delivered.
- Customer separation
- Payment gates
- HMRC integration
- Injection and uploads
- Sessions and auth
- What leaks
Building control for software
We review UK tax and accounting software that somebody else built. We do not build the thing we check, and that is the whole point.
Two reports: plain English for you, a fix list for your developers. Re-test included.
Someone filed a real tax return without paying.
Not a demo. A live UK tax platform, a real submission, from an account that had never paid. It had been live for months. Their developers were competent and had no idea.
Who was the last person outside your dev team to look at your code?
“Nobody”
Can an account that cancelled last month still reach its old data?
“I would have to ask them”
When were your fraud prevention headers last checked against HMRC's validator?
“When we got approved”
Your developers say it is fixed. How would you know if it was not?
“I would not”
If you answered like that, nothing is wrong with your company. It just means nobody independent has ever looked.
Book a callGetting production API access means agreeing to HMRC's terms, and those terms say you must test for security vulnerabilities before going live, including regular penetration testing. At approval HMRC reads your sandbox logs to confirm your fraud prevention headers are right. It asks nothing about the testing.
Steps three and four are the ones nobody sells you.
Read the full sequenceTwo services
£2,500one off
An independent read on what your developers actually delivered.
£450per month
Every time they ship, it gets checked before it goes live.
How the standing check worksCustomer separation and payment gates come first. That is where real money moves, and they are the two most often enforced only in the interface.
What we do
Changing one identifier in the URL returned another company's client list and its filed returns.
Failure examples describe the class of problem, not extracts from a client report. The payment gate one is real: it is the engagement described further up this page, published with permission.
Testing follows
OWASP Testing GuideWeb application coverage
PTESPenetration Testing Execution Standard
NIST SP 800-115Technical assessment methodology
Free, and genuinely useful
HMRC checked yours once, at approval, on sandbox traffic. It has not looked since. Sending them correctly is a legal requirement, and it is a different question from handling them safely.
Twenty minutes, no charge. Tell us who built your platform and what your customers have started asking for. If we are not the right fit we will say so on the call.