Security · updated 2026-09-04
Customs data, treated like tax records.
What is actually in place, stated plainly so your security or procurement team can check it against their list. Nothing here is aspirational; if it is on this page, it is running.
- Where data lives
- One server in Portsmouth, United Kingdom (Contabo). PostgreSQL for records, a data volume for documents. No third-party storage, analytics or AI services.
- In transit
- TLS 1.2+ everywhere (automatic certificates). Internal services (calculation engine, database) are on private networks with no public ports.
- Isolation
- Every query is scoped to an organisation through membership; a client workspace's members see only that workspace. Uploaded files are stored under the organisation's own directory and served only to its members.
- Sign-in
- Email links or passwords (bcrypt-hashed, throttled). Optional two-step verification with any authenticator app plus one-time recovery codes. Every signed-in device is listed and can be signed out individually or all at once; revocation takes effect immediately.
- Free tools
- The liability preview and supplier-file check process files in memory on a temporary filesystem and store nothing.
- Records
- Every vault document is SHA-256 checksummed on upload. Every action in an organisation is written to an append-only audit trail with actor, time and IP.
- Backups
- Nightly database dump and document archive with 14-day rotation, a dump before every deployment, and a rehearsed restore (September 2026). Deleted data ages out of backups within 30 days.
- Change control
- Every change runs an automated gate before it reaches production: 96 engine tests, 27 unit tests and a 140-check end-to-end suite that drives sign-in, roles, ledgers, the vault, export, sessions and two-step verification against a real database and engine.
- Monitoring
- Health is checked every five minutes with alerting on state change; application errors are captured and reviewed weekly.
- Retention
- Your data stays while your account or organisation exists. You can delete a ledger, a document, an organisation or your whole account yourself; we keep HMRC-relevant records only as long as you keep them with us. Audit logs and backups follow the same deletion within 30 days.
- People
- One founder-operator with access to production; no outsourced support with data access.
Reporting a vulnerability
Email hello@cbamreturn.co.uk with what you found and how to reproduce it. You will get a human reply within two working days and a fix timeline within seven. Please do not access other organisations' data beyond what is needed to demonstrate the issue. Machine-readable contact: /.well-known/security.txt.
Related: privacy · data processing terms · subprocessors · terms.