Security

What we actually do, and what we don't.

Financial data deserves a straight answer rather than a row of logos. Here is how the platform is built, and where we are still early.

Controls in the product today

Everything on this list is implemented and in use, not on a roadmap.

A database per tenant

Not a shared table with a tenant column. Each customer’s data lives in its own database, so cross-tenant exposure is not one forgotten WHERE clause away.

Encryption in transit and at rest

TLS on everything. Credentials and third-party tokens — HMRC, bank feeds, accounting connections — are encrypted at rest with application-level keys.

Two-factor authentication

TOTP-based second factor available on every account, and enforceable across a practice rather than left to each user’s discretion.

Role-based permissions

Granular permissions per role, scoped so staff see the clients they are assigned to and nothing else.

Audit trail

Who did what, when, and to which record — including automated and AI-initiated actions, which are logged the same way a person’s are.

Login monitoring

Authentication attempts recorded and rate limited, so credential stuffing is visible rather than silent.

Signed integrations

Outbound webhooks are HMAC-signed and their deliveries logged. API tokens are scoped per integration and independently revocable.

Retention and deletion

Configurable retention policies, and per-tenant export and deletion that is genuinely per tenant because the data was never commingled.

UK and EU hosting

The application and its databases are hosted in the UK and EU. The AI features are the exception: text they work on is sent to our AI providers (OpenAI, Anthropic and Google), which process it in the United States under their data-processing terms. Each practice chooses which AI actions are switched on.

Isolation

Separation that is structural, not conditional

Most multi-tenant software keeps every customer in the same tables and separates them with a tenant column and a filter on every query. It works right up until one query is written without the filter — and then one customer sees another customer's ledger.

Qwikr gives each tenant its own database. The separation is a property of the connection rather than a condition in a query, so it cannot be forgotten. It also makes exporting, backing up or deleting one customer's data a clean operation instead of a careful one.

  • Own database per tenant, not row-level filtering
  • Cross-tenant access is not reachable by a missing clause
  • Per-tenant backup, export and deletion
  • Central platform data kept separate from tenant ledgers
Tenant isolation
Harewood Joinery
own database · own credentials
Bramble & Co
own database · own credentials
Ridgeway Consulting
own database · own credentials

A query in one tenant's context has no route to another tenant's rows.

Accountability

Automated actions are logged like human ones

The risk with automation in accounting is not that it makes mistakes. It is that it makes them quietly, and the record does not show that anything unusual happened.

So every action carries its actor. A posting made by a rule, a submission triggered by a schedule and a categorisation applied by the AI all land in the same audit trail as one made by a person, with the reasoning and the evidence attached.

  • Actor recorded on every action, human or automated
  • AI decisions logged with their reasoning and inputs
  • Approvals and rejections retained, not just outcomes
  • Filing submissions logged with what was sent and when
Audit trail
a.patel@vat_return.submittedQ3 · £4,182.40
rule:38transaction.categorised7502 · auto
ai:queuesuggestion.approvedby a.patel@
systempay_run.posted24 employees

The honest answers

No — and we would rather say so than imply otherwise. Qwikr is a new company and neither certification has been completed. The controls described on this page are real and in the product today; the audited attestation of them is not something we have yet. If your procurement process requires certification, tell us and we will be straight with you about timing.

The platform has run without significant incident to date, but we are early enough that a few months is not a meaningful statistic and we will not dress it up as one. Enterprise agreements can include a contractual service level with agreed remedies — that is a commitment we are willing to make in writing.

No. Client data is not used to train third-party foundation models. Where AI features process a transaction they do so to answer that request, and the pattern learning that improves categorisation stays inside your own tenant.

Access by our staff is restricted to what is needed for support and is logged. We will not browse a customer’s ledger out of curiosity, and the audit trail exists so that claim is checkable rather than merely stated.

You export it and we delete it. Because each tenant has its own database, both are clean operations rather than a filtered extract we hope caught everything.

Yes, by arrangement. Get in touch before you start so we can agree scope and timing, and so we do not treat your test as a live attack.

Email support@qwikr.tax with the details and we will acknowledge it. We would much rather hear about a problem from you than read about it later.

Found something?

If you believe you have found a security issue, tell us before you tell anyone else and we will work with you on it.

support@qwikr.tax

Send us your security questionnaire

We will fill it in properly, including the questions where the answer is not yet.