Client credentials
Connector client secrets and OAuth tokens are sealed with AES-GCM, bound to their connection, and never written to logs or the audit trail. Rotating refresh tokens are replaced automatically.
Controls, data and the limits on AI
A practice run by one person needs stronger controls than one run by three, not weaker ones. These are enforced in the platform, not written in a policy.
Reviewer approval and client sign-off bind to a fingerprint of the exact figures. Change a figure afterwards and both are void automatically.
Connector client secrets and OAuth tokens are sealed with AES-GCM, bound to their connection, and never written to logs or the audit trail. Rotating refresh tokens are replaced automatically.
Blocking checks, reviewer approval and client sign-off are enforced on the server for every caller, including the API and the assistant.
Submissions are idempotent, and live filing is switched off until the practice has its own credentials, HMRC recognition and Companies House software filing approval.
Each event is chained to the one before by a fingerprint, so tampering is detectable rather than theoretical.
AI reads documents, suggests transaction coding and answers questions from practice data. It never produces a filed figure, cannot approve, sign or file, and its suggestions are marked for spot checks.
UK GDPR basis in the engagement letter, no client data used to train models, tenant isolation on every row, and the practice keeps its own database.
The assistant and the API can read and prepare. Approving, signing and filing need a named person in the web app.
Who approved this figure, on what date, against which version, and what did the client sign? Every answer is in the audit trail, and the chain shows if anything was altered.