This Security Statement explains the measures we use to help protect ForwardifyMtd, user accounts and customer data.
Last updated: 08/06/2026
We take reasonable steps to protect the application, but customers and users are also responsible for secure passwords, device security, user permissions and careful use of HMRC authorisation.
ForwardifyMtd is designed to support secure online invoicing, company data separation, user access control and HMRC MTD VAT integration. No online service can be guaranteed to be completely secure, but we aim to use appropriate technical and organisational safeguards.
Our data protection measures may include:
Where the application connects to HMRC MTD VAT services, we use HMRC’s authorisation flow and transmit fraud prevention header data where required.
Customers are responsible for ensuring that:
The application may be hosted using [Hosting Provider / Infrastructure Provider]. Infrastructure controls may include firewalls, restricted access, monitoring, patching, backups and disaster recovery procedures.
Hosting and infrastructure providers may change from time to time. Where relevant, these providers will be listed in our Subprocessor List.
We may maintain logs to help secure the service, investigate errors, prevent fraud, detect unauthorised access and support audit trails.
Logs may include login events, IP addresses, user agent information, system events, invoice actions, HMRC API activity and email sending records.
We may create backups for operational resilience, disaster recovery and accidental data loss protection.
Backups are not a substitute for your own exports or statutory record keeping. You should export and retain business records where appropriate.
You are responsible for:
If we identify a security incident affecting customer data, we will investigate and take reasonable steps to contain, assess and address the issue.
Where required, we will notify affected customers or relevant authorities in accordance with applicable law.
Please report suspected security issues to:
Please do not publicly disclose security issues before we have had a reasonable opportunity to investigate and respond.