HMRC Regulatory Update: From May 2026, conveyancers filing SDLT returns must register as tax advisers.
SDLT calculations involve sensitive client data—names, addresses, financial details. We protect it with security standards used by banks and government agencies, supporting the trust your clients place in your practice.
AES-256 at rest, TLS 1.3 in transit
UK only — data never leaves the UK
Role-based permissions, 2FA available
GDPR, ICO registered, Cyber Essentials Plus
SOC 2 Type II (in progress)
99.9% guaranteed
Annual third-party testing
Daily encrypted backups, disaster recovery
How We Protect Your Client Information
All data transmitted between your browser and our servers is encrypted using TLS 1.3—the latest and most secure transport protocol. This is the same encryption standard used by banks for online banking.
All stored data is encrypted using AES-256 encryption—the standard approved by governments for classified information. Even if someone physically accessed our servers, the data would be unreadable without encryption keys.
Encryption keys are managed through a dedicated key management service with automatic rotation. Keys are never stored alongside the data they protect.
Your data never leaves the United Kingdom.
All SDLT Check infrastructure is hosted in UK data centres. This includes:
Optional but recommended. When enabled, logging in requires:
Supported authenticators:
Every action in SDLT Check is logged:
| Event | What's Recorded |
|---|---|
| Login | User, timestamp, IP address, device |
| Calculation created | User, timestamp, file reference |
| Calculation verified | Verifier, timestamp |
| Report exported | User, timestamp, format |
| User added/removed | Admin, timestamp, affected user |
| Settings changed | Admin, timestamp, what changed |
Audit logs are retained for 7 years—aligned with legal document retention requirements.
Managers and Admins can view audit logs for their firm. Logs can be exported for compliance purposes.
Built for Business-Critical Operations
We guarantee 99.9% uptime—that's less than 9 hours of downtime per year.
No single point of failure.
Meeting Your Professional Obligations
Fully compliant with UK GDPR and Data Protection Act 2018.
Download Data Processing Agreement →Supports SRA compliance obligations for secure client information handling.
How We Build Secure Software
Annual third-party testing by independent security specialists.
How we handle vulnerabilities:
All third-party services undergo security review before integration.
| Service | Purpose | Security |
|---|---|---|
| AWS (UK regions) | Infrastructure | SOC 2, ISO 27001 |
| Stripe | Payment processing | PCI DSS Level 1 |
| Auth0 | Authentication | SOC 2, ISO 27001 |
| Datadog | Monitoring | SOC 2 |
Everything Your IT Team Needs
2-page summary for decision-makers
Detailed technical controls
GDPR-compliant DPA
Executive summary (NDA required)
Current certification
Current third-party services
All data is stored in UK data centres. Your data never leaves the United Kingdom. This includes primary storage, backups, and logs.
Yes. We're fully compliant with UK GDPR and the Data Protection Act 2018. We act as a data processor on your behalf, and we provide a Data Processing Agreement for all customers.
Yes. You can delete individual calculations at any time. For bulk deletion or account closure, contact support. Note that some data may be retained for legal/regulatory compliance.
In the unlikely event of a data breach, we would: (1) Contain and investigate immediately, (2) Notify affected customers within 72 hours, (3) Notify the ICO if required, (4) Provide full transparency, (5) Offer appropriate remediation. We carry cyber liability insurance to cover breach response costs.
We share minimal operational data with infrastructure providers (necessary for service delivery). We never sell data. We never share calculation content with third parties. See our sub-processor list for details.
Currently: Cyber Essentials Plus, ICO registration. In progress: SOC 2 Type II (expected Q2 2025). We also align with ISO 27001 controls, though we're not currently certified.
Security questions? Let's talk. Our team is happy to discuss security requirements, complete questionnaires, or arrange technical deep-dives with your IT team.