Skip to main content

Security reporting

We welcome responsible reports that help protect customers and financial or tax records.

Report a vulnerability

Email hello@myltdaccounts.co.uk with the subject Security vulnerability. Include the affected URL or component, likely impact, reproduction steps, and a minimal safe proof of concept.

Do not email live taxpayer records, OAuth tokens, passwords, bank credentials, complete account numbers, or unnecessary personal data.

Responsible testing

Avoid privacy violations, accessing another customer's data, social engineering, denial of service, destructive changes, persistent access, and automated high-volume scanning. Stop and report immediately if you encounter customer or credential data.

What happens next

We aim to acknowledge reports within two UK business days, triage severity, contain credible risks, coordinate remediation, and provide updates where contact details are available. This target is not a guarantee of resolution within two days.

Urgent account concerns

If you believe your own account is compromised, sign out active sessions where possible, disconnect affected integrations, contact us immediately, and separately notify your bank or HMRC when their credentials or services may be involved.