Report a Security Issue
InvoClouds handles tax data — VAT returns, Corporation Tax filings, company officer details. We take that responsibility seriously, and we would much rather hear about a problem from you than find out about it the hard way.
If you think you have found a security vulnerability, or you believe you have experienced a security incident involving InvoClouds, please get in touch. You do not need to be a customer to report something.
How to reach us
Email security@invoclouds.com. We read everything that comes in.
To help us act quickly, please tell us:
- what the issue is, in plain terms
- the URL, page or API endpoint affected
- the steps to reproduce it
- how we can contact you for follow-up questions
Please do not send us real customer records, live credentials, or anyone's personal tax information as part of your report. A description and a screenshot with the sensitive parts removed is enough.
What happens next
- We will acknowledge your report within 2 working days.
- Within 10 working days we will give you our assessment and, where a fix is needed, an expected timeline.
- We will keep you updated until it is closed out.
- If you would like credit for the find, we are happy to give it. Just say so.
What is in scope
These are ours, and we want to hear about them:
- invoclouds.com
- app.invoclouds.com
- the InvoClouds API
These fall outside what we can act on:
- services we do not control — HMRC APIs, the Companies House Gateway, our hosting provider's own infrastructure
- denial-of-service or load testing
- social engineering aimed at our staff or our customers
- physical security testing
- reports generated purely by an automated scanner with no evidence of real impact
A few things we ask
We are not going to pursue anyone who reports a genuine issue in good faith. In return, please:
- do not access, change or delete data belonging to anyone other than yourself
- do not run scans heavy enough to degrade the service for other users
- give us a reasonable chance to fix the issue before you make it public
If personal data may have been exposed
Put DATA BREACH in your subject line so it gets prioritised. We assess every such report against our obligations under the UK GDPR, including the requirement to notify the Information Commissioner's Office within 72 hours where the incident meets the threshold for reporting.
If the issue affects HMRC or Companies House filings
Please say so explicitly in your report. Where an incident touches VAT (MTD), Corporation Tax or Companies House submissions made through InvoClouds, we notify HMRC through the Developer Hub within 72 hours, with a named contact and a direct telephone number, as required under HMRC's terms of use for MTD software.
Related pages
- Privacy Policy — what data we hold and why
- Terms and Conditions