Security & verification

The evidence trail you can check yourself

Every filing event in PromptFiling is written into an append-only chain: each record carries a cryptographic fingerprint of the one before it, so history cannot be edited without breaking the chain visibly. The chain heads are signed, the signing key's public half is published at /api/audit/pubkey, and anyone — customer, lender, solicitor — can verify a chain at /api/audit/verify without an account. Filing certificates carry a QR code that resolves against this chain, which is why a PromptFiling certificate cannot be quietly forged: editing the PDF changes nothing, because the proof lives here.

How your data is treated

Company numbers, deadlines and filing history come from the public register. What you add — your e-mail, your figures, your company authentication code — is stored encrypted, used only to do the job, and deleted on your instruction. The authentication code never appears in logs, and our build process mechanically proves that on every release. We are an independent tool, not connected to Companies House or HMRC, and we never file anything without your explicit approval.

Found a vulnerability?

Write to security@promptfiling.co.uk. We read every report, we answer, and we do not pursue good-faith researchers. Details in /.well-known/security.txt.

Back to PromptFiling