Trust and security
Bastion Gateway is designed so people remain in control, client data stays separated, and every action sent to HMRC leaves a dependable record.
Access and refresh tokens are encrypted before storage. They are never exposed to your browser or stored in readable form.
Access is scoped to the correct workspace and client. Staff permissions control who can view and change each part of the work.
A person must review the figures and make the required declaration before anything can be sent to HMRC.
The service records what was sent, when it was sent and what HMRC returned. Unknown outcomes are shown clearly, never as success.
Passwords use memory-hard hashing. Sessions rotate, state-changing requests are protected, and staff accounts support multi-factor authentication.
Journeys are tested for keyboard use, screen readers, high zoom, text spacing and strong colour contrast against WCAG 2.2 AA.
The software helps prepare and check your work. It does not give tax advice or decide your tax position. Figures are sent only after an authorised person reviews and confirms them.
We do not sell personal data or use advertising trackers on tax-data pages. Read what we collect, where it is processed and how deletion requests work.
Read the privacy policyAsk about our controls, request accessibility help, or report a suspected vulnerability.
[email protected]