Security and data handling
Current architecture · last updated 17 August 2026
What is live today
The public website and free local validator run on Cloudflare Pages. The paid service now has a separate customer workspace that is created only after UK Filing verifies a completed Stripe subscription. It stores reusable mappings, agreement details, monthly runs, review status and intentional source/output uploads. Files selected in the free validator still remain entirely in the browser and are never included in checkout.
Infrastructure
Cloudflare delivers the pages and public references, runs the checkout and workspace functions, stores workflow records in D1 and customer-file values in Workers KV. The D1 database was created in Cloudflare's Eastern Europe region. KV uses Cloudflare's global infrastructure. Cloudflare documents automatic AES-256-GCM encryption at rest and TLS in transit for KV. Stripe and workspace-signing secrets are stored as encrypted platform secrets and are not shipped to the browser.
Current service providers
| Provider | Current role | Location | Customer files |
|---|---|---|---|
| Cloudflare, Inc. | Site delivery, Functions, D1 workflow database, KV file storage and network security | D1 primary region: Eastern Europe; KV and delivery: global, including the United States | Only paid-workspace files intentionally uploaded by an authenticated subscriber |
| Stripe group entities | Hosted checkout, recurring billing, payment authentication and fraud prevention | Global service; relevant entities and transfers are described by Stripe | Not transmitted; checkout receives route, quantity and versioned acceptance metadata |
| Hostpoint AG | Email hosting | Switzerland | Must not be sent by ordinary email |
Local validation safeguards
The validator has no network call for customer-file content, results or usage telemetry. It accepts only the advertised extensions, limits files to 20 MB, caps displayed findings and populated rows, escapes file-derived display text and uses a restrictive Content Security Policy. Refreshing or closing clears the working state. Starting checkout posts the selected route, agreement quantity and explicit terms acceptance to the same site; no free-validator file or result is attached.
Paid workspace safeguards
A completed Stripe Checkout Session must carry the UK Filing product marker, supported route, quantity and terms version before a workspace is created. The private workspace token is derived with a server-held signing secret; only its SHA-256 hash is stored in D1. The token is sent to workspace APIs in an authorisation header and same-origin checks protect write actions. Agreement and file queries always include the authenticated workspace identifier.
Uploads are limited to CSV/XLSX, 20 MB and the route-specific output type. Each stored file receives an unguessable tenant-specific key, a SHA-256 integrity hash and automatic 90-day expiry. D1 records the monthly status and security-relevant workflow events. Customers can delete individual files or the complete workspace. The generated output is marked review-ready only when the implemented structural pre-check reports zero errors; the customer must still review and submit it.
The paid workspace stores compact validation evidence metadata, including the output SHA-256 and applied rule names, but not the line-level finding notes in D1. A customer-entered submission reference is an audit aid only; UK Filing does not verify it against the GCA or HTE portal.
Bearer-link limitation: anyone who obtains the full private link can act as that workspace user. Store it in a password manager, do not forward it and report suspected disclosure to Dali AI so the workspace can be replaced. UK Filing does not currently offer individual team accounts, multi-factor authentication or role-based access.
Subscription management
The management link opens a dedicated Stripe customer-portal configuration. Stripe verifies the checkout email with a one-time passcode. The portal permits cancellation at the end of the paid period, payment-method updates and invoice access. UK Filing does not collect a portal password or passcode.
Deletion and incident handling
KV automatically expires stored file values after the displayed retention period; workspace controls delete the storage object and mark its record deleted, while complete workspace deletion removes its files and relational records. The Data Processing Addendum governs customer instructions, sub-processors, incident notice, assistance and end-of-contract deletion. Report suspected access or a security problem to [email protected] without attaching customer data.
What we do not claim
Dali AI claims no ISO 27001 certification, Cyber Essentials mark, service-level percentage, content-level accuracy guarantee, portal submission or multi-user access control. KV is global despite the D1 primary region, and UK Filing does not present Eastern Europe as an exclusive data-residency guarantee.
Reporting a problem
Write to [email protected] without attaching customer data. This address is monitored for security and privacy enquiries.