Features & Security

Everything connected.
Everything protected.

Open Banking feeds, HMRC filings, AI insight — every path your money takes runs through one platform, locked down end to end.

Scroll — watch the network become a shield

One platform. Every filing.

From your bank feed to HMRC's servers — Filabl handles the whole journey.

📨

MTD VAT Returns

A recognised Making Tax Digital connection — not a workaround. Calculate, review and submit VAT returns directly to HMRC via OAuth 2.0.

Starter +
🏛️

CT600 · SA100 · Payroll RTI

Corporation Tax, Self Assessment and payroll Real Time Information — filed from the same dashboard your books already live in.

Growth
💬

AI Accountant

Powered by Claude from Anthropic and grounded in your real financial data and UK tax rules. Answers in seconds, 24/7 — no appointments.

All plans
🏦

Open Banking

Connect 40+ UK banks — Barclays, HSBC, Lloyds, Monzo, Starling, Revolut and more — via FCA-authorised Stripe Financial Connections.

Starter +

AI auto-categorisation

Transactions sorted into the right UK tax categories with up to 97% accuracy, with anomaly detection flagging anything that looks off.

Starter +
🧾

Receipt scanning & inbox

Snap or forward a receipt by email — AI extracts the supplier, amount, VAT and category, then matches it to your transactions.

Starter +
📄

Invoicing, bills & quotes

Branded invoices with payment reminders, bill tracking, quotes that convert to invoices, plus contacts and fixed assets — free forever.

All plans
🤝

Client portal

Invite your accountant with scoped access, sync company details from Companies House, and export everything any time. No lock-in.

Growth

Locked down, end to end.

The network above pulls together into a single shield — that's the design principle. Every layer of Filabl is built to protect your financial data.

🔐

AES-256-GCM encryption

HMRC credentials are field-encrypted at rest with a unique random IV per operation. Authentication tags are verified on every read — tampering is detected, not trusted.

🛡️

TLS 1.2+ everywhere

Every connection is encrypted in transit, enforced by HSTS with a two-year max-age and browser preload. There is no unencrypted path to Filabl.

🗄️

Row-level isolation

Row-Level Security at the database layer means each account can only ever read its own data — enforced by the database itself, not just the application.

⏱️

Rate limiting

Authentication and API endpoints are rate-limited against brute-force and abuse, with session tokens verified on every single request.

🔏

CSRF-proof OAuth

HMRC and bank connections use HMAC-signed, timestamped state tokens — cross-site request forgery on the OAuth flow is cryptographically blocked.

🇬🇧

UK GDPR & data residency

Your data lives in the EU London region. We never sell it, never train AI on it without consent, and notify you and the ICO within 72 hours of any breach affecting your rights.

🇬🇧 UK GDPR AES-256-GCM at rest HSTS preload Row-Level Security CSP · X-Frame-Options · COOP RFC 9116 security.txt

Full details in our security policy. Found a vulnerability? See security.txt.

See it all in action

Start free — connect a bank, scan a receipt, ask the AI anything.

Get started free →
No credit card required · Free plan available · UK-only