Terms of use

Operational and acceptable-use rules for using AAA WebFiling safely and lawfully.

Last updated: 4 September 2026. These Terms of Use supplement the AAA WebFiling Terms and Conditions and Privacy Policy.

1. Use only with authority

Only access or manage a company, person, client, VAT registration or filing where you are authorised to do so. Do not use public-register availability as a reason to access protected credentials, impersonate an officer, make an unauthorised filing or obtain non-public tax information.

2. Keep credentials protected

Do not disclose or share account login codes, company authentication codes, Companies House personal codes, HMRC credentials, OAuth tokens or other protected filing credentials with unauthorised people. Do not place them in public notes, screenshots, support messages or shared documents unless a secure process specifically requires them.

3. Accurate and lawful submissions

Do not knowingly submit false, misleading, incomplete or unauthorised information. Review the company identifier, VAT registration number, filing period, names, dates, figures and declarations before the final submission step. Where the software shows a validation error or safety warning, do not bypass it by manipulating a request outside the intended workflow.

4. HMRC authorisation and VAT access

HMRC VAT data may only be accessed through an active HMRC authorisation for the relevant VAT registration number. Do not attempt to reuse another person's or another company's HMRC authorisation. Re-authorise when required and stop using the connection if your authority to act ends.

5. HMRC fraud-prevention controls

The VAT service is designed to send HMRC-required fraud-prevention information with relevant API requests. Do not falsify browser, device, public-IP, source-port, authentication, vendor or forwarding information and do not use technical measures intended to defeat these controls. The categories of information involved are described in the Privacy Policy.

6. VAT return submission safety

A timeout, lost browser connection or delayed response does not mean a VAT return should automatically be submitted again. AAA WebFiling may mark an outcome as uncertain and use a retrieval or reconciliation step before another filing decision. Do not intentionally create duplicate submissions.

7. Sandbox and test environments

Where AAA WebFiling provides an internal test or sandbox workflow, use only test credentials and test data intended for that environment. Do not treat a sandbox receipt as evidence of a real filing and do not place live taxpayer credentials into a test workflow unless the workflow expressly supports and requires them.

8. Account roles and delegated access

If an organisation grants access to staff, accountants, company secretaries, agents or other users, it is responsible for assigning appropriate permissions and removing access when it is no longer needed. A user must not use delegated access outside the scope of the authority granted.

9. Prohibited technical use

You must not:

  • attempt to bypass authentication, authorisation, rate limits, filing gates or security controls;
  • probe or exploit vulnerabilities except through an expressly authorised security-testing arrangement;
  • send malware, malicious payloads or deliberately malformed requests;
  • use automated traffic at a rate that could disrupt the service or cause abuse of Companies House, HMRC or another external API;
  • scrape protected account or client information outside the functions intentionally provided by the service;
  • reverse engineer or copy proprietary parts of the service except to the extent the law expressly permits.

10. External service rules

Use of Companies House, HMRC, payment, communications or signature integrations may also be subject to rules imposed by those services. You must not use AAA WebFiling to cause us to breach an external authority's API terms, security requirements or legal obligations.

11. Audit and evidence

The service may keep audit events, filing statuses, timestamps, submission attempts, receipts, correlation references and selected security metadata to support filing evidence, security and troubleshooting. Do not attempt to alter or destroy audit evidence relating to a filing or security event.

12. Reporting problems

If you believe the wrong company, VAT registration, filing period or user authorisation is shown, stop before submitting and raise a support request. If you suspect account compromise or exposure of a filing credential, report it promptly and rotate or revoke the affected credential where appropriate.

13. Enforcement

We may restrict an account or feature where we reasonably believe these rules are being breached or where continued access would create a security, legal, regulatory or external-integration risk. Serious or unlawful activity may be reported to the relevant authority where legally appropriate.