How we keep your data secure
Last updated 20 July 2026.
Protecting your books is part of how Kontala is built. Here is what that means in practice, in plain words.
Encrypted in transit
Everything between your browser and Kontala travels over HTTPS, so your data is encrypted on its way to and from the app.
Your password
Kontala never stores your password itself, only a one-way hash of it, so it cannot be read back even by us. Password reset links work once and expire after a short time.
After 5 failed sign-in attempts in a row, the account is locked for 30 minutes to slow down guessing attacks - see Signing in to Kontala.
Your HMRC and FreeAgent connections
When you connect Kontala to HMRC or FreeAgent, you sign in on their site, so Kontala never sees those passwords. The access tokens they give us are stored encrypted (AES-256), and the encryption key is held outside the database, so a copy of the database alone is not enough to read them.
Where your data lives
Kontala runs on Google Cloud, in the EU. Files you attach, such as receipts, are stored in Google Cloud Storage in a private bucket, and downloads use time-limited links.
Access inside your account
Every user has a permission level, so people only see the areas you have given them. Only owners and admins can manage users and integrations.
If you have a security question, or something to report, email support@kontala.com.
I need help with...
View all categoriesArticles in this section
- How we keep your data secure
- HMRC and Making Tax Digital