№ 10Compliance dossier · Security
For directors, IT leads, and accountants
Security and compliance.
Your Xero connection is scoped to what we actually need to draft and post vouchers — nothing more. Each company's data lives in its own tenant and never crosses with another. The detail below is for anyone who wants to know exactly what we can and can't see.
§ 01What we read · what we don't
Connected Xero org · per company
✓ What we read
- 01Transactions on the orgs you connect — to draft and post vouchers.
- 02Contact details on the orgs you connect — to identify shareholders.
- 03Account settings — to know which dividend account and bank to use.
- 04Your registered office address from Companies House (separately, by company number).
✕ What we don't
- 01Payroll data, employee records, or salary information.
- 02Advisor permissions or anything outside the listed Xero scopes.
- 03Bank feeds, statements, or live banking connections.
- 04Other clients' data — every Xero org is its own tenant on our side.
§ 02Xero scopes requested
OAuth consent · per organisation
These are the scopes you grant when you connect a Xero organisation to Dividendly. Xero is moving from broad transaction scopes to granular ones during 2026 — your consent screen may differ depending on when you authorised the connection. We keep access as narrow as supports the workflows you actually use.
§ 03Tenant isolation
No shared layer between client orgs
Each company's data stays in its own tenant.
Directors, vouchers, settings, and workflow records are all scoped per organisation. When you switch from one company to another, you switch tenants — there's no shared layer where a voucher from one client could appear in another's ledger.
§ 04UK voucher fields
Carried on every voucher
Vouchers we generate carry the fields HMRC expects.
- 01Date dividend is paid
- 02Company name and company registration number
- 03Shareholder name receiving dividend
- 04Dividend amount per share and total dividend amount
- 05Financial period and tax year context
¶Have a security question?
Write to us.
For specifics about Xero scopes, multi-tenant data isolation, compliance evidence, or anything else this page doesn't cover. We'll come back the same business day.
hello@dividendly.co.uk