UK transfer documentation provided
already in place
Comprehensive audit trail
every request timestamped
ISO/IEC 27001:2022 certified
independently audited, not self-declared
Automated reminders
no manual chasing
The problem with the inbox
Email was never built for this.
Most accountancy practices still collect their most sensitive client documents through the channel with the least control. Three reasons that stops being defensible the moment someone asks you to prove it.
/01
No chain of custody
Once a document lands in an inbox, it’s copied, forwarded and downloaded beyond your visibility. No record exists of who accessed it, or when.
/02
No access control
An inbox is all-or-nothing. Anyone with mailbox access sees every attachment, whether they need to or not: passports, National Insurance numbers, UTRs, financial records.
/03
No proof of completeness
Fragmented email threads mean fragmented submissions. A folder of emails is not proof of a defensible process.
Every open request, tracked in real time. No status meetings required.
No app. No account. Just a secure link, completed on their phone.
Companies House identity verification
Identity verification is now a volume problem.
Since November 2025, directors and people with significant control have had to verify their identity with Companies House. Existing officeholders have until their next confirmation statement, with a final backstop of 18 November 2026. Companies House estimates six to seven million people are in scope.
For practices doing company secretarial work, that means collecting documents and personal codes from a large number of clients inside a fixed window, then chasing the ones who do not respond. Gatheroo does not perform the verification itself. It handles the requesting, the guiding, the chasing and the record.
How it works
From “we need these documents” to a complete record.
Four steps, no client accounts, no attachments, no chasing.
Build the request once
Assemble exactly what you need from guided fields, clear instructions and conditional logic, so clients know exactly what to provide and how. Use your own templates or start from ours.
Preview what they'll see
Review the request exactly as your client will see it before it goes out. Catch missing fields or unclear wording before they do.
Send a link, not a login
Each client receives a unique, secure portal link. Nothing to install, no account to create, no attachment ever sent. Add optional two-factor authentication via email or SMS.
Receive a complete record
Automated reminders handle the chasing until every field is complete. Every view, submission and update is logged: timestamped, ready to produce on request.
Gatheroo Differentiator
Verify, record and delete, without the risk
Some documents need to be seen, not kept. When a client submits a photo ID or passport, your obligation is often to verify it, not store it indefinitely.
Gatheroo lets you view a document directly in the portal, mark it as viewed, and delete it on the spot, no need to download it to your systems first. The activity log records the full sequence: uploaded, viewed, deleted. Your process is on record.
For practices with customer due diligence obligations under the Money Laundering Regulations, this is the feature most alternatives do not have.
Requested
ID verification request sent to client, 1:58pm
Received
Photo ID uploaded by client, 2:14pm
Viewed
Sighted in-portal by Claire, 2:31pm, marked as viewed
Deleted
Removed from Gatheroo servers by Claire, 2:32pm, logged permanently
Security & compliance
Businesses need processes. Clients are individuals. Gatheroo bridges the gap.
Built for accounting practices that can’t afford to get this wrong. Your intake process needs to be more than convenient. It needs to be defensible.
CERTIFICATION
Certified to ISO/IEC 27001:2022
Certificate 1357-I-1. Independently audited and under ongoing surveillance, covering access control, risk and incident response.
Data Residency
Stored in Australia, with UK transfer documentation provided
Our data processing agreement applies automatically. A completed International Data Transfer Agreement is available on request, with the supporting information for your transfer risk assessment.
Encryption
TLS in transit, AES-128-GCM for sensitive fields
All data travels over TLS. Sensitive fields like National Insurance Numbers and UTRs are encrypted at rest using AES-128-GCM. Storage volumes and S3 are encrypted at rest using AES-256.
Audit Trail
Every request, submission, view and download logged
A complete record of your intake process, ready when you need it.
Access Control
Two-factor authentication via email or SMS
Role-based access so sensitive information stays with the people who need it.
Data Deletion
Deleted the moment you’re done
Deleting a file removes it from the platform straight away, rather than leaving it sitting in an inbox. It then ages out of our encrypted seven-day backup cycle.
Pricing
Simple, transparent pricing. No lock-in.
Gatheroo costs less than one hour of rework per week. Most teams save considerably more than that from day one.
Prices in Australian dollars. Charged in AUD, so the sterling amount will vary slightly with the exchange rate.
Gather Small
37
/mobilled annually
- 2 Team Members
- 10 Active requests
- 10 GB File storage
- 1 Template transfers
- Unlimited Clients / recipients
- Unlimited Templates
Gather Medium
67
/mobilled annually
- 5 Team Members
- 50 Active requests
- 50 GB File storage
- 3 Template transfers
- Unlimited Clients / recipients
- Unlimited Templates
Gather Large
117
/mobilled annually
- 10 Team Members
- 100 Active requests
- 100 GB File storage
- 5 Template transfers
- Unlimited Clients / recipients
- Unlimited Templates
From our users
Working somewhere larger, or need a formal security review?
Larger practices and those with a formal vendor assessment process can request our security documentation, including ISO certification details, the data processing agreement with UK Addendum, and supporting material for your transfer risk assessment.