Security

Your accounting documents deserve bank-grade security

A ledger file contains the entire financial life of a company. Here is how we protect it, from upload to deletion.

Encryption and hosting

  • Encrypted transport (TLS 1.2 minimum, HSTS with preload)
  • Files encrypted at rest on European object storage, access with time-limited keys
  • Database hosted in the European Union, encrypted daily backups
  • Strict nonce-based content security policy, origin isolation, complete security headers

Access control

  • Strict per-organisation isolation: no query crosses a workspace boundary
  • Owner, administrator, member and viewer roles; time-limited invitations
  • Temporary lockout after five failed logins, reset with a single-use link
  • Hashed, scoped, revocable API keys with a usage log
  • Audit log of sensitive actions available to administrators

Artificial intelligence and confidentiality

Extraction of scanned PDFs and writing of the summary use a language model through a professional API whose terms exclude training on transmitted data. Only the necessary pages are sent, and results are flagged as AI-generated with a confidence index. The financial computations themselves are deterministic and use no model.

Your rights

  • Delete documents and analyses at any time from the workspace
  • Full export of your data in JSON and CSV
  • Account deletion with anonymisation of personal data
  • Contact the data protection officer through the contact form

Reporting a vulnerability

Security researchers are welcome. Send a description of the issue and the steps to reproduce it through the contact form, mentioning the word security in the subject. We acknowledge every report within two business days, keep you informed of the fix and credit you if you wish. Please avoid accessing data that is not yours while testing.