Security

Your files, your buying rates, your customers: strictly yours

In brokerage, sensitive data is not only personal: it is your buying rates, your partner network and your margins. Here is how we protect them, explained plainly and without unverifiable promises.

Settings — Security

Security controls

GDPR compliant
  • AES-256 encryption at rest
  • SAML SSO / Google Workspace
  • Audit log — 12 months
  • EU hosting — Frankfurt

Our principles

Six commitments, explained without spin

Each point describes a real mechanism, not an intention. Where something is on our roadmap rather than live, we say so.

Strict isolation between organisations

Each organisation has its own data scope. Separation is enforced at database level, through access rules evaluated on every request, not only by a filter in the interface. No query can return a file, a quote or a contact belonging to another organisation, even in case of an application error.

Mailbox access through official OAuth, never a password

Connecting your Microsoft 365 or Google Workspace mailbox goes exclusively through the provider's OAuth protocol. You never share your password with us. Issued tokens are stored encrypted with limited permissions, and revoking access from your provider console cuts it immediately.

Managed cloud hosting and monitoring

The infrastructure runs on a recognised managed cloud provider, with separate production and development environments. Administrator access is named, protected by two-factor authentication and logged. Dependencies are tracked so published fixes are applied quickly.

Backups and continuity

Data is backed up automatically, retained over several rolling days with geographic redundancy. Restore procedures are documented and tested, because a backup that has never been restored is not a backup.

Encryption at rest and in transit

All exchanges between your browser, our application and our services run over TLS. Stored data — files, attachments, mailbox tokens — is encrypted at rest, and documents attached to files are only accessible through time-limited signed links.

GDPR and transparency

Processing of personal data present in files follows GDPR principles: minimisation, limited purpose, defined retention, right of access and deletion. Compliance documentation and the data processing agreement are provided on request.

These guarantees apply whatever your plan: they are not reserved for Enterprise contracts. To understand which data actually flows through the tool, see the detailed workflow on the product page, or the commercial terms on the pricing page.

FAQ

Frequently asked security questions

A security question before you start?

We are happy to answer a security questionnaire and provide our compliance documentation on request.

No credit card required to start.