Your files, your buying rates, your customers: strictly yours
In brokerage, sensitive data is not only personal: it is your buying rates, your partner network and your margins. Here is how we protect them, explained plainly and without unverifiable promises.
Settings — Security
Security controls
GDPR compliant
AES-256 encryption at restOn
SAML SSO / Google WorkspaceOn
Audit log — 12 monthsOn
EU hosting — FrankfurtOn
Our principles
Six commitments, explained without spin
Each point describes a real mechanism, not an intention. Where something is on our roadmap rather than live, we say so.
Strict isolation between organisations
Each organisation has its own data scope. Separation is enforced at database level, through access rules evaluated on every request, not only by a filter in the interface. No query can return a file, a quote or a contact belonging to another organisation, even in case of an application error.
Mailbox access through official OAuth, never a password
Connecting your Microsoft 365 or Google Workspace mailbox goes exclusively through the provider's OAuth protocol. You never share your password with us. Issued tokens are stored encrypted with limited permissions, and revoking access from your provider console cuts it immediately.
Managed cloud hosting and monitoring
The infrastructure runs on a recognised managed cloud provider, with separate production and development environments. Administrator access is named, protected by two-factor authentication and logged. Dependencies are tracked so published fixes are applied quickly.
Backups and continuity
Data is backed up automatically, retained over several rolling days with geographic redundancy. Restore procedures are documented and tested, because a backup that has never been restored is not a backup.
Encryption at rest and in transit
All exchanges between your browser, our application and our services run over TLS. Stored data — files, attachments, mailbox tokens — is encrypted at rest, and documents attached to files are only accessible through time-limited signed links.
GDPR and transparency
Processing of personal data present in files follows GDPR principles: minimisation, limited purpose, defined retention, right of access and deletion. Compliance documentation and the data processing agreement are provided on request.
These guarantees apply whatever your plan: they are not reserved for Enterprise contracts. To understand which data actually flows through the tool, see the detailed workflow on the product page, or the commercial terms on the pricing page.
FAQ
Frequently asked security questions
A security question before you start?
We are happy to answer a security questionnaire and provide our compliance documentation on request.