Ready for Veri*factu 2027 How we handle it
satsm
Security and data

How we protect your data and your customers’ data, told without the hot air.

You won’t find compliance badges or vague promises here. This is what the system really does, and what it doesn’t do yet.

Every company, its own space

Your company has its own database and its own file folder, not a column keeping your rows apart from someone else’s. If a query ever went wrong, there would be nothing to see: another company’s data physically lives somewhere else.

Who gets in, and to what

Membership of a company is checked on the server on every single request. An identifier sent from the browser never decides an access. Inside your company, permissions follow the role and can be fine-tuned person by person.

Encryption

Passwords are stored with Argon2id, not encrypted: not even we can read them. Sensitive personal data and integration credentials are encrypted at rest with a different key for each company, so one account’s material cannot be decrypted with another account’s context.

Support access

If we need to go into your space to help you, it takes a written reason, the access expires on its own and the whole thing is logged. There are no invisible doors.

Backups, and the way out

A daily backup per company, restored per company. And if you leave, you take your data with you in standard formats: a full export from your own admin area, without asking us for permission.

What we can’t claim yet

We have no external certifications. The legal pages are drafts pending legal review. And the system letting you comply with Veri*factu doesn’t mean you are complying: that depends on your tax details and on your certificate.

Explore the product for your business.

Explore the processes your shop uses in a demonstration.