Security
1. Overview
Accordix uses technical and organisational measures designed to protect Customer data. This page describes the current implementation and its limitations. It is not a certification and does not claim SOC 2, ISO 27001, certified archiving, end-to-end encryption or immunity from security incidents.
2. Hosting and infrastructure
Accordix runs on Render using a managed PostgreSQL database and persistent storage. The intended primary deployment region is Frankfurt, Germany. Render is relied on for physical, network, infrastructure and platform controls.
3. Encryption
Traffic to and from Accordix is protected using HTTPS/TLS. Passwords are stored as salted bcrypt hashes.
Accordix does not currently apply its own field-level or file-level encryption at rest. Database, disk, snapshot and backup protections are provided at infrastructure level by the hosting provider. Accordix does not claim customer-managed encryption keys or end-to-end encryption.
4. Authentication and access control
Access requires authentication. Sessions use signed HttpOnly cookies and production deployments use the Secure flag. Login attempts are rate-limited. Role and permission checks distinguish business members, accountants, firm owners and operators.
Production access by Accordix is limited to operational, security and support needs. The current operator role has broad application-level access and must therefore be protected as a privileged account.
5. Tenant separation
Customer organisations are logically separated through application-level query scoping and permission checks. Accordix does not currently claim database row-level security or a physically separate database for every Customer.
6. Upload and file controls
The application applies upload-size limits, path-safety checks and permission checks. Inline browser preview is restricted to supported formats. Files linked to a request may nevertheless include formats beyond PDF, JPG, PNG and CSV. Accordix does not currently claim automated malware scanning for every upload. Customers should upload only business files they trust and should not use Accordix to distribute executable or active content.
7. Logging and auditability
Accordix records operational and intake information for email and WhatsApp processing and maintains limited technical logs. It does not currently provide a complete immutable end-user audit trail for every in-app upload, view, download, modification, export or deletion.
Sensitive document contents, tokens and download links are not intentionally written to normal application logs. Intake records may contain sender identifiers, message metadata and error details needed to process and troubleshoot inbound messages.
8. Backups and recovery
Backup and snapshot behaviour is provider-managed and depends on the applicable Render service and plan. Deleted data may remain in backups or snapshots until they expire or are overwritten under the provider's then-current lifecycle.
Accordix does not guarantee a fixed 35-day maximum for every backup copy. Backups are intended for service recovery and are not ordinarily used to restore an individual record deleted by a Customer.
9. AI and communications providers
Where instructed by a Customer, complete document files may be transmitted to Google Cloud Vertex AI for invoice extraction, bank-statement extraction or linked-document suggestions. WhatsApp messages and attachments are processed through Meta's WhatsApp Business Platform where that channel is used. Provider details and safeguards are listed on the Subprocessors page.
10. Incident response
Accordix maintains an internal incident and personal-data-breach response procedure. Suspected incidents are assessed, contained, documented and escalated to the responsible operator. Affected Customers are notified without undue delay where a personal-data breach affects their data, in accordance with the Data Processing Agreement.
11. Secure development and secrets
Accordix uses dependency management, code review where practicable, environment-managed secrets and production configuration separation. Credentials and service-account material must not be committed to the repository. Security controls and legal disclosures are reviewed when material processing changes are introduced.
12. Data export and deletion
Export and deletion are currently assisted operational processes. Scope and limitations are described on the Data Export & Deletion page.
13. Current limitations
The following should not be assumed to exist today:
- multi-factor authentication;
- self-service password reset;
- server-side revocation of every issued session token;
- signed or time-limited document download URLs;
- application-managed encryption at rest;
- complete end-user audit logging;
- database row-level security;
- automated malware scanning of every upload;
- guaranteed removal of all backup copies within a fixed 35-day period;
- a completed independent penetration test or security certification.
These limitations do not mean that no safeguards exist, but Customers should evaluate whether the current controls are appropriate for their intended document categories and risk level.
14. Responsible disclosure
Security reports: security@accordix.sk. Please avoid accessing, changing or retaining other users' data and allow a reasonable opportunity to investigate before public disclosure.