AES-256
Field Encryption
TLS 1.3
In Transit
30 days
Backup Retention
24/7
Monitoring
🔒Security Layer 01
Encryption — Active Now
Sensitive data is encrypted before it touches the database.
🔑
TLS 1.3 in Transit
All communication between your browser and our servers is encrypted with TLS 1.3. This is enforced on every request, no exceptions.
💾
AES-256-GCM Field Encryption
PII fields — phone numbers, tax IDs, contact details — are encrypted with AES-256-GCM at the application layer before being written to the database.
🗝️
Key Management (In Progress)
Encryption keys are currently managed via environment secrets. A dedicated key vault with automatic rotation is on our roadmap for Q3 2025.
👤Security Layer 02
Access Control — Active Now
The right people see the right data. Nothing more.
🎛️
Role-Based Access (RBAC)
Granular permissions per user — by module, branch, and action type. A cashier cannot access payroll. Fully configurable by your admin.
🏢
Company & Branch Isolation
Multi-company users have strict data boundaries enforced at the database query level. Switching companies never leaks data between entities.
🔑
Authentication Security
Passwords are hashed using bcrypt and never stored in plain text. Sessions are signed, short-lived, and invalidated on logout. 2FA via TOTP (Google Authenticator, Authy) is available from account settings.
🏗️Security Layer 03
Infrastructure & Uptime
Built on managed cloud infrastructure with automated backups.
⚡
Managed Cloud Hosting
FinovaOS runs on Supabase (PostgreSQL) and Vercel — both enterprise-grade platforms with built-in redundancy, SSL, and infrastructure monitoring.
💿
Automated Daily Backups
Supabase performs automated daily database backups. Point-in-time recovery is available. Your data is never stored on a single machine.
🌐
Uptime Commitment
We target 99.9% uptime. Our infrastructure providers (Vercel + Supabase) maintain SLAs above this threshold. Live status is always accessible.
📋Security Layer 04
Audit Trails — Active Now
Every security action is logged and protected from modification.
📝
Immutable Security Logs
Login attempts, password changes, 2FA events, permission changes, and data exports are logged with timestamp, IP address, and user identity — and cannot be modified or deleted.
🔍
Full Activity History
Every create, update, and delete operation in your company is tracked and viewable by authorized admins. Your auditors will have a complete paper trail.
📊
Structured Export
Audit logs can be exported as CSV for your compliance team or external auditors at any time.
🌐Security Layer 05
Network & Application Security
Hardened against common web threats.
🛡️
Security Headers
All responses include HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy headers to defend against common browser-based attacks.
🚧
Rate Limiting on Auth
All authentication endpoints (login, signup, magic link, 2FA) are rate-limited per IP to prevent brute-force and credential stuffing attacks.
🔬
Penetration Testing (Planned)
We plan to engage a third-party security firm for penetration testing before our Enterprise tier launch. Results will be shared under NDA upon request.
🔏Security Layer 06
Privacy & Data Ownership
Your data is yours. We are just the custodian.
🚫
Zero Data Selling
We never sell, share, or license your financial data to third parties. Your business data is never used for advertising or analytics sold externally.
📤
Full Data Export
Export your complete data at any time in CSV, Excel, or PDF format. No lock-in. You can leave whenever you want — and take everything with you.
🗑️
Right to Deletion
Request full account deletion at any time. We will purge all your data within 30 days and provide written confirmation. No hidden retention.