Skip to content

Security

How Syllevo protects your data

Accountants hand Syllevo their clients' financial documents. That only works if the answers on this page are specific, verifiable, and true. Here they are. If anything is unclear, ask us directly.

Your data stays in the EU

  • All personal and invoice data at rest lives in the European Union (the database, the document store, and the infrastructure between them).
  • Third-party processing, such as error tracking, uses EU regions. A vendor that cannot process data in the EU does not touch personal data.
  • This website sets no trackers and loads no third-party scripts. There is no cookie banner because there is nothing to consent to.

Encrypted in transit and at rest

  • Every connection uses TLS, including the internal traffic between Syllevo's own services.
  • Databases and document storage are encrypted at rest.
  • Credentials and connection tokens (such as e-Factura tokens) get an extra layer: they are encrypted with AES-256-GCM before they ever reach the database.

Never lose a document

  • Originals are stored immutably and addressed by their content. Nothing can overwrite an invoice once it has arrived.
  • A monthly job verifies storage against the database in both directions, so a missing or orphaned file is found by us, not by you.
  • Every access that matters (exports, permission changes, document downloads) lands in an audit trail.
  • The database is backed up daily with point-in-time recovery, and backups stay in the EU.

Access is denied by default

  • Every request must carry an explicit permission. Anything not explicitly allowed is rejected, through the same enforcement point for humans and API keys alike.
  • Firms control access per client company: a team member sees exactly the clients they were granted, nothing more.
  • Multi-factor authentication is available to every account.

GDPR: who is responsible for what

Under GDPR, Syllevo (Businice S.R.L.) is a data processor. Your organization is the data controller. Your data is processed on your instructions, and those instructions are real, executable operations in the product: export everything, delete everything, per organization and per client.

We sign a data processing agreement with every organization. Write to security@syllevo.com and we will send it, along with the current list of sub-processors.

Sub-processors are listed in the DPA, and the list is maintained: adding one is a deliberate decision, never a silent change.

Export and deletion are never gated

You can export every original document and all structured data at any time, on any package, during a grace period, after a refund, and at cancellation. Data portability is not a feature tier.

Deleting your organization offers a full export first, then removes your data on a stated schedule (database rows, stored documents, and, as they expire, backups). Deletion is audited and confirmable.

Found something? Tell us

Security reports go straight to people who can act on them. Write to security@syllevo.com