Security is not a feature.
It's the foundation.

Your financial data is the most sensitive information your business has. Here's exactly how we protect it.

TLS Encrypted
GDPR Compliant
CCPA Compliant

Layers of security

Defense in depth: multiple independent security controls, so no single failure compromises your data.

Encryption In Transit

All data in transit is protected by TLS 1.2+. Older, insecure protocol versions are disabled.

Access Control

Role-based access control (RBAC) with granular permissions per module. Session management with automatic expiry and forced logout capabilities.

Audit Trail

Every action in Booklet is logged with timestamp, user, IP address, and change details. Audit logs are immutable, tamper-evident, and retained for 7 years. Exportable at any time.

Infrastructure Security

Hosted on enterprise-grade cloud infrastructure. Network segmentation, DDoS protection, and Web Application Firewall (WAF) on all public endpoints.

Vulnerability Disclosure

We run a responsible disclosure program. Security researchers can report vulnerabilities to security@booklet.io. We acknowledge reports within 24 hours and coordinate disclosure responsibly.

Standards and certifications

We meet or exceed the requirements of major data protection standards worldwide.

GDPR

πŸ‡ͺπŸ‡Ί EU

Full compliance with EU General Data Protection Regulation. DPA available on request.

TLS 1.2+

πŸ”’ Active

All data in transit protected by modern TLS. TLS 1.0 and 1.1 are disabled.

CCPA

πŸ‡ΊπŸ‡Έ US

California Consumer Privacy Act compliance. Data deletion and portability supported.

Security built into how we build

Not added at the end. Embedded into every step of our development and operations process.

Principle of Least Privilege

Internal employees have access only to systems required for their role. Customer data access by employees requires documented justification and is logged.

Automated Security Scanning

Every code change is scanned for known vulnerabilities using SAST tools. Dependencies are monitored for CVEs and updated automatically.

Secure Development Lifecycle

Security reviews are embedded into our engineering process, not bolted on at the end. All developers complete annual security training.

Incident Response Plan

We maintain a documented incident response plan tested quarterly. In the event of a breach, affected customers are notified within 72 hours.

Daily Encrypted Backups

Customer data is backed up daily to geographically separate locations. Backups are encrypted and tested for recoverability monthly.

API Security

Rate limiting, JWT authentication, and CORS controls protect every request to the Booklet API.

Who can access your data?

Your data belongs to you. Booklet employees do not have default access to your financial records, employee data, or business information. Access is controlled by a permissions system that requires explicit authorization for any employee to view customer data.

When you contact support, a support agent may request temporary, read-only access to your account to diagnose an issue. This access is time-limited (typically 4 hours), fully logged, and requires your explicit consent.

Our engineering team accesses production infrastructure only through audited, multi-factor-authenticated systems. No unlogged "back door" access exists. All access events are retained in an immutable audit log.

We will not provide your data to government agencies or law enforcement without a valid legal process (court order, subpoena, or equivalent). When legally permissible, we notify affected customers before complying.

Found a vulnerability?

We appreciate responsible security research. If you discover a security vulnerability in Booklet, please report it to us privately. We'll acknowledge your report within 24 hours, work with you to understand the issue, and credit you in our security acknowledgements.

Report a Vulnerability
πŸ“§
Email us
security@booklet.io, encrypted with our PGP key
⏱️
24-hour acknowledgement
We confirm receipt of every report within one business day
🀝
Coordinated disclosure
We work with you on timeline before public disclosure
πŸŽ–οΈ
Security credits
Valid reports are credited in our security acknowledgements page