AIBOKIFY / SECURITYAccess, protection and control of your data
Illustrative preview · In developmentEDITION 2026
CONTROL OVER ACCESS

Decide who works with your data.

Set invoice permissions, add two-step verification and work with your accountant through authorized access.

Ask about security →
N° 02PROTECTION IN EVERYDAY WORK

Controls you can use yourself.

01

Set team permissions

Roles and permissions define who can read, create, edit or perform other invoice actions. Accountant access is managed separately.

02

Add a layer of protection at sign-in

Enable two-step verification with an authenticator app and keep your recovery codes safe. Users choose whether to enable it.

03

Work within the selected company

Browser access is restricted by company. An accountant needs authorization to work with a client company.

04

Keep the documents you need

Use the product’s export and backup options. Before closing an account, check what you need to retain and ask about financial history.

N° 03THOUGHTFUL CHOICES

Your review matters too.

Review the access you grant

Choose roles and permissions to match each person’s work. Check the active company before working with a client’s data.

Check scanned data

Scanning uses an external provider, Claude. Review the document and extracted fields before saving.

Protect the device you use

When you use fiscalization, the fiscal key and pending submissions may be stored on your device. Restrict access to it and keep recovery codes somewhere safe.

N° 04FOR YOUR REVIEW

The details, when you need them.

Storage and technical access

Server connections use HTTPS/TLS. Postgres RLS restricts browser-role data by company; privileged server services (service_role) bypass RLS. AES-GCM applies only to fields where encryption is configured.

These controls do not constitute a promise that all stored data is encrypted. Ask about the hosting region and retention periods before use.

Certifications and payment services

We have not published ISO 27001, PCI-DSS or ATK certificates. Card payments depend on provider activation; fiscalization requires SEF setup and approval.

Exports, account closure and privacy

Account closure and deletion of financial history are different actions. Contact us about personal-data requests, retention terms and the data processing agreement.

Monitoring and reporting issues

Technical monitoring filters some sensitive fields, but does not guarantee removal of all personal data. When reporting an issue, describe the steps without sending passwords or card details.

Guaranteed incident-response times and certification reports have not been published.

N° 05ASK YOUR QUESTIONS

What does your business need from security?

Tell us your access, retention or privacy requirements. Clarify the terms before bringing your business data.

© 2026 aibokify. All rights reserved.
Invoicing, payments and reports