Security is not a feature.
It's the foundation.
Your financial data is the most sensitive information your business has. Here's exactly how we protect it.
Layers of security
Defense in depth: multiple independent security controls, so no single failure compromises your data.
Encryption In Transit
All data in transit is protected by TLS 1.2+. Older, insecure protocol versions are disabled.
Access Control
Role-based access control (RBAC) with granular permissions per module. Session management with automatic expiry and forced logout capabilities.
Audit Trail
Every action in Booklet is logged with timestamp, user, IP address, and change details. Audit logs are immutable, tamper-evident, and retained for 7 years. Exportable at any time.
Infrastructure Security
Hosted on enterprise-grade cloud infrastructure. Network segmentation, DDoS protection, and Web Application Firewall (WAF) on all public endpoints.
Vulnerability Disclosure
We run a responsible disclosure program. Security researchers can report vulnerabilities to security@booklet.io. We acknowledge reports within 24 hours and coordinate disclosure responsibly.
Standards and certifications
We meet or exceed the requirements of major data protection standards worldwide.
GDPR
πͺπΊ EUFull compliance with EU General Data Protection Regulation. DPA available on request.
TLS 1.2+
π ActiveAll data in transit protected by modern TLS. TLS 1.0 and 1.1 are disabled.
CCPA
πΊπΈ USCalifornia Consumer Privacy Act compliance. Data deletion and portability supported.
Security built into how we build
Not added at the end. Embedded into every step of our development and operations process.
Principle of Least Privilege
Internal employees have access only to systems required for their role. Customer data access by employees requires documented justification and is logged.
Automated Security Scanning
Every code change is scanned for known vulnerabilities using SAST tools. Dependencies are monitored for CVEs and updated automatically.
Secure Development Lifecycle
Security reviews are embedded into our engineering process, not bolted on at the end. All developers complete annual security training.
Incident Response Plan
We maintain a documented incident response plan tested quarterly. In the event of a breach, affected customers are notified within 72 hours.
Daily Encrypted Backups
Customer data is backed up daily to geographically separate locations. Backups are encrypted and tested for recoverability monthly.
API Security
Rate limiting, JWT authentication, and CORS controls protect every request to the Booklet API.
Who can access your data?
Your data belongs to you. Booklet employees do not have default access to your financial records, employee data, or business information. Access is controlled by a permissions system that requires explicit authorization for any employee to view customer data.
When you contact support, a support agent may request temporary, read-only access to your account to diagnose an issue. This access is time-limited (typically 4 hours), fully logged, and requires your explicit consent.
Our engineering team accesses production infrastructure only through audited, multi-factor-authenticated systems. No unlogged "back door" access exists. All access events are retained in an immutable audit log.
We will not provide your data to government agencies or law enforcement without a valid legal process (court order, subpoena, or equivalent). When legally permissible, we notify affected customers before complying.