Skip to content
Documentation
English
Open the app

Encryption and data protection

The technical measures actually in place in NovaFisko: encrypted transport, passwords, tokens, secrets, signed links, local copy and access control.

This page describes the protection measures implemented by the software. It distinguishes what can be verified in the way NovaFisko works from what depends on hosting and organisation, which is marked "to be confirmed".

Overview

Measure In place in the software
Encrypted exchanges (HTTPS) with mandatory secure connection Yes
Passwords stored as an irreversible hash Yes
Session and integration tokens stored as a hash Yes
Secrets of external services and integrations encrypted in the database Yes
Offline local copy encrypted on the device Yes (AES 256)
Signed, time-limited preview links Yes
Limitation of sign-in attempts Yes
SHA-256 fingerprint of exports Yes
Full encryption of the server disks To be confirmed with the hosting provider
Two-factor authentication Coming soon

Encryption of exchanges

All communication between the application and the server goes through HTTPS. The server sends the strict transport security header (HSTS) with a duration of one year, subdomains included: a browser that has already visited the site then refuses any unencrypted connection.

Other security headers accompany each response: no display of the pages in a frame of another site, no guessing of file types, limitation of the information passed on to third-party sites, deactivation of the camera, the microphone and geolocation.

Passwords and sign-in

  • Passwords are never stored in clear text. Only an irreversible hash is kept; NovaFisko cannot tell you your password, only let you reset it.
  • After ten failed sign-in attempts from the same address, sign-ins are blocked for five minutes.
  • Each sign-in, successful or failed, is recorded in the audit log.
  • For a user of a firm linked to Novadesko, the credentials are verified with Novadesko.
Warning

Two-factor authentication is not yet available in the application. In the meantime, use a long and unique password, managed by a password manager, and never share an account between several team members.

Access tokens

After sign-in, the application receives a token that identifies it on each request. The server keeps only its hash: the full value is displayed only once, when it is created. Signing out revokes the token.

Integration tokens, intended for third-party software, follow the same principle and add three protections:

  • rights limited to what you choose: read, write, synchronisation;
  • an optional expiry date;
  • the date of last use, to spot a forgotten token.

See API authentication.

Secrets of external services

The keys that allow NovaFisko to call external services (Peppol access point, company detection, analysis engine, email server) are encrypted in the database and appear neither in the code nor in the versioned configuration files.

The same applies to the configuration of the integrations enabled on a company file:

  • it is stored encrypted;
  • the interface only displays a masked form of the secret fields;
  • it is excluded from the change history.

Webhook secrets are also encrypted and displayed only once, at creation.

Some files must be displayable without the application transmitting your token, for example a PDF in the viewer. NovaFisko then uses signed links: the address contains a signature and an expiry date, and any modification of the link invalidates it.

Link Validity period
Preview of a PDF export 15 minutes
Preview of a supporting document hosted by Novadesko 20 minutes
Preview of a file uploaded to the importer A few minutes
Logo of a company file or of a firm 30 days
Documents shared by email 7 days
Note

A signed link gives access to the file to anyone who holds it during its validity period. Do not copy it into an email: use the document sending feature provided by the application, or download the file.

Offline local copy

When you make a company file available offline, its data is copied to the device and encrypted with AES 256. The encryption key is generated randomly on the device. It is kept in the secure keychain of the system when available; otherwise, in the preferences of the application, which offers weaker protection.

  • On a shared or borrowed computer, use Clear local data at the end of your session.
  • Enable disk encryption on your computer (FileVault, BitLocker, LUKS): it is the most effective protection in the event of theft.

Access partitioning

  • Each request checks that the user has access to the requested company file. If not, the company file is presented as not found, without confirming its existence.
  • Company files and firms are designated by a random public identifier, and not by a guessable sequential number.
  • Sensitive actions (forcing a revert, purging the trash, changing the team) are reserved for leads, managers and administrators.
  • NovaFisko does not write to Novadesko, with the sole exception of the documents created by the accountant.

Integrity of accounting data

  • A posted entry can be neither changed nor deleted.
  • Each export carries a SHA-256 fingerprint of its data, recorded in the audit trail.
  • The complete accounting file contains a manifest of fingerprints that makes it possible to verify each file.
  • Webhooks are signed (HMAC-SHA256), which allows the recipient to verify their origin.

A fingerprint proves that a file has not been modified. It is neither an electronic signature nor a qualified timestamp.

What depends on hosting

The following points do not depend on the software but on the infrastructure and the organisation. They are to be confirmed in your contractual documents.

Subject Status
Location of the hosting in the European Union Announced by NovaFisko; to be confirmed in the contract
Encryption of disks and backups To be confirmed
Frequency and retention of backups, recovery plan To be confirmed
Management of the access of platform administrators To be confirmed
Penetration tests and certifications To be confirmed
Tip

For your own risk analysis, ask NovaFisko for the up-to-date security sheet and attach it to your record of processing activities.

See also