Encryption and data protection
The technical measures actually in place in NovaFisko: encrypted transport, passwords, tokens, secrets, signed links, local copy and access control.
This page describes the protection measures implemented by the software. It distinguishes what can be verified in the way NovaFisko works from what depends on hosting and organisation, which is marked "to be confirmed".
Overview
| Measure | In place in the software |
|---|---|
| Encrypted exchanges (HTTPS) with mandatory secure connection | Yes |
| Passwords stored as an irreversible hash | Yes |
| Session and integration tokens stored as a hash | Yes |
| Secrets of external services and integrations encrypted in the database | Yes |
| Offline local copy encrypted on the device | Yes (AES 256) |
| Signed, time-limited preview links | Yes |
| Limitation of sign-in attempts | Yes |
| SHA-256 fingerprint of exports | Yes |
| Full encryption of the server disks | To be confirmed with the hosting provider |
| Two-factor authentication | Coming soon |
Encryption of exchanges
All communication between the application and the server goes through HTTPS. The server sends the strict transport security header (HSTS) with a duration of one year, subdomains included: a browser that has already visited the site then refuses any unencrypted connection.
Other security headers accompany each response: no display of the pages in a frame of another site, no guessing of file types, limitation of the information passed on to third-party sites, deactivation of the camera, the microphone and geolocation.
Passwords and sign-in
- Passwords are never stored in clear text. Only an irreversible hash is kept; NovaFisko cannot tell you your password, only let you reset it.
- After ten failed sign-in attempts from the same address, sign-ins are blocked for five minutes.
- Each sign-in, successful or failed, is recorded in the audit log.
- For a user of a firm linked to Novadesko, the credentials are verified with Novadesko.
Two-factor authentication is not yet available in the application. In the meantime, use a long and unique password, managed by a password manager, and never share an account between several team members.
Access tokens
After sign-in, the application receives a token that identifies it on each request. The server keeps only its hash: the full value is displayed only once, when it is created. Signing out revokes the token.
Integration tokens, intended for third-party software, follow the same principle and add three protections:
- rights limited to what you choose: read, write, synchronisation;
- an optional expiry date;
- the date of last use, to spot a forgotten token.
See API authentication.
Secrets of external services
The keys that allow NovaFisko to call external services (Peppol access point, company detection, analysis engine, email server) are encrypted in the database and appear neither in the code nor in the versioned configuration files.
The same applies to the configuration of the integrations enabled on a company file:
- it is stored encrypted;
- the interface only displays a masked form of the secret fields;
- it is excluded from the change history.
Webhook secrets are also encrypted and displayed only once, at creation.
Signed links
Some files must be displayable without the application transmitting your token, for example a PDF in the viewer. NovaFisko then uses signed links: the address contains a signature and an expiry date, and any modification of the link invalidates it.
| Link | Validity period |
|---|---|
| Preview of a PDF export | 15 minutes |
| Preview of a supporting document hosted by Novadesko | 20 minutes |
| Preview of a file uploaded to the importer | A few minutes |
| Logo of a company file or of a firm | 30 days |
| Documents shared by email | 7 days |
A signed link gives access to the file to anyone who holds it during its validity period. Do not copy it into an email: use the document sending feature provided by the application, or download the file.
Offline local copy
When you make a company file available offline, its data is copied to the device and encrypted with AES 256. The encryption key is generated randomly on the device. It is kept in the secure keychain of the system when available; otherwise, in the preferences of the application, which offers weaker protection.
- On a shared or borrowed computer, use Clear local data at the end of your session.
- Enable disk encryption on your computer (FileVault, BitLocker, LUKS): it is the most effective protection in the event of theft.
Access partitioning
- Each request checks that the user has access to the requested company file. If not, the company file is presented as not found, without confirming its existence.
- Company files and firms are designated by a random public identifier, and not by a guessable sequential number.
- Sensitive actions (forcing a revert, purging the trash, changing the team) are reserved for leads, managers and administrators.
- NovaFisko does not write to Novadesko, with the sole exception of the documents created by the accountant.
Integrity of accounting data
- A posted entry can be neither changed nor deleted.
- Each export carries a SHA-256 fingerprint of its data, recorded in the audit trail.
- The complete accounting file contains a manifest of fingerprints that makes it possible to verify each file.
- Webhooks are signed (HMAC-SHA256), which allows the recipient to verify their origin.
A fingerprint proves that a file has not been modified. It is neither an electronic signature nor a qualified timestamp.
What depends on hosting
The following points do not depend on the software but on the infrastructure and the organisation. They are to be confirmed in your contractual documents.
| Subject | Status |
|---|---|
| Location of the hosting in the European Union | Announced by NovaFisko; to be confirmed in the contract |
| Encryption of disks and backups | To be confirmed |
| Frequency and retention of backups, recovery plan | To be confirmed |
| Management of the access of platform administrators | To be confirmed |
| Penetration tests and certifications | To be confirmed |
For your own risk analysis, ask NovaFisko for the up-to-date security sheet and attach it to your record of processing activities.