Security
Last updated: 25 September 2026
How Faktury.co.uk protects your invoices and your account. We state only what we have measured or what the code enforces — with the limits of each measure.
Encryption of your data
Invoice and receipt files (PDFs, photos, e-mail bodies) and sensitive fields — addresses, VAT numbers, line items, accounting firms’ bank details, notes and support correspondence — are stored encrypted with AES-256-GCM, with a fresh data key for every write.
Data keys are protected by a master key in AWS Key Management Service in London (eu-west-2), which never leaves AWS and rotates automatically every year. Each encrypted value is bound to its table, row and field: copied anywhere else, it cannot be read.
Some fields stay in plain form because the database must search or add them up: supplier name, invoice number, amounts, dates and e-mail addresses.
Connections
Both sites work only over HTTPS (TLS 1.3, HSTS for 2 years with preload). Key exchange combines the classic X25519 curve with ML-KEM-768 (FIPS 203) — we measured X25519MLKEM768 being negotiated on 25 September 2026 between the browser and our edge network (Cloudflare). We did not measure the hop from the edge to our hosting for this page.
The limit: certificate signatures are still classical. Hybrid key exchange protects today’s recorded traffic from being decrypted in the future; we do not claim anything is “100% quantum-safe”.
Check it yourself: echo | openssl s_client -connect www.faktury.co.uk:443 -groups X25519MLKEM768 2>/dev/null | grep Negotiated
Where your data is
- Application: Vercel, functions in London.
- Database and files: Supabase, on AWS infrastructure in Ireland (eu-west-1).
- Encryption keys: AWS KMS in London.
- The full list of providers, countries and transfer safeguards: Privacy Policy, sections 4 and 5.
Sign-in and your account
- Two-factor authentication (authenticator app) and passkeys.
- Lockout after repeated failed sign-ins, and bot protection on sign-in.
- Passwords are stored only as a hash.
- Invoice files are never handed out as direct storage links: our server serves them, and a preview uses a link valid for 5 minutes, bound to you and to that invoice.
Deleting your data
Deleting your account in the app first removes every invoice file, then the account data; it succeeds only once the file folder is empty. Documents in the Bin disappear after 30 days, file included. Retention periods for everything else are in the Privacy Policy, section 6.
Reporting a problem
Found a vulnerability? Write to pomoc@faktury.co.uk. We will reply, and we will not take legal action against anyone who reports in good faith without accessing other people’s data.