Security
Your business documents deserve serious protection.
What follows is a factual description of the measures BüroPilot uses. We do not claim certifications we have not completed.
Data protection principles
Your data is yours
We process your documents to run the service. We do not sell your data and we do not use client information for advertising.
Minimal collection
We collect the information the product needs to create documents and run your account, and nothing beyond it.
Clear separation
Each company account is isolated so one customer can never read another customer's documents.
Reversible decisions
You can export your data or ask for account deletion without contacting sales first.
How BüroPilot protects your documents
Each measure below is either implemented or part of the launch scope. We update this page rather than promise more than the product does.
- Encryption
- Traffic between your browser and BüroPilot runs over HTTPS with modern TLS. Stored documents, database contents and backup copies are encrypted at rest.
- Authentication and optional 2FA
- Passwords are stored as salted hashes and are never readable by us or displayed back to you. Two-factor authentication can be enabled per user for accounts that need a second step at sign-in.
- Company-level data separation
- Every record belongs to exactly one company account, and access checks run on the server for each request rather than being enforced only in the interface.
- Backups and document archive
- Backups run on a schedule and are stored encrypted. Sent and generated documents stay available in your archive so your document history is recoverable.
- Audit history
- Important actions on documents — created, edited, sent, marked paid — are recorded with a timestamp and the user who performed them.
- Data export and deletion
- You can export your documents and client data from your account. On request, account data is deleted, subject to the retention periods Swiss bookkeeping rules require for issued documents.
- Hosting
- Account data and documents are stored on infrastructure located in Switzerland.
Reporting a security issue
If you believe you have found a vulnerability, contact us before disclosing it publicly. We will confirm receipt and keep you informed while we investigate.
