Your data, protected
Frihet is built with security from the ground up. End-to-end encryption, EU data residency, full regulatory compliance, and zero tracking without consent.
Encryption
Your data is encrypted at rest and in transit. Integration credentials are protected with the most demanding industry standard.
- AES-256-GCM for stored integration credentials
- TLS 1.3 for all communications in transit
- HMAC-SHA256 for signing webhooks and invoice portal links
- Encryption keys securely managed via Google Cloud KMS
Authentication
Robust access control with multiple identity providers and anti-fraud protections.
- Enterprise authentication with Google, GitHub, and Microsoft providers
- Advanced bot protection on signup and login
- Per-user access rules: each user can only access their own data
- Session tokens with automatic expiration and rotation
Payment Security
We never store card data. All payment processing goes through Stripe, certified PCI DSS Level 1.
- Stripe PCI DSS Level 1: the highest payment security standard
- Zero card data stored on Frihet servers
- Stripe webhooks verified with cryptographic signatures
- Billing portal with single-use HMAC-SHA256 signed links
GDPR Compliance
Privacy by design. We respect your data rights and do not track without explicit consent.
- Cookie consent banner with granular control
- No analytics or tracking until the user gives consent
- Right to data export (Art. 20 GDPR)
- Right to data deletion (Art. 17 GDPR)
- EU data residency: PostHog EU, Sentry EU
Infrastructure
Built on enterprise-grade cloud infrastructure, with geographic redundancy and continuous monitoring.
- Enterprise-grade cloud infrastructure with 99.95% SLA
- Document database with automatic geo-redundant multi-region replication
- Serverless compute with automatic scaling and automated patching
- Global edge network with CDN and DDoS protection
- Real-time status monitoring at status.frihet.io
Regulatory Compliance
Frihet complies with tax and e-invoicing regulations in force in Spain and Europe.
- VeriFactu: hash chain, record immutability, AEAT submission
- TicketBAI: compatible with the Basque Country tax system
- E-invoicing compliant with European regulation
- Data integrity audit with full traceability
- Automated daily backups with 30-day retention
Start with the peace of mind that your data is secure
Free plan available. No credit card. No tracking.
Start free