Skip to content

Security with a concrete scope

We publish which control is available, what surface it protects, and where a third-party provider or beta feature is involved.

This page does not generalize a surface-specific cryptographic control to the whole product, publish a Frihet uptime SLA, or present a beta feature as complete compliance.

  • Account security Live
  • Stripe payments Live
  • VeriFactu Live
  • TicketBAI Beta

Cryptographic protection with a documented scope

Encryption is stated only for surfaces verified in the manifest, not as a blanket property of every piece of data.

  • AES-256-GCM for stored fiscal certificates in flows that require them
  • HMAC-SHA256 verification for 94 webhook event types
  • HMAC links for the client and invoice portals
  • The GDPR data export includes an encrypted backup

Account and authentication

Account controls are live and listed as specific capabilities in the product manifest.

  • TOTP two-factor authentication through Firebase Identity Platform MFA
  • Active-session view with individual or global revocation
  • Login history with device, browser, and operating system
  • Link and unlink Google, GitHub, and Microsoft providers

Payment-flow boundary

Client payments use Stripe Connect and Stripe Checkout sessions. The processor's security controls and certifications belong to Stripe.

  • Stripe Connect for accepting client payments
  • Checkout sessions for the hosted collection flow
  • Payment failures trigger the documented recovery flow
  • Current processor terms and certifications should be checked with Stripe

Data and consent controls

Frihet includes specific controls for export, deletion, and consent; we do not summarize them as an absolute guarantee.

  • Versioned cookie consent with granular activation
  • Account data export as JSON with an encrypted backup
  • Scheduled account deletion with a grace period and cancellation
  • Erase, PII-scrub, and export functions that preserve applicable fiscal retention

Observable availability

We do not publish our own availability figure without a backed commitment. Current service state is shown on the public status page.

  • Public operational status at status.frihet.io
  • Current status takes precedence over any marketing message
  • No Frihet uptime SLA or blanket availability promise is made here

Fiscal features by status

Scope is published feature by feature. VeriFactu is live; TicketBAI remains beta outside the operational Bizkaia flow.

  • VeriFactu live with AEAT XML submission, certificates, statuses, and PDF indicators
  • TicketBAI operational in Bizkaia; Gipuzkoa and Araba remain beta until validated with a production certificate
  • Stored fiscal certificates use AES-256-GCM
  • No blanket fiscal-compliance claim is made for countries or flows not marked live

Service status

Check the public availability source before making an operational decision.

status.frihet.io

Review the controls and try the product

The free plan is available without a card; the security scope is documented here.