Security with a concrete scope
We publish which control is available, what surface it protects, and where a third-party provider or beta feature is involved.
This page does not generalize a surface-specific cryptographic control to the whole product, publish a Frihet uptime SLA, or present a beta feature as complete compliance.
- Account security Live
- Stripe payments Live
- VeriFactu Live
- TicketBAI Beta
Cryptographic protection with a documented scope
Encryption is stated only for surfaces verified in the manifest, not as a blanket property of every piece of data.
- AES-256-GCM for stored fiscal certificates in flows that require them
- HMAC-SHA256 verification for 94 webhook event types
- HMAC links for the client and invoice portals
- The GDPR data export includes an encrypted backup
Account and authentication
Account controls are live and listed as specific capabilities in the product manifest.
- TOTP two-factor authentication through Firebase Identity Platform MFA
- Active-session view with individual or global revocation
- Login history with device, browser, and operating system
- Link and unlink Google, GitHub, and Microsoft providers
Payment-flow boundary
Client payments use Stripe Connect and Stripe Checkout sessions. The processor's security controls and certifications belong to Stripe.
- Stripe Connect for accepting client payments
- Checkout sessions for the hosted collection flow
- Payment failures trigger the documented recovery flow
- Current processor terms and certifications should be checked with Stripe
Data and consent controls
Frihet includes specific controls for export, deletion, and consent; we do not summarize them as an absolute guarantee.
- Versioned cookie consent with granular activation
- Account data export as JSON with an encrypted backup
- Scheduled account deletion with a grace period and cancellation
- Erase, PII-scrub, and export functions that preserve applicable fiscal retention
Observable availability
We do not publish our own availability figure without a backed commitment. Current service state is shown on the public status page.
- Public operational status at status.frihet.io
- Current status takes precedence over any marketing message
- No Frihet uptime SLA or blanket availability promise is made here
Fiscal features by status
Scope is published feature by feature. VeriFactu is live; TicketBAI remains beta outside the operational Bizkaia flow.
- VeriFactu live with AEAT XML submission, certificates, statuses, and PDF indicators
- TicketBAI operational in Bizkaia; Gipuzkoa and Araba remain beta until validated with a production certificate
- Stored fiscal certificates use AES-256-GCM
- No blanket fiscal-compliance claim is made for countries or flows not marked live
Service status
Check the public availability source before making an operational decision.
status.frihet.ioReview the controls and try the product
The free plan is available without a card; the security scope is documented here.