Security & trust
Last updated: 3 June 2026
We treat the security of customer and end-customer data as a first-class product requirement. This page summarises the controls we operate today, the vendors we rely on, and where to find authoritative information. For the contractual version, see Schedule 2 of our DPA.
Data protection
- In transit: all public traffic is encrypted using modern TLS.
- At rest: the production database, backups, and object storage are encrypted.
- Tenant isolation: data is isolated per tenant and continuously tested for cross-tenant leakage.
- Card data: never stored by BookOS, handled directly by a PCI-DSS Level 1 payment provider.
Access & authentication
- BookOS operator credentials are isolated in the environment, not stored in the application database.
- Role-based, least-privilege access with periodic reviews.
- Customer-side: passwords are securely hashed; sessions are scoped per device.
Reliability & recovery
- Encrypted backups with point-in-time recovery on the production database.
- Restore procedures are documented and tested regularly.
- The Service is hosted in the EU on reputable managed cloud infrastructure.
Vulnerability management
- Automated dependency updates across our repositories.
- Security patches applied promptly; critical issues prioritised.
- Coordinated disclosure programme: see vulnerability disclosure and /.well-known/security.txt.
Monitoring & incident response
- Centralised application logs, security event logs, and immutable audit trails.
- Error tracking and anomaly alerting on production systems.
- Documented incident-response playbook with prompt triage of suspected breaches.
- Customer notification of confirmed personal-data breaches within 72 hours under GDPR Art. 33 / DPA § 9.
Data residency & sub-processors
Application and database are hosted in the EU. A small set of sub-processors is engaged to deliver the Service. The current list, with role, location, and transfer mechanism, is published at bookos.io/legal/subprocessors and forms part of our DPA.
Compliance & certifications
- GDPR & ePrivacy: we operate under EU data-protection law; our DPA incorporates the EU Standard Contractual Clauses (2021/914) for any necessary international transfers.
- Danish Bookkeeping Act: 7-year retention of invoices and accounting records.
- Digital Services Act: single point of contact published at /legal/dsa-contact.
- Independent certifications: a current compliance summary is available to enterprise customers under NDA.
Security questionnaires & due diligence
Enterprise customers may request our standard security questionnaire response (CAIQ-Lite based) and the latest summaries of third-party assessments by emailing security@bookos.io. We respond within 10 business days.
Reporting security issues
Report a suspected vulnerability to security@bookos.io per the rules in our disclosure programme. We do not pursue good-faith researchers who follow the published policy.
