Security Centre
Customer data, protected by design.
Access controls, encryption, authentication, auditability and privacy-focused architecture — explained plainly.
Data protection & isolation
- Every record belongs to an organisation. Users only access organisations and records they are authorised for.
- Authorisation is enforced server-side and in the database with Row Level Security — not in the browser.
- Roles are stored separately from user profiles and checked on every request.
- Least-privilege access: people and services get only the permissions they need.
Authentication
- Secure account authentication with hashed credentials and managed sessions.
- Multi-factor authentication via authenticator apps (TOTP) and SMS.
- Session tokens expire and refresh automatically.
- Account recovery through verified channels.
Encryption
- All traffic is encrypted in transit with TLS.
- Data is encrypted at rest by the underlying infrastructure.
- Sensitive credentials, such as Open Banking tokens, are stored encrypted and only used server-side.
Documents
- Documents are held in private storage — never public URLs.
- Access is granted through short-lived signed links for authorised users.
- Visibility follows the same organisation and role permissions as the rest of the platform.
Privacy & GDPR
- Designed around data minimisation, purpose limitation and access control.
- Customer organisations are typically the data controller for data they manage in Letzo!; Letzo! processes it on their behalf.
- Letzo! supports customers in responding to data subject requests.
- Contractual terms are set out in our Data Processing Terms and Privacy Policy.
Monitoring & incidents
- Application errors and security-relevant events are logged and monitored.
- Suspected incidents are investigated, contained and remediated.
- Affected customers are informed in line with legal and contractual obligations.
Availability
- Hosted on managed cloud infrastructure with operational monitoring.
- Managed database backups support recovery.
- Errors are captured and triaged continuously.
Customer controls
- Team roles and permissions per organisation.
- MFA for every user.
- Per-user notification preferences.
- Organisation management and document access controls.
Responsible disclosure
Report security vulnerabilities, suspicious activity or privacy concerns to the Letzo! security team.
Please give us reasonable time to investigate before any public disclosure, and do not access or modify other customers’ data.
Letzo! does not currently hold third-party security certifications. See also the Privacy Policy and Data Processing Terms.