Security

Accounting documents should stay private.

Files are stored privately, customer links expire, and access to firm data is restricted across storage, the database and server routes.

The BilagPilot mascot protects documents with a security shield

How access is restricted

Customer link

  • Each link applies to one specific request.
  • The link uses a random token. Only its SHA-256 hash is stored.
  • It expires, can be replaced and is an access link, not identity verification.

File

  • Uploaded files are stored in private Supabase Storage.
  • Downloads pass through controlled server routes and time-limited signed links.
  • File type, size, count and upload attempts are validated and limited.

Firm

  • Access requires sign-in, membership and the correct role.
  • Row Level Security and server checks scope clients, requests, files, reminders, integrations and activity to the correct firm.
  • Requests, link opens, uploads, reminders, status changes and completion are logged.

Data and responsibility

  • For client data in the service, the accounting firm is the controller and BilagPilot is the processor.
  • Supabase provides the database and private file storage. Other subprocessors and processing locations are listed in the privacy notice.
  • Retention and deletion follow the data processing agreement. BilagPilot is not the official accounting archive.

Security questions

Report possible misconfiguration or suspected incidents to kevin@bilagpilot.no. Include the time and affected account or link. Do not send documents or unnecessary personal data by email.