Security and data protection
Security, hosting and data protection
Alibera runs either on a server you own or in the cloud with providers in Slovenia or the EU. This page sets out where your data sits, who can reach it, what happens when something breaks, and what we do not claim.
Anything settled in your contract rather than fixed for everyone is marked as such below.
Where each answer is settled
- Data residency
- In your contract
- Audit trail
- Always on, in the product
- Backups
- Configurable per customer
- Recovery time
- In your contract
- Accreditation
- None, see below
01Where your data lives
Two ways to run Alibera
You choose where the database sits. That choice changes who holds the server, not which features you get.
| CloudWe host it | On-premiseYou host it | |
|---|---|---|
| Where the database sits | With hosting providers in Slovenia or the EU. | On hardware you own. |
| Who controls access to the server | We do, inside the scope your contract sets. | You do, physically and on the network. |
| Multi-factor sign in | On by default. | Configurable. |
| Restore after an outage | We run it for you, from the last verified stable backup. | You can run it yourself, from the last verified stable backup. |
| Audit trail on every login, change and deletion | Yes | Yes |
| Role, department and location permissions | Yes | Yes |
| Separate staging environment | Yes | Yes |
The same product either way
Access control, the audit trail and the staging environment are part of the system in both models. Multi-factor sign in is on by default in cloud and configurable on-premise.
02GDPR
Personal data, handled to the contract
We follow GDPR and the other regulations that apply to your business. Processing is limited to what your contract covers, and your data does not leave the country without your consent.
Ask us for
- the hosting arrangement that would apply to your contract
- the retention periods we would agree with you
- the processing terms we would put in writing
- Access, correct, delete
- You hold those rights over the personal data in your system, and we support you in exercising them.
- Written into the contract
- How those rights work in practice is defined with you, rather than left to a policy page you never signed.
- Scope-limited processing
- We process what your contract covers, and your data does not leave the country without your consent.
03Backups and recovery
Backups you can actually restore from
Backups are encrypted and stored separately from the live system, and access to them is strictly limited. How often they run is set per customer. We recommend daily or weekly, depending on how much of your operation stops when the system does.
- Encrypted, and kept apart from the primary system
- Frequency configurable, with daily or weekly recommended
- Access to the backups is strictly limited
If something goes down
We restore the system to the last verified stable backup. On-premise customers can run that restore themselves, and in cloud we run it for you.
04Access control and the audit trail
Who can open what, and a record of what they did
- Every login, change and deletion is logged
- The log records the user, the timestamp and a description of the action. It is part of the system, always on, and not something you pay extra to switch on.
- Roles, departments and locations
- Permissions are role based and can be scoped to an individual, a department or a location, with inheritance. They are configured around your structure rather than picked off a fixed list.
- How people sign in
- Multi-factor sign in is on by default in cloud and configurable on-premise. Sign in can also be restricted by IP address and filtered by email domain.
- A separate staging environment
- Changes are tested in an environment that is not your live system. You see a change working before it reaches the people doing the work.
- Integration traffic is signed and encrypted
- Traffic between Alibera and the systems it connects to uses signed tokens and encryption on the wire. The API will not answer a request that is not signed.
- Security testing runs regularly
- We test the system on a regular basis. We are not naming a standard or a third party for it, because we would then be implying an accreditation we do not hold.
Slovenian market
FURS fiscalization
FURS fiscalization is work we have done for the Slovenian market, through the tax certification project behind the Alibera Accounting module. We are not going to describe it here as a finished feature you can switch on.
How it applies depends on how you issue documents, so we go through it with you during configuration rather than describing one fixed setup here. If it is the reason you are on this page, raise it on the first call.
06Straight answers
What we do not claim
A security page is worth as much for what it refuses to say. Here is what you will not find above, and why.
- Not claimedNo accreditation to wave at you
- Alibera holds no third party security accreditation, and we are not going to imply one by printing a standard name on this page.
- Not claimedNo availability figure
- We do not publish an availability percentage. Nothing we have measured is published in a form that would back one up, so quoting a number would be marketing rather than information.
- Not claimedNo response or recovery times here
- Recovery time, response time and retention periods are set in your contract, against what your business actually needs. A figure on this page that did not match your contract would be worse than no figure at all.
- Not claimedWhat our own team can see
- Technician access is limited to what an intervention needs, it is logged, and it is visible to you. We do not claim that our team is unable to see your data, because people supporting a live system sometimes have to look at it.
Bring the hard security questions to the first call
Send the questions your IT lead would ask. We would rather answer them before you shortlist us than after.