Security and data protection

Security, hosting and data protection

Alibera runs either on a server you own or in the cloud with providers in Slovenia or the EU. This page sets out where your data sits, who can reach it, what happens when something breaks, and what we do not claim.

Anything settled in your contract rather than fixed for everyone is marked as such below.

Where each answer is settled

Data residency
In your contract
Audit trail
Always on, in the product
Backups
Configurable per customer
Recovery time
In your contract
Accreditation
None, see below

01Where your data lives

Two ways to run Alibera

You choose where the database sits. That choice changes who holds the server, not which features you get.

Cloud and on-premise, side by side
CloudWe host itOn-premiseYou host it
Where the database sitsWith hosting providers in Slovenia or the EU.On hardware you own.
Who controls access to the serverWe do, inside the scope your contract sets.You do, physically and on the network.
Multi-factor sign inOn by default.Configurable.
Restore after an outageWe run it for you, from the last verified stable backup.You can run it yourself, from the last verified stable backup.
Audit trail on every login, change and deletionYesYes
Role, department and location permissionsYesYes
Separate staging environmentYesYes

The same product either way

Access control, the audit trail and the staging environment are part of the system in both models. Multi-factor sign in is on by default in cloud and configurable on-premise.

02GDPR

Personal data, handled to the contract

We follow GDPR and the other regulations that apply to your business. Processing is limited to what your contract covers, and your data does not leave the country without your consent.

Ask us for

  • the hosting arrangement that would apply to your contract
  • the retention periods we would agree with you
  • the processing terms we would put in writing
Request these three
Access, correct, delete
You hold those rights over the personal data in your system, and we support you in exercising them.
Written into the contract
How those rights work in practice is defined with you, rather than left to a policy page you never signed.
Scope-limited processing
We process what your contract covers, and your data does not leave the country without your consent.

03Backups and recovery

Backups you can actually restore from

Backups are encrypted and stored separately from the live system, and access to them is strictly limited. How often they run is set per customer. We recommend daily or weekly, depending on how much of your operation stops when the system does.

  • Encrypted, and kept apart from the primary system
  • Frequency configurable, with daily or weekly recommended
  • Access to the backups is strictly limited

If something goes down

We restore the system to the last verified stable backup. On-premise customers can run that restore themselves, and in cloud we run it for you.

04Access control and the audit trail

Who can open what, and a record of what they did

Every login, change and deletion is logged
The log records the user, the timestamp and a description of the action. It is part of the system, always on, and not something you pay extra to switch on.
Roles, departments and locations
Permissions are role based and can be scoped to an individual, a department or a location, with inheritance. They are configured around your structure rather than picked off a fixed list.
How people sign in
Multi-factor sign in is on by default in cloud and configurable on-premise. Sign in can also be restricted by IP address and filtered by email domain.
A separate staging environment
Changes are tested in an environment that is not your live system. You see a change working before it reaches the people doing the work.
Integration traffic is signed and encrypted
Traffic between Alibera and the systems it connects to uses signed tokens and encryption on the wire. The API will not answer a request that is not signed.
Security testing runs regularly
We test the system on a regular basis. We are not naming a standard or a third party for it, because we would then be implying an accreditation we do not hold.

Slovenian market

FURS fiscalization

FURS fiscalization is work we have done for the Slovenian market, through the tax certification project behind the Alibera Accounting module. We are not going to describe it here as a finished feature you can switch on.

How it applies depends on how you issue documents, so we go through it with you during configuration rather than describing one fixed setup here. If it is the reason you are on this page, raise it on the first call.

06Straight answers

What we do not claim

A security page is worth as much for what it refuses to say. Here is what you will not find above, and why.

Not claimedNo accreditation to wave at you
Alibera holds no third party security accreditation, and we are not going to imply one by printing a standard name on this page.
Not claimedNo availability figure
We do not publish an availability percentage. Nothing we have measured is published in a form that would back one up, so quoting a number would be marketing rather than information.
Not claimedNo response or recovery times here
Recovery time, response time and retention periods are set in your contract, against what your business actually needs. A figure on this page that did not match your contract would be worse than no figure at all.
Not claimedWhat our own team can see
Technician access is limited to what an intervention needs, it is logged, and it is visible to you. We do not claim that our team is unable to see your data, because people supporting a live system sometimes have to look at it.

Bring the hard security questions to the first call

Send the questions your IT lead would ask. We would rather answer them before you shortlist us than after.