Trust & Security

Security at 7Konto

How we protect your data, your customers' data, and your business. Enterprise-grade security practices built into the platform from day one.

Security isn't a checkbox at 7Konto — it's built into the platform architecture. Every design decision considers security implications, from database schema (immutable audit logs, cryptographic signing) to infrastructure choices (EU data residency, redundant deployments) to operational practices (72-hour incident notification, regular drills).

Security domains

How we secure the platform

Six areas of security practice, applied continuously.

Encryption

  • TLS 1.3 for all data in transit
  • AES-256 encryption at rest
  • Encrypted database backups
  • Encrypted API tokens with SHA-256 hashing
  • HMAC-signed webhook payloads

Access Control

  • Role-based access control (RBAC) for admin users
  • API key management with granular scopes
  • Multi-factor authentication support
  • Session management with automatic timeout
  • IP allowlisting for Enterprise tier

Infrastructure

  • EU-based data centers by default (GDPR compliance)
  • Redundant deployments with automatic failover
  • Real-time monitoring with 24/7 alerting
  • Regular security patching
  • DDoS protection at edge

Regulatory Compliance

  • GDPR-compliant data handling by design
  • PSD2 closed-loop exemption compliance
  • Slovak Data Protection Act adherence
  • Data Processing Agreements available
  • Records of Processing Activities maintained

Auditability

  • Immutable audit logs for all transactions
  • User action logging for admin operations
  • Reconciliation reports for financial accuracy
  • Data export APIs for customer verification
  • Timestamped, cryptographically signed events

Incident Response

  • Documented incident response procedures
  • Notification within 72 hours for personal data breaches
  • Regular incident response drills
  • Post-incident reports for affected customers
  • Continuous improvement based on lessons learned
Compliance

Standards and regulations

Standard Description Status
GDPR General Data Protection Regulation (EU 2016/679) Compliant by design
PSD2 Closed-Loop Payment Services Directive 2 closed-loop exemption Operating under exemption
Slovak Data Protection Act Zákon o ochrane osobných údajov Compliant
CCPA California Consumer Privacy Act (for US customers) Compatible practices
SOC 2 Type I System and Organization Controls audit In progress
Data protection

Where and how we store data

Default: EU data centers

All customer data is stored in EU-based data centers by default, providing GDPR compliance and low latency for European customers. Backups are stored redundantly across multiple EU locations.

Regional options (Enterprise)

Enterprise customers can request data residency in other regions (US, UK, Ukraine, Africa) to meet local regulatory requirements. Cross-region replication with appropriate safeguards.

Data minimization

We collect only the data necessary to provide our Services. We never sell customer data. We use aggregated, anonymized data for analytics only where personal identification is impossible.

Data ownership

You own your customer data. We're a data processor, not a controller. Full data export via API. Deletion available on request. Migration assistance provided if you switch platforms.

Reporting

Report a security issue

If you've found a security vulnerability, please report it responsibly. We take reports seriously and respond quickly.

Responsible disclosure

  1. 1. Email security@7konto.com with details of the vulnerability
  2. 2. We will acknowledge receipt within 24 hours
  3. 3. We will investigate and provide status updates
  4. 4. We will notify you when the issue is fixed
  5. 5. With your permission, we may publicly acknowledge your contribution

Please do not publicly disclose vulnerabilities before we've had a reasonable opportunity to address them. We appreciate responsible reporting and work quickly on legitimate issues.

Security questions before signing up?

We're happy to discuss specific security requirements, review documentation, sign NDAs, and complete security questionnaires.

Discuss security requirements