AES-256 encryption

Your accounting data never leaves Europe

European hosting, encryption at rest and in transit, full access logging. Here is exactly what we do with your documents.

The journey of an invoice
  • SendingEnd-to-end TLS 1.3, no exceptions.01
  • StorageAES-256, keys managed in Europe.02
  • ProcessingIsolated per company, never pooled.03
  • AccessSSO and two-factor, every read logged.04
Compliance

Guarantees backed by the AWS infrastructure

Paystar is hosted on Amazon Web Services, in the Paris region. We inherit the hosting provider’s certifications for the infrastructure; GDPR compliance and access control remain our responsibility.

  • GDPRAppointed data protection officer, processing register kept up to date, and a standard data processing agreement.DPA available
  • S3 AES-256 encryptionEvery document is encrypted server-side by Amazon S3 with AES-256 as soon as it is uploaded, and only decrypted when read by an authorised user.Encryption at rest
  • AWS SOC reportsThe AWS services we rely on are covered by SOC 1, 2 and 3 reports, renewed every year by an independent auditor and available through AWS Artifact.Renewed every year
  • AWS Paris regionData stored and backed up in the eu-west-3 region of Amazon Web Services, in France. No replication outside the European Union.Never leaves the EU
Architecture

Every company is isolated, key included

Your company's data lives in its own logical space, with its own encryption key. A breach does not spread from one file to another.

  • Keys managed by hardware security module, with automatic rotation
  • No direct database access by our teams, even in production
  • Annual external penetration test, summary provided on request
Access control
  • Administrator accountEnterprise SSO, two-factor mandatoryActive
  • Partner practiceRead access, expires automatically at the end of the engagementActive
  • Service tokenRestricted scope, scheduled rotationActive

Every document view is logged and kept for the full statutory period.

Commitments

What we guarantee, line by line

The same table we hand to our clients' IT departments.

DataLocationEncryptionRetention
Supporting documentsEuropean UnionAES-256 at restStatutory retention period
Ledger entriesEuropean UnionAES-256 at restStatutory retention period
Banking credentialsNever storedMandate held by the authorised provider—
Access logsEuropean UnionAES-256 and timestampingStatutory retention period
BackupsEuropean UnionAES-256, offline copyRolling window
Frequently asked questions

The questions your IT teams ask

Yes. Our standard agreement is GDPR-compliant and covers onward processing; we are also happy to review yours, with an answer within a few working days.

Documentation

Every document, in one place

Hosting provider certifications, security policy, penetration test results, list of subprocessors: the security team sends them on request.