AES-256 encryption
Your accounting data never leaves Europe
European hosting, encryption at rest and in transit, full access logging. Here is exactly what we do with your documents.
The journey of an invoice
- SendingEnd-to-end TLS 1.3, no exceptions.01
- StorageAES-256, keys managed in Europe.02
- ProcessingIsolated per company, never pooled.03
- AccessSSO and two-factor, every read logged.04
Compliance
Guarantees backed by the AWS infrastructure
Paystar is hosted on Amazon Web Services, in the Paris region. We inherit the hosting provider’s certifications for the infrastructure; GDPR compliance and access control remain our responsibility.
- GDPRAppointed data protection officer, processing register kept up to date, and a standard data processing agreement.DPA available
- S3 AES-256 encryptionEvery document is encrypted server-side by Amazon S3 with AES-256 as soon as it is uploaded, and only decrypted when read by an authorised user.Encryption at rest
- AWS SOC reportsThe AWS services we rely on are covered by SOC 1, 2 and 3 reports, renewed every year by an independent auditor and available through AWS Artifact.Renewed every year
- AWS Paris regionData stored and backed up in the eu-west-3 region of Amazon Web Services, in France. No replication outside the European Union.Never leaves the EU
Architecture
Every company is isolated, key included
Your company's data lives in its own logical space, with its own encryption key. A breach does not spread from one file to another.
- Keys managed by hardware security module, with automatic rotation
- No direct database access by our teams, even in production
- Annual external penetration test, summary provided on request
Access control
- Administrator accountEnterprise SSO, two-factor mandatoryActive
- Partner practiceRead access, expires automatically at the end of the engagementActive
- Service tokenRestricted scope, scheduled rotationActive
Every document view is logged and kept for the full statutory period.
Commitments
What we guarantee, line by line
The same table we hand to our clients' IT departments.
| Data | Location | Encryption | Retention |
|---|---|---|---|
| Supporting documents | European Union | AES-256 at rest | Statutory retention period |
| Ledger entries | European Union | AES-256 at rest | Statutory retention period |
| Banking credentials | Never stored | Mandate held by the authorised provider | — |
| Access logs | European Union | AES-256 and timestamping | Statutory retention period |
| Backups | European Union | AES-256, offline copy | Rolling window |
Frequently asked questions
The questions your IT teams ask
Yes. Our standard agreement is GDPR-compliant and covers onward processing; we are also happy to review yours, with an answer within a few working days.
Documentation
Every document, in one place
Hosting provider certifications, security policy, penetration test results, list of subprocessors: the security team sends them on request.