Your data is safer here than in your van.
We take security seriously because your customer data, invoices, and financial records are the backbone of your business.
Infrastructure
Graftly is built on enterprise-grade infrastructure, but designed for small businesses. Here is how we keep your data safe:
UK Data Residency
Your data is stored in London (AWS eu-west-2). Never leaves the UK.
Bank-Level Encryption
AES-256 encryption for data at rest. TLS 1.3 for data in transit.
PCI DSS Compliant Payments
We never touch your card numbers. All payments processed by Stripe (Level 1 PCI).
Local-First Architecture
Your phone holds a secure copy. Works offline, syncs when connected.
Automatic Backups
Daily encrypted backups. 30-day retention. Disaster recovery tested.
GDPR Compliant
Full data portability. Right to deletion. Transparent data practices.
Data Storage
Your data is stored in PostgreSQL databases hosted by Supabase in the London (eu-west-2) AWS region. This means:
- Data never leaves the United Kingdom
- Subject to UK data protection laws
- No exposure to foreign data access requests
- Industry-standard database technology used by thousands of businesses
Payment Security
We use Stripe for all payment processing. This means we never see, store, or have access to your card details. Stripe is a PCI Level 1 Service Provider, the highest level of certification in the payments industry.
- Card numbers are never stored on our servers
- All payment pages use Stripe's secure hosted fields
- Stripe handles fraud detection and prevention
- Your payment details are protected by Stripe's enterprise security
Offline Security
Graftly uses a local-first architecture. This means a copy of your data is stored securely on your device. Here is how we protect it:
- Local database is encrypted using device-level encryption
- Biometric authentication (Face ID, fingerprint) available
- Automatic session timeout for inactive devices
- Remote wipe capability if device is lost
Reliability
We aim for 99.9% uptime. Here is how we achieve it:
- Redundant infrastructure across multiple availability zones
- Automatic failover for database and API servers
- Real-time monitoring and alerting
- Offline mode ensures you can always access your data
Your Rights
Under GDPR and UK data protection law, you have the right to:
- Access: Request a copy of all data we hold about you
- Rectification: Correct any inaccurate information
- Erasure: Request deletion of your data
- Portability: Export your data in standard formats (CSV, JSON)
- Object: Opt out of certain data processing
To exercise any of these rights, email privacy@getgraftly.com or message us on WhatsApp.
Security Contact
If you discover a security vulnerability, please report it responsibly to security@getgraftly.com. We take all reports seriously and will respond within 24 hours.