Back to Home

Security & Data Protection

Last updated: December 2024

Your data is safer here than in your van.

We take security seriously because your customer data, invoices, and financial records are the backbone of your business.

Infrastructure

Graftly is built on enterprise-grade infrastructure, but designed for small businesses. Here is how we keep your data safe:

UK Data Residency

Your data is stored in London (AWS eu-west-2). Never leaves the UK.

Bank-Level Encryption

AES-256 encryption for data at rest. TLS 1.3 for data in transit.

PCI DSS Compliant Payments

We never touch your card numbers. All payments processed by Stripe (Level 1 PCI).

Local-First Architecture

Your phone holds a secure copy. Works offline, syncs when connected.

Automatic Backups

Daily encrypted backups. 30-day retention. Disaster recovery tested.

GDPR Compliant

Full data portability. Right to deletion. Transparent data practices.

Data Storage

Your data is stored in PostgreSQL databases hosted by Supabase in the London (eu-west-2) AWS region. This means:

  • Data never leaves the United Kingdom
  • Subject to UK data protection laws
  • No exposure to foreign data access requests
  • Industry-standard database technology used by thousands of businesses
Data Sovereignty: Unlike US-based competitors, your data stays in London. Not Arizona. Not Sydney. London.

Payment Security

We use Stripe for all payment processing. This means we never see, store, or have access to your card details. Stripe is a PCI Level 1 Service Provider, the highest level of certification in the payments industry.

  • Card numbers are never stored on our servers
  • All payment pages use Stripe's secure hosted fields
  • Stripe handles fraud detection and prevention
  • Your payment details are protected by Stripe's enterprise security

Offline Security

Graftly uses a local-first architecture. This means a copy of your data is stored securely on your device. Here is how we protect it:

  • Local database is encrypted using device-level encryption
  • Biometric authentication (Face ID, fingerprint) available
  • Automatic session timeout for inactive devices
  • Remote wipe capability if device is lost
Device Security: We recommend enabling a PIN or biometric lock on your phone. If your device is lost or stolen, contact us immediately and we can revoke access.

Reliability

We aim for 99.9% uptime. Here is how we achieve it:

  • Redundant infrastructure across multiple availability zones
  • Automatic failover for database and API servers
  • Real-time monitoring and alerting
  • Offline mode ensures you can always access your data

Your Rights

Under GDPR and UK data protection law, you have the right to:

  • Access: Request a copy of all data we hold about you
  • Rectification: Correct any inaccurate information
  • Erasure: Request deletion of your data
  • Portability: Export your data in standard formats (CSV, JSON)
  • Object: Opt out of certain data processing

To exercise any of these rights, email privacy@getgraftly.com or message us on WhatsApp.

Security Contact

If you discover a security vulnerability, please report it responsibly to security@getgraftly.com. We take all reports seriously and will respond within 24 hours.