Security
15 August 2026
What this page commits to
Every sentence on this page describes what the software does today. When a protection changes, this page changes with it.
To check a point or report a flaw, write to info@at-cg.be. We answer within two working days.
Where your data lives
On OVH servers in the European Union, in a PostgreSQL database. One provider outside the Union receives data in the clear: Resend, a US company, for the address and text of e-mails, under standard contractual clauses. Infomaniak, in Switzerland, only receives archives encrypted before they leave, without the key.
Each business lives inside its own boundary: every business table carries the business identifier, and the code refuses any read that lacks it. One business can neither read nor write inside another.
Who else touches it
Mollie B.V. for payments, without Kallli ever seeing a card number. Resend for e-mails, Brevo for text messages. Infomaniak, in Switzerland, for encrypted backups. Google Ireland Ltd and Microsoft Ireland Operations Ltd if you choose to sign in through them or to sync your calendar. Recommand, a Belgian access point, for Peppol electronic invoices.
Infomaniak receives the full archive, encrypted before it leaves, without the key. The others see only what their task requires: an address for an e-mail, a number for a text message, the client's name and the appointment time in your Google or Outlook calendar if you enable that sync.
How you get in
Passwords of at least twelve characters, hashed with scrypt at the level OWASP recommends. A password found in a known breach is refused, at sign-up and at change: we query Have I Been Pwned by k-anonymity, your password never leaves our servers.
Two-step verification with an authenticator app, with backup codes. It also applies to Google and Microsoft sign-ins. You see your open sessions in your settings and can close one, or all the others.
Five sign-in attempts per five minutes, then a wait. An account whose address is not verified does not get in.
What is protected at rest
Businesses' payment tokens are encrypted with AES-256 before being written. The server refuses to start if the encryption key is missing.
A backup of database and files every night, encrypted with AES-256 before leaving the server, kept fourteen days on site and longer at Infomaniak. An e-mail alert goes out if a backup fails. Every archive can be decrypted and read back without touching production.
All traffic is encrypted in transit, HSTS enabled for a year on all subdomains.
What we keep on record
Every change to an appointment leaves a line: who, when, what changed. The business sees it on the appointment sheet. This log does not erase itself over time.
Subscription invoices are kept ten years, as Belgian law requires, including after a business closes.
If something breaks
A breach affecting your data is reported to you by e-mail within 72 hours of our noticing it, with what was affected and what we did.
We reviewed the code against nine OWASP points on 10 August 2026, then a second time on 15 August. The fixes are in production. The details of the flaws stay between us.
How you leave
You export your client file in one click, at any time. You cancel from your settings, with no letter and no call. The account stays restorable for thirty days, then everything is erased from the database, except the invoices the law requires us to keep. The encrypted backups follow in turn, as they rotate.