Security is the product — and how we run it.
FirmoryX exists to help you prove your clients' security posture, so our own has to hold up. Here is how we protect the data you trust us with. For formal certifications like SOC 2 or ISO 27001, see the note below.
Tenant isolation at the database
Every organization's data is separated by PostgreSQL Row-Level Security policies enforced in the database itself — not just in application code — so one tenant can never read another's clients, devices, or reports.
Encryption in transit
All traffic to firmoryx.se is served over HTTPS/TLS. Data moving between our application and our database and storage providers is encrypted in transit.
We never touch card data
Payments are handled entirely by Stripe, a PCI-DSS Level 1 provider. Card numbers are entered directly into Stripe and never reach FirmoryX's servers.
Least-privilege access & roles
Accounts are scoped by role (admin vs. technician). Sensitive surfaces — billing, user management, client management — are enforced on the server, not just hidden in the UI. Roles are read from a trusted server-side source and cannot be spoofed by the client.
Managed authentication
Sign-in is handled by a managed authentication provider with securely hashed credentials and signed session cookies. We only set cookies strictly necessary to keep you signed in — no advertising trackers.
Authenticated email
Alert and digest email is sent from our own mail infrastructure with SPF, DKIM, and DMARC configured on firmoryx.se, protecting recipients from spoofed messages in our name.
Tamper-evident evidence
Every compliance report carries a stable report ID and a SHA-256 content hash, so any later modification of the exported PDF is detectable.
Data residency & sub-processors
Generated evidence PDFs are stored in EU-jurisdiction object storage. Our full sub-processor list, including where each one operates, is published and kept current.
Your data, your control
You can export your entire organization's data, or permanently delete it, at any time from Settings → Account & data — satisfying GDPR access, portability, and erasure rights.
Certifications & compliance
FirmoryX is built to be GDPR-compliant and uses infrastructure providers that are themselves SOC 2 and ISO 27001 certified (Neon, Vercel, Cloudflare, Stripe). We do not yet hold our own SOC 2 or ISO 27001 attestation — a deliberate sequencing decision for an early-stage product. If your procurement process requires one, talk to us about timelines.
Report a vulnerability
Found a security issue? We want to hear from you. Email security@firmoryx.se with details and steps to reproduce. Please give us a reasonable window to remediate before any public disclosure; we will acknowledge your report and keep you updated.
See also our Privacy Policy, DPA, and sub-processor list.