Security and data protection
We publish only claims that can be verified in the code or in the operational configuration.
EGN encryption at rest
The unified civil number (EGN) is encrypted at rest with AES-256-GCM using a separate personal-data key. This is implemented in the platform code; whether the production key is active for all records is monitored operationally and we do not state it here as an already verified fact.
Authentication
Passwords are stored as bcrypt hashes, never in plain text. The session token (JWT) is sent in an HTTP-only cookie that is not accessible from JavaScript in the browser.
Payments
Payments go through Stripe Checkout: you are redirected to Stripe's hosted payment page and card data never passes through Firmify's servers.
Document integrity
Generated documents receive a SHA-256 hash when created and when signed, so the file can be verified for changes.
Data controller
Firmify EOOD · UIC 208745197 · Sofia 1618, Maestro Kanev St. 66B, entrance V, apt. 10. Details on personal data processing — in the privacy policy.
This page publishes no claims without evidence: we do not state a specific hosting provider, backup policy, compliance certifications or customer counts.