Security and data protection

We publish only claims that can be verified in the code or in the operational configuration.

EGN encryption at rest

The unified civil number (EGN) is encrypted at rest with AES-256-GCM using a separate personal-data key. This is implemented in the platform code; whether the production key is active for all records is monitored operationally and we do not state it here as an already verified fact.

Authentication

Passwords are stored as bcrypt hashes, never in plain text. The session token (JWT) is sent in an HTTP-only cookie that is not accessible from JavaScript in the browser.

Payments

Payments go through Stripe Checkout: you are redirected to Stripe's hosted payment page and card data never passes through Firmify's servers.

Document integrity

Generated documents receive a SHA-256 hash when created and when signed, so the file can be verified for changes.

Data controller

Firmify EOOD · UIC 208745197 · Sofia 1618, Maestro Kanev St. 66B, entrance V, apt. 10. Details on personal data processing — in the privacy policy.

Privacy policy

This page publishes no claims without evidence: we do not state a specific hosting provider, backup policy, compliance certifications or customer counts.