How Bilenta protects accounting data
Accounting data is sensitive. Bilenta ships the controls accountants ask for on every plan. We say plainly what is not certified yet.
Two-factor authentication
TOTP-based 2FA with backup codes and trusted devices. Company owners can require 2FA for every member before they touch the books.
Encryption
Connections use TLS 1.2+. Bank credentials and signing certificates are stored with AES-256-GCM. Files in S3 use AES-256. Not every personal identifier uses field-level AES-256-GCM.
Roles & permissions
Six built-in roles with per-page permissions and approval workflows — everyone sees exactly what their job needs, nothing more.
Full audit trail
Every change is logged: who did what, when, and from where. Essential for firms, reassuring for everyone.
Account protection
Brute-force lockouts, session revocation on password change, and security alerts that notify admins about unusual activity.
Your data stays yours
BILENTA Ltd. is an EU-registered company in Burgas. The GDPR page is public. Export or delete company data as described there.
Hosted in the EU
The application, PostgreSQL, encrypted backups and uploaded files sit on AWS in eu-north-1 (Stockholm). That data is not copied to a region outside the EU. We do not claim ISO 27001, SOC 2, or a contractual uptime, RPO or RTO figure.
Self-serve export
From Settings → Data, download a JSON archive of the books and a ZIP of documents. Secrets such as SMTP passwords are stripped. No support ticket required.
What we do not claim
Bilenta is not ISO 27001 or SOC 2 certified and we do not publish a contractual uptime, RPO or RTO figure. If procurement needs those in a contract, ask — including for an Enterprise instance.