Security
The security of your data is a central part of how we build and operate Volk Accountant. On this page we set out the technical and organisational measures we rely on to keep your information confidential, available and protected against loss or unauthorised access. We continuously review and refine these measures in line with the current state of technology.
Encryption in transit
The entire website and application are encrypted using TLS (HTTPS). This means that all data exchanged between your device and our servers – from login credentials to the receipts and invoices you work with – travel through an encrypted connection.
The encryption protects the transmitted information from being read or manipulated by third parties while it is on its way across the network, for example over public or shared internet connections.
Encryption at rest
Data that you store in Volk Accountant are kept in encrypted form. Encryption at rest ensures that stored information cannot simply be read even if someone were to gain physical or low-level access to the underlying storage media.
Together with encryption in transit, this creates a consistent layer of protection for your data both while they are being transmitted and while they are being stored.
EU data storage (Frankfurt)
Your data is deliberately stored within the European Union: the database and file storage run on Supabase in the EU/Frankfurt region, and the application itself runs on Vercel with Frankfurt am Main as its function region.
This means the processing of your data falls under the high level of protection set out in the GDPR. A number of supporting services — email delivery, AI-assisted receipt recognition and payment processing — are provided by companies based in the USA. Those transfers are safeguarded by Standard Contractual Clauses under Art. 46 GDPR and, where applicable, the EU-US Data Privacy Framework. The individual providers are listed in our privacy policy.
Regular backups
We create regular, automated backups of your data. These backups allow us to restore information in the event of a technical fault, an operational error or another incident that could otherwise lead to data loss.
Automating this process ensures that backups are made reliably and consistently, without depending on manual intervention.
Access restriction on a need-to-know basis
Access to systems and data is granted strictly on a need-to-know basis. Only authorised personnel have access, and that access is limited to what is actually required to carry out their specific tasks.
By keeping the circle of people with access as small as possible and tying it to a genuine operational need, we reduce the risk of both accidental and deliberate misuse.
Separation of customer data
The data of different customers are kept logically separated from one another. This separation ensures that the information belonging to one customer cannot be accessed or seen in the context of another customer's account.
Maintaining clear boundaries between customer datasets is a fundamental part of how the application is designed and operated.
Password security
Login credentials are never stored in plain text. We store passwords using recognised, secure procedures so that the original password cannot be reconstructed from the stored value.
To protect your own account, we recommend choosing a strong, unique password that you do not reuse for other services, and keeping your credentials confidential at all times.
Reporting security incidents
If you become aware of a potential vulnerability or a possible security incident, please let us know by email at info@volkaccountant.com. We take every report seriously and investigate each one.
Your reports help us to identify and address issues quickly and to keep improving the security of our services for all customers.
Last updated: 22 July 2026
