Your figures, under your control.
Financial data is the most sensitive thing a company has. statycs keeps it in the EU, encrypted at every step, and open only to the people you choose.
YOUR DEVICE
-
Your file stays with you
Read in your own browser - never uploaded.
-
Only the figures travel, encrypted
Nothing else leaves your computer.
EUROPEAN UNION
-
Checked at the door
Passkeys, and your administrators approve every new device.
-
Stored encrypted, kept apart
Encrypted at rest, logically separated per customer.
-
Backed up three times over
Encrypted before it leaves, in at least three separate locations.
Encrypted at every step.
Your files are never uploaded: they are read in your own browser. Your data is encrypted in transit, at rest and in every backup, and the backups are kept in at least three separate locations inside the EU.
EU
Nothing crosses this line - no copy, no cache, no backup.
One customer never sees another.
Every request is checked on our servers against the company it belongs to. Identifiers are random, so nothing can be guessed.
There is no impersonation feature - no button that shows us your screen.
Your data works for you, not for us.
Your figures are never sold, and identifiable figures are never shared with anyone.
You can export everything at any time, and when you leave, we delete it.
No passwords. Passkeys.
There is no password to phish, reuse or leak, because statycs never issues one. And the decision over who gets in stays with you.
-
Sign in without a password
A single-use code to the user's verified address the first time, then a passkey on their device. Nothing is stored that a breach elsewhere could reuse here.
-
Required, if you want it
Your administrators can make passkeys mandatory, for administrators only or for everyone. Passkeys follow the FIDO2 standard and cannot be phished.
-
New devices need your approval
Every new passkey has to be approved by one of your administrators. Someone who takes over a mailbox still cannot open your figures.
-
Everyone sees only their part
Roles from viewer to administrator, set per company. A department head can be limited to their own department's figures.
What reviewers ask first.
Anything beyond this we will answer directly, in writing, and we are happy to complete your own questionnaire.
Where is our data stored?
Inside the European Union: the application, the database and every backup. Every provider involved is listed, with its location and purpose, in our data processing agreement. That is where the list carries contractual weight, and where you gain the right to be notified before it changes.
How is our data protected?
It is encrypted on the way from your browser to us, between our own services, at rest, and in every backup. The database is not reachable from the internet; only the application can talk to it.
What happens to a file we upload?
It is read in your own browser, and the file itself is never transmitted to us. Only the extracted figures are sent. That removes a whole category of risk: there is no uploaded document on our side to be lost, leaked or misused.
How do users sign in?
Without passwords - none is ever created, transmitted or stored. On first login the user receives a single-use code at their verified email address, then sets up a passkey on their device. From then on the passkey is the key: phishing-resistant, with no shared secret that can be intercepted or replayed.
Your administrators can make passkeys mandatory for administrators or for everyone. Where a device cannot support passkeys and you have not made them mandatory, the email code remains available.
What happens if someone loses their device?
They sign in with a single-use code to their verified address and set up a new passkey. That step on its own opens nothing.
A new passkey locks their access until one of your administrators approves them back in. Someone who has taken over a mailbox ends up with a session and no figures.
Can statycs staff see our figures?
The product has no impersonation or "view as customer" feature. A small number of statycs engineers hold infrastructure access for operating the platform, each authenticated individually. No external contractors are granted access.
Is our data used in test environments?
No. Development and test environments never contain production data. They run on generated data, so a mistake in a test environment cannot expose a real figure of yours.
What is our data used for, beyond serving us?
Your data is never sold. Under our standard terms, anonymised and aggregated figures may be used to produce industry benchmarks, and you can opt out of that at any time - the terms set out exactly how. Negotiated agreements can exclude it outright, and several do.
Identifiable figures are never shared with anyone. Where a contract requires a stricter commitment than the standard terms, that belongs in the agreement rather than on a web page, and we are happy to write it in.
What happens if something fails?
Encrypted backups are kept in at least three separate locations. Recovery is a defined process, and we rehearse a full disaster recovery at least twice a year so it works when it is needed. Recovery commitments are set out in the contract - ask us if your reporting calendar has specific requirements.
How quickly would you tell us about a breach?
Without undue delay, as our data processing agreement sets out. Art. 33(2) GDPR sets no risk threshold on a processor notifying the controller, and we apply none - you hear about it, and you decide what it means for your own filing.
The notification carries the nature of the breach, the categories and approximate number of people affected, the likely consequences, what we have already done, and a named contact - in time for your own 72-hour deadline to the supervisory authority.
How do we get our data out?
Your files never leave your computer. We only ever receive the figures extracted from them, so the original files stay with you the whole time.
The figures you can export at any time, in machine-readable form - Excel and CSV directly from the product, and a full structured export on request. On termination your data is deleted, subject to any statutory retention you instruct us to observe as controller.
How do we report a security issue?
Write to [email protected]. We acknowledge receipt, come back to you with an assessment, and we will not pursue anyone who reports a genuine finding in good faith.
Don't compromise on data security.
We work hard on security so you don't have to.