Diffa

Security

Version 1, in force from 2026-10-03

The Swedish version governs if the two differ.

Diffa is provided by Sliti & Klay Group AB, reg. no. 559524-2891, Remigatan 41, SE-261 45 Landskrona, Sweden. This page is written for you who review Diffa as a supplier: an accounting firm, an IT manager or an auditor. It says what applies today, not what we hope for.

1. Where the data lives

Bookkeeping data and material are stored in Sweden, at Google Cloud in Stockholm. The test and production environments are separate: own projects, own databases, own keys. Test data is test data.

What is not in Sweden is listed on the page Subprocessors with location and transfer basis: sign-in at Google, e-mail through Resend in Ireland, Ask Diffa at OpenAI in the USA, diffa.se through Cloudflare.

2. Encryption

All data is encrypted at rest and in transit. The database and the document storage are encrypted by Google Cloud. All traffic goes over TLS.

Secrets such as keys to platforms and accounting systems are additionally envelope-encrypted by Diffa itself: every time a secret is saved a new data key is created, which in turn is encrypted by a master key in Cloud KMS. The master key never leaves KMS. An encrypted secret is bound to its place, so that it cannot be moved to another company or another connection.

3. Access

Every part of the service runs with its own identity and least privilege. No part can read more than it needs. The database is reached only from the service, not from the internet.

You sign in with Google, Microsoft or e-mail and password through Firebase. Diffa has no open registration: an account is created only through a purchase, an invitation or a consent in Fortnox.

Our own access to your view in the service happens only in a support case or at your request. It is logged with who, when and which company. It is visible in the service while it lasts.

4. As little data as possible

Personal data about your customers is removed before anything is stored. Names, addresses, e-mail, phone and card details disappear when the material arrives. What does not exist cannot leak.

5. Suppliers

Every supplier that processes data on our behalf has a written agreement with us with at least the protection we promise you. The list with function, location and transfer basis is on the Subprocessors page. Changes are announced 30 days in advance.

6. Incidents

If we discover an incident concerning your data we act in this order: contain, understand, inform. Affected customers are told without undue delay, aiming for within 48 hours of discovery, with what is known. If the incident concerns personal data, you get the material you need to notify the Swedish Authority for Privacy Protection within 72 hours.

7. Retention

Everything behind a voucher is kept until 31 December of the eighth year after the voucher’s year and is then deleted automatically. Account data is deleted 90 days after an agreement has ended. Technical logs are cleared after at most twelve months. The log of our support access is kept for twelve months.

8. How we work

We are a small company. We are below the size threshold of NIS2 (the Swedish Cybersecurity Act) and have not had an external party assess us against ISO 27001. We still work by the principles of both: risk assessment, least access, logging, incident handling and supplier control. When we say something applies here, it is because it is built that way, not because it is written in a policy.

9. Report a vulnerability

If you have found something that looks wrong, we want to know. Write to support@diffa.se. We answer within two working days and tell you what we are doing about it.