Romfeya UBP was created by a cybersecurity company. This page describes exactly what the system does to protect your data – mechanism by mechanism, without generalities.
Client data is not kept as rows in a shared table, separated by a filter. Every company has a separate database, and the application executes a request solely against the database recorded in the user’s session.
Company data
Documents, counterparties, items, stock, manufacturing, reports – and the uploaded files – are in the company’s database.
Accounts and sign-in
User accounts and login details are in a central database, separated by company.
Analytics
The dashboards read the company’s database through a separate connection and are displayed with temporary access issued for the current session.
Custom modules
A module developed for one company is visible only to that company and works on its database.
02
A login that does not rely on the password alone
Passwords
Stored only as an Argon2 hash. The password itself is not kept anywhere.
Two-factor authentication
Every user can turn on a code from an authenticator app. It is enabled from the profile, with a QR code.
Lockout
A wrong password and a wrong code are counted together. After 5 failed attempts the account is locked for 15 minutes.
Session
Signed, valid for 8 hours, in a cookie that is inaccessible to scripts and sent only over an encrypted connection.
Visibility
Every user sees their last login and the number of failed attempts in their profile.
03
Denied, unless explicitly allowed
Access is determined by the user’s role, at two levels. Every request is checked – not only what is visible in the menu.
Menus
A role sees and opens only the permitted screens. Documents are divided by category – sales, purchases, inventory, finance.
Actions
Separate permissions within a screen – for example, completing a production job or closing a tracked delivery.
The company’s roles are configured during implementation – from then on, deny by default applies
A new user is created with no role – there is no accidental administrator
Sensitive actions remain reserved for the company administrator
The AI assistant’s reports go through the same check
04
Who, when, what
The audit is not a report that someone has to switch on. It is written in the same transaction as the change itself – if the change is rolled back, the audit record does not remain either.
Change audit
Every creation, change and deletion in all modules: time, user, action and the content of the record.
Access log
Which user opened which screen, and when.
No physical deletion
The main records are deactivated rather than deleted – the history and the reports stay intact.
Logs by area
The contact consent log is append-only. Every automatic delivery check and every call of an AI report also leaves a record.
05
Tools for your customers’ personal data
The system does not just protect the data – it helps you meet your own data protection obligations.
Consent register
For every counterparty: whether they want commercial messages and whether they allow proactive communication. No record means no consent.
Evidence
Every change of consent is recorded with the channel, the date and the customer’s words. The log is append-only.
The “right to be forgotten”
The request is recorded by an employee, and it is carried out only by the administrator – in two steps, by typing the exact name of the counterparty.
What is erased
Phone, email, contact person, address, bank accounts. The name, the UIC (company ID) and the documents are kept – because of statutory obligations.
The language model does not write queries and has no connection to the database. It chooses one of the predefined read-only reports – there are 13 to start with, and the set is extended through configuration. The report is run by the system – after checking the user’s permissions.
By default, counterparty names are replaced with pseudonyms before they reach the model
A limited number of rows go to the model; the number is configurable
Conversations are not stored; only a trail of which report was called, and by whom, is kept
The assistant works with your own key to a provider of your choice and is switched off until you configure it
07
Beneath the application
Connection
HTTPS only, with TLS 1.2 and 1.3. Older protocols are disabled.
Network
A deny-by-default firewall. The database is not reachable from the internet – the application reaches it through a private encrypted tunnel.
Secrets
The keys are not in the code. Without them the application refuses to start.
External services
Passwords and tokens for the mailbox, the channels and the AI provider are stored encrypted and are not shown again.
Error tracking
The error-tracking service receives only the user’s internal number and technical data – no names, emails or IP addresses.
08
Your part in security
The system locks the doors, but you hold the keys. Three things make the biggest difference:
Turn on two-factor authentication for everyone who has access to finance and personal data
Give each role only what it needs for the job
Before you turn on the AI assistant, put your arrangements with the model provider in order
09
What is to come — and what you will not see here
Measure
Status
Mandatory two-factor authentication if the company so decidestoday, turning it on is each user’s choice
planned
Finer-grained permissions – at the level of action and field
planned
There are no badges or certificates on this page that we do not hold. The mechanisms described can be verified in the demo environment and in the functional specification.