Saltar al contenido principal

Security

How we protect accounting operations and customer data.

What afínate guarantees

Verifiable principles, present in every document processed.

Full data ownership

Download and deletion available at any time, with no restrictions.

Auditable documents

The system allows editing values, reclassifying or voiding any record.

24/7 customer support

WhatsApp +57 321 390 2280 and email [email protected].

Colombian data protection law

Personal data handled in compliance with Law 1581 of 2012 (Habeas Data).

Meta Business verified

WhatsApp owner Meta validated the legal identity and authorized official operation.

For IT and compliance teams

For audit processes that require security questionnaires, data processing agreements or formal technical evidence, afínate prepares documentation tailored to each case. Requests by email or WhatsApp.

Frequently asked questions

The most common queries, grouped by audience.

Business

Who accesses each account's information?
Only the owning organization. Every database query is filtered by user via Row Level Security (RLS); no other customer can read someone else's information. The afínate team accesses data only when required for support or maintenance, under strict confidentiality criteria.
Can the data be downloaded or deleted at any time?
Yes. The dashboard exports documents, accounting entries and reports as PDF and CSV on demand. When the account is deleted, data is removed in compliance with Law 1581 (Habeas Data).
How is Law 1581 (Habeas Data) handled?
afínate processes personal data in accordance with Colombian Law 1581 of 2012 and its regulations. Any data subject may request consultation, update, correction or deletion by writing to [email protected].
What does Meta Business verification mean?
afínate operates as a Verified Business under Meta Business (owner of WhatsApp). Meta validated the company's legal identity and authorized official use of the WhatsApp Business API for customer support.
How is a vulnerability or incident reported?
Email [email protected] with the details of the finding. Each case is reviewed and answered within a reasonable timeframe. For active incidents, WhatsApp +57 321 390 2280 is also available.

Technical

Serverless infrastructure
afinate runs 100% on Cloudflare (site, APIs and queues) and Supabase (managed Postgres database). There are no in-house servers to manage or patch: each layer is operated and updated by the infrastructure provider.
Database access control
The database enforces Row Level Security (RLS) on 100% of its tables: every query is automatically filtered by the authenticated user's company, preventing one customer from reading another's data even if the application layer fails.
Encryption in transit and at rest
All communication (website, dashboard, APIs, WhatsApp) travels encrypted over TLS. Data at rest is encrypted by Supabase.
Cryptographic verification of WhatsApp webhooks
Every inbound WhatsApp message must carry Meta's HMAC signature; if the signature is invalid, the message is rejected before processing.
Secrets and key management
Keys and credentials live in Cloudflare Secrets Store. They are never written into the site code or sent to the customer's browser.
Authentication
Dashboard access uses Supabase Auth: email, Google, Microsoft, Facebook or LinkedIn. WhatsApp identity is verified with one-time-use links.
AI processing
Documents are analyzed via established AI provider APIs. The business's data is not sold or used for advertising.
PCI-compliant payments
Payments are processed exclusively through Wompi, a Colombian payment gateway. afinate does not store card data.