Saltar al contenido principal

Security

How we protect each company's administrative operation and its data.

What afínate guarantees

Verifiable principles, present in every document processed.

Full data ownership

Download and deletion available at any time, with no restrictions.

Auditable documents

The system allows editing values, reclassifying or voiding any record.

24/7 customer support

Three channels, one Lucía: WhatsApp +57 321 390 2280, email [email protected] and the dashboard chat.

Colombian data protection law

Personal data handled in compliance with Law 1581 of 2012 (Habeas Data).

Meta Business verified

WhatsApp owner Meta validated the legal identity and authorized official operation.

For IT and compliance teams

For audit processes that require security questionnaires, data processing agreements or formal technical evidence, afínate prepares documentation tailored to each case. Requests go through the form.

Frequently asked questions

The most common queries, grouped by audience.

Business

Who accesses each account's information?
Only the owning organization. Every database query is filtered by user via Row Level Security (RLS); no other customer can read someone else's information. The afínate team accesses data only when required for support or maintenance, under strict confidentiality criteria.
Can the data be downloaded or deleted at any time?
Yes. The dashboard exports documents, accounting entries and reports as PDF and CSV on demand. When the account is deleted, data is removed in compliance with Law 1581 (Habeas Data).
How is Law 1581 (Habeas Data) handled?
afínate processes personal data in accordance with Colombian Law 1581 of 2012 and its regulations. Any data subject may request consultation, update, correction or deletion by writing to [email protected].
What does Meta Business verification mean?
afínate operates as a Verified Business under Meta Business (owner of WhatsApp). Meta validated the company's legal identity and authorized official use of the WhatsApp Business API for customer support.
How is a vulnerability or incident reported?
Email [email protected] with the details of the finding. Each case is reviewed and answered within a reasonable timeframe. For active incidents, WhatsApp +57 321 390 2280 is also available.

Technical

No in-house servers
afinate runs 100% on managed services: a global content delivery network with DDoS mitigation (site, dashboard, APIs, queues, scheduled jobs and PDF rendering) and a managed backend-as-a-service platform (Postgres database, authentication and file storage). There are no in-house servers to manage or patch: each layer is operated and updated by the provider.
Which providers take part in the service?
Specialist providers, each with a narrow role: a global content delivery network with DDoS mitigation (site, dashboard, APIs, queues and PDF generation), a managed backend-as-a-service platform (database, authentication and storage), multimodal vision and language models (reading documents, images and audio), a language-model provider (the conversational agent's models), Meta (the official WhatsApp channel), a transactional email provider, an authorised technology provider for transmitting electronic documents to the DIAN, and a Colombian payment gateway. Each provider receives only what it needs to do its job; the named list is shared in the formal documentation, on request.
Database access control
The database enforces Row Level Security (RLS) on 100% of its tables: every query is automatically filtered by the authenticated user's company, preventing one customer from reading another's data even if the application layer fails.
Encryption in transit and at rest
All communication (website, dashboard, APIs, WhatsApp and email) travels encrypted over TLS. Data at rest is encrypted by the managed database platform.
Each of the three channels is verified before acting
WhatsApp: every inbound message must carry Meta's HMAC signature, or it is rejected before processing. Email: the sender is validated with SPF, DKIM and DMARC, and issuing any money document requires an explicit confirmation with the word CONFIRMO (never a plain "yes"), with a WhatsApp notice to the account holder; creating a new account over email is blocked, with no exception. Dashboard chat: the user's authenticated session.
Secrets and key management
Keys and credentials live in the managed secrets vault of the infrastructure provider. They are never written into the site code or sent to the customer's browser.
Authentication
Dashboard access uses the managed authentication service of the platform: email or social sign-in. WhatsApp identity is verified with one-time-use links.
AI processing
Documents are read with multimodal vision and language models, and conversations are handled with language models served by a specialist provider, always through their APIs. The business's data is not sold, used for advertising or used to train models.
PCI-compliant payments
Payments are processed exclusively through a PCI-compliant Colombian payment gateway. afinate does not store card data.
Transmission to the DIAN
Electronic documents are transmitted to the DIAN through an authorised electronic invoicing technology provider. afinate keeps the CUFE and the acceptance status of every document so the full trace stays available.