Dynafis Trust Center

Security, privacy and trust

Dynafis processes sensitive finance and invoice data with clear security measures, controlled access rights and traceable processes.

Last content review: July 30, 2026

01

Company identity

Product

Dynafis

Operator

General Informatics

Company location

European Union · Poland

02

Privacy and data processing

Dynafis processes data for defined purposes, with role-based controls and according to enabled features and contracts.

Roles of the parties

Depending on the use case, the customer acts as controller and Dynafis as processor. Dynafis processes its own contract, security and billing data as controller.

Data minimisation

Only data required for the selected invoice, review, export or integration workflow is processed.

Retention and deletion

Retention periods are separated by data type and use. Anonymous short-check artefacts are scheduled for deletion after 24 hours by default.

Data export

Reviewed invoice data and approved artefacts can be exported through supported formats and API flows.

International transfers

International transfers are described and safeguarded only according to the providers and contracts actually enabled.

Data processing agreement

A DPA is available as a central legal document and is not replaced by marketing claims.

Subprocessors and external services

ProviderPurposeData categoryProcessing regionSafeguardStatusLast review
Contractually named hosting/storage providerApplication operation and object storageApplication data and documentsRegion stated in the DPAContract, access controls and documented operational measuresActiveJul 30, 2026
Configured AI providerOptional extraction and assistanceOnly content required for the enabled flowAccording to provider and contract configurationProduction approval, minimised data flow and provider training disabledProvider-specificJul 30, 2026
Mollie / PayPalOptional payment processingBilling and transaction dataAccording to the selected provider and contract documentationOnly for the enabled payment method; Dynafis does not store complete card detailsProvider-specificJul 30, 2026
Brevo or configured SMTP providerTransactional and support emailEmail address and required message contentAccording to provider and contract configurationMinimised message content, restricted access and retention rulesProvider-specificJul 30, 2026

03

Technical security measures

Status labels distinguish active, planned and provider-specific measures.

Active

TLS-encrypted transmission

Public web and API connections are provided over TLS.

Active

Secure password storage

Passwords are not stored in plain text; authentication and tokens are protected server-side.

Active

Two-factor authentication

Every account can optionally be protected with an authenticator app, QR code and one-time recovery keys.

Active

Roles and permissions

Roles, object access and API actions are checked server-side.

Active

Tenant and legal-entity separation

Workspace, organisation, client and legal entity are treated as separate access contexts.

Active

Audit and activity logs

Security-relevant changes, approvals and processing steps are logged traceably.

Active

Secrets and credentials

Credentials are not exposed in the interface or public logs and are separated by purpose.

Active

Backups and recovery

Backups, recovery and objectives are documented as operational evidence; commitments are based on documented tests.

Active

Monitoring and error detection

Service health, queues and security-relevant errors are monitored and communicated without sensitive internals.

Active

Separated environments

Development, test, sandbox and production use separate configurations and release rules.

04

Dynafis Secure Processing

Dynafis Secure Processing combines technical and organisational safeguards for controlled, traceable finance and invoice workflows.

Controlled data intake

File type, size, origin and permitted processing paths are checked before further processing.

Traceable processing steps

Original, extraction, rule finding, AI suggestion, human decision and export remain separately traceable.

Separation by organisation and legal entity

Data and connectors are processed in the correct organisation, client and legal-entity context.

Role-based approvals

Approvals and sensitive actions are tied to roles, permissions and, where configured, four-eyes review.

Auditability

Versions, changes, decisions and exports can be traced through audit and activity data.

Controlled exports and deletion

Exports follow permissions and format boundaries; deletion respects retention and audit rules.

05

E-invoicing and connectors

Connectors are labelled transparently by availability and dependency. Provider or authority logos are not presented as Dynafis certification.

KSeF

Active

Client- and legal-entity-specific connection with test and production context.

Peppol

Provider-specific

Peppol services are provided through a connected Peppol service provider.

Bank matching

Beta

CAMT.053, MT940 and CSV import with traceable allocation and manual review.

SFTP file import

Active

Automatic key- or password-protected retrieval from configured directories.

Import mailbox

Active

Automatic retrieval of approved statement attachments through a configured mailbox.

EBICS

Provider-specific
Premium connector

Read-only retrieval as a premium connector; activation and bank keys require approval by the bank.

06

Availability and operations

Operational information is provided through defined status and support channels.

  • The public system status shows operationally relevant information without attack-enabling internal detail.
  • Maintenance and security-relevant incidents are communicated through the designated status and support channels.
  • The date of the latest content review is visible on this page.

07

Report a security issue

Report a potential security issue through the protected form. Submissions are validated server-side, protected against abuse and stored as traceable support cases.

Please do not send passwords, API keys or unnecessary personal data.

08

Evidence and certifications

Only evidence that actually exists is shown as active.

Active

Internal security documentation

Policies, risks, controls and operational evidence are maintained with versioning.

Active

Privacy documentation

Privacy notice, DPA and cookie documentation are linked centrally.

Planned

External penetration test

Will only be shown as completed after a real test and approved evidence.

Planned

ISO/IEC 27001

Readiness and ISMS structures are being prepared. Dynafis currently claims neither certification nor formal conformity.

09

AI transparency

Optional AI features are described separately, purpose-bound and transparently.

Optional AI services

The active provider, model, purpose and data flow must be documented and approved before production use.

No Dynafis model training

Customer documents and invoice content are not used to train Dynafis models.

Human decision remains separate

AI outputs are treated as labelled suggestions with provenance and confidence; acceptance, modification or rejection remains traceable.

10

Frequently asked questions

Is Dynafis ISO/IEC 27001 certified?

No. Readiness and ISMS structures are being prepared; certification will only be published after it is actually granted.

Is Dynafis itself a certified Peppol Access Point?

Peppol services are provided through a connected Peppol service provider. Dynafis does not claim its own Access Point certification.

Where can I find privacy and contract information?

Privacy notice, DPA, terms and imprint are linked centrally in the footer and in the company section of this Trust Center.

How do I report a security issue?

Use the protected form in this Trust Center. Do not send passwords, API keys or complete customer documents.