illico Book ← Back to home
Trust & Safety

Security

How we protect your business data
🔒 Your financial data is sensitive. We take every reasonable measure to keep it private, encrypted, and protected.

Our security commitments

🔐
End-to-end encryption
All data transmitted between your browser and our servers is encrypted using TLS 1.2+.
🏦
Bank-level storage
Your data is stored on enterprise-grade cloud infrastructure (AWS) — the same stack used by thousands of financial apps.
📄
Local PDF processing
Bank statement PDFs are processed entirely in your browser. The raw file is never sent to any server.
🔑
Secure authentication
Passwords are never stored in plain text. We use secure hashing with salt for all credentials.
🛡️
Row-level security
Database access is enforced with row-level security (RLS). You can only access your own data — never another user's.
💳
PCI-compliant payments
Card payments are handled by Stripe, a PCI DSS Level 1 certified provider. We never store card numbers.

Data encryption

All connections to illicobook.com are served over HTTPS with TLS encryption. Data stored in our cloud database is encrypted at rest using AES-256. Your passwords are hashed using industry-standard algorithms and are never stored or transmitted in plain text.

Bank statement import security

When you upload a PDF, CSV, or Excel bank statement:

  • The file is read entirely within your browser using JavaScript
  • The raw file content is never uploaded to our servers
  • Only the extracted transaction records (date, amount, description) are stored in your account
  • You review and approve all transactions before they are imported

This means your actual bank statement document stays on your device at all times.

Mobile money security

When you connect a mobile money wallet (MTN MoMo, Orange Money, Wave, etc.):

  • Your mobile money PIN or password is never entered into illico Book
  • Payment prompts are sent directly to your phone by the mobile operator
  • illico Book only receives transaction confirmation, not your wallet credentials
  • You authorize each payment directly on your mobile device

Access control

Each illico Book account is isolated at the database level. Row-level security (RLS) policies ensure that even if a security breach occurred, no user could access another user's financial records.

On the Pro plan, team access allows up to 3 users per account. Each team member uses their own login credentials. Account owners can remove team members at any time.

Your responsibilities

To keep your account secure, we recommend:

  • Use a strong, unique password for your illico Book account
  • Never share your login credentials with untrusted parties
  • Log out when using illico Book on a shared or public device
  • Keep your email account secure — it is the recovery method for your illico Book account
  • Contact us immediately if you suspect unauthorized access

Incident response

In the unlikely event of a security breach that affects your data, we commit to:

  • Investigating and containing the incident within 24 hours of detection
  • Notifying affected users by email within 72 hours
  • Providing a clear explanation of what data was affected and what steps we are taking
  • Cooperating with relevant data protection authorities as required by law

Third-party services

illico Book integrates with trusted third-party services, each with their own security certifications:

  • Cloud database — SOC 2 Type II compliant hosting on AWS infrastructure
  • Stripe — PCI DSS Level 1 certified payment processing
  • Mobile money operators (MTN, Orange, Wave, etc.) — regulated by national telecommunications authorities

Found a security issue?

We take security reports seriously. If you discover a vulnerability, please report it responsibly and we will respond within 48 hours.

info@illicobook.com