🔒 Your financial data is sensitive. We take every reasonable measure to keep it private, encrypted, and protected.
Our security commitments
🔐
End-to-end encryption
All data transmitted between your browser and our servers is encrypted using TLS 1.2+.
🏦
Bank-level storage
Your data is stored on enterprise-grade cloud infrastructure (AWS) — the same stack used by thousands of financial apps.
📄
Local PDF processing
Bank statement PDFs are processed entirely in your browser. The raw file is never sent to any server.
🔑
Secure authentication
Passwords are never stored in plain text. We use secure hashing with salt for all credentials.
🛡️
Row-level security
Database access is enforced with row-level security (RLS). You can only access your own data — never another user's.
💳
PCI-compliant payments
Card payments are handled by Stripe, a PCI DSS Level 1 certified provider. We never store card numbers.
Data encryption
All connections to illicobook.com are served over HTTPS with TLS encryption. Data stored in our cloud database is encrypted at rest using AES-256. Your passwords are hashed using industry-standard algorithms and are never stored or transmitted in plain text.
Bank statement import security
When you upload a PDF, CSV, or Excel bank statement:
- The file is read entirely within your browser using JavaScript
- The raw file content is never uploaded to our servers
- Only the extracted transaction records (date, amount, description) are stored in your account
- You review and approve all transactions before they are imported
This means your actual bank statement document stays on your device at all times.
Mobile money security
When you connect a mobile money wallet (MTN MoMo, Orange Money, Wave, etc.):
- Your mobile money PIN or password is never entered into illico Book
- Payment prompts are sent directly to your phone by the mobile operator
- illico Book only receives transaction confirmation, not your wallet credentials
- You authorize each payment directly on your mobile device
Access control
Each illico Book account is isolated at the database level. Row-level security (RLS) policies ensure that even if a security breach occurred, no user could access another user's financial records.
On the Pro plan, team access allows up to 3 users per account. Each team member uses their own login credentials. Account owners can remove team members at any time.
Your responsibilities
To keep your account secure, we recommend:
- Use a strong, unique password for your illico Book account
- Never share your login credentials with untrusted parties
- Log out when using illico Book on a shared or public device
- Keep your email account secure — it is the recovery method for your illico Book account
- Contact us immediately if you suspect unauthorized access
Incident response
In the unlikely event of a security breach that affects your data, we commit to:
- Investigating and containing the incident within 24 hours of detection
- Notifying affected users by email within 72 hours
- Providing a clear explanation of what data was affected and what steps we are taking
- Cooperating with relevant data protection authorities as required by law
Third-party services
illico Book integrates with trusted third-party services, each with their own security certifications:
- Cloud database — SOC 2 Type II compliant hosting on AWS infrastructure
- Stripe — PCI DSS Level 1 certified payment processing
- Mobile money operators (MTN, Orange, Wave, etc.) — regulated by national telecommunications authorities