Skip to content

How we keep your data secure

The encryption, hosting, and account protections that keep your financial data safe in Kontala.

Last updated 20 July 2026.

Protecting your books is part of how Kontala is built. Here is what that means in practice, in plain words.

Encrypted in transit

Everything between your browser and Kontala travels over HTTPS, so your data is encrypted on its way to and from the app.

Your password

Kontala never stores your password itself, only a one-way hash of it, so it cannot be read back even by us. Password reset links work once and expire after a short time.

After 5 failed sign-in attempts in a row, the account is locked for 30 minutes to slow down guessing attacks - see Signing in to Kontala.

Your HMRC and FreeAgent connections

When you connect Kontala to HMRC or FreeAgent, you sign in on their site, so Kontala never sees those passwords. The access tokens they give us are stored encrypted (AES-256), and the encryption key is held outside the database, so a copy of the database alone is not enough to read them.

Where your data lives

Kontala runs on Google Cloud, in the EU. Files you attach, such as receipts, are stored in Google Cloud Storage in a private bucket, and downloads use time-limited links.

Access inside your account

Every user has a permission level, so people only see the areas you have given them. Only owners and admins can manage users and integrations.

If you have a security question, or something to report, email support@kontala.com.