Skip to main content

Security & Compliance

Trust is built into how we work, not bolted on afterwards. Square Software treats data protection, secure engineering and Albanian regulatory compliance as standing practices on every project, from the first line of code to production operations. This page describes the posture we actually maintain.

Data protection: Law 9887 and GDPR alignment

Square Software is an Albanian company and processes personal data under Albanian Law No. 9887 “On the Protection of Personal Data”, supervised by the Commissioner for the Right to Information and Protection of Personal Data (IDP). Albanian data-protection law is closely modelled on the EU framework, and we engineer our systems so the same controls satisfy the EU General Data Protection Regulation (GDPR) for clients and end-users in the European Union.

In practice that means data minimisation by default, a lawful basis for every processing activity, honoured data-subject rights (access, rectification, erasure, portability), retention limits, and Data Processing Agreements with the clients on whose behalf we process data. When we act as a processor, we follow the controller’s documented instructions and pass equivalent obligations to any sub-processor.

  • Privacy-by-design and by-default in every new feature
  • Data Processing Agreements (DPAs) defining controller/processor roles
  • Documented lawful basis, purpose limitation and retention schedules
  • Support for data-subject requests and breach-notification timelines

Secure software development lifecycle (SDLC)

Security is part of engineering, not a separate gate at the end. Our delivery process embeds review and verification at each stage so vulnerabilities are caught early, when they are cheapest to fix.

  • Mandatory peer code review and protected main branches
  • Least-privilege access, secrets kept out of source control, scoped credentials
  • Dependency and vulnerability scanning in CI; prompt patching of known CVEs
  • Encryption in transit (TLS) and at rest for sensitive data
  • Separate environments for development, staging and production
  • Audit logging and monitoring on production systems

Fiscalization & AKSHI compliance know-how

We build software that has to interoperate with Albanian government systems, so we maintain working knowledge of those regimes rather than treating them as an afterthought. Our team implements fiscalization (the real-time electronic invoicing mandated by the General Directorate of Taxes), including secure handling of fiscalization certificates, signing of invoices, and transmission to the central platform.

For projects that touch e-government infrastructure, we work to the technical and interoperability standards published by the National Agency for Information Society (AKSHI), which governs Albania’s public digital services.

  • Fiscalization integration (invoice signing, certificate handling, real-time reporting)
  • Familiarity with AKSHI interoperability and e-government standards
  • Correct handling of NIPT, tax and invoicing data fields

Where your data is hosted

Hosting location is a decision we make with each client, driven by data-residency, latency and regulatory needs rather than a one-size-fits-all default. For clients and end-users in the European Union, we host on EU-based infrastructure from established providers so data stays within the EU/EEA. Where a project requires Albanian data residency, we host accordingly.

Production environments are isolated from development and staging, access is restricted on a least-privilege basis, and backups are encrypted. We document the hosting arrangement and the sub-processors involved as part of each engagement’s Data Processing Agreement.

Reporting a security vulnerability

If you believe you have found a security vulnerability in this website or in software we operate, we would rather hear it from you than from an incident. Email info@square.al with enough detail to reproduce the issue: the affected URL or component, the steps you took, and what you observed. The same contact information is published in machine-readable form at https://square.al/.well-known/security.txt, in the format defined by RFC 9116.

What you can expect from us: we will acknowledge your report, investigate it, and tell you what we found and what we intend to do about it. We will not pursue legal action against anyone who reports a vulnerability in good faith, stays within the boundaries below, and gives us a reasonable opportunity to fix the issue before disclosing it publicly.

  • Please do not access, modify or delete data belonging to anyone else
  • Please do not degrade the service: no denial-of-service testing, no high-volume automated scanning, no spam
  • Please do not use social engineering, phishing or physical attacks against our staff or our clients
  • Please allow us a reasonable period to remediate before publishing details
  • We do not run a paid bug-bounty programme, but we are glad to credit you in our acknowledgements if you want that

Verified, not claimed

A trust page that only asserts things about itself is worth very little. Every item below links instead to somebody else’s check, so you can confirm it without taking our word for anything. If one of these claims ever stops being true, we remove the claim rather than leave it standing.

  • Green hosting

    Both the CDN edge and the origin server that serve this site are independently verified as running on renewable energy. The origin sits in Hetzner’s Finnish region, which is backed by hydroelectric power certificates.

    Green Web Foundation check for square.al
  • Transport security

    TLS 1.3, with HTTP Strict Transport Security set for a year, applied to subdomains and submitted to the browser preload list.

    Qualys SSL Labs report
  • HTTP security headers

    A Content Security Policy, framing refused outright, MIME-type sniffing disabled, a strict referrer policy, and camera, microphone, geolocation and browsing-topics access switched off.

    Mozilla Observatory scan
  • Accessibility

    Partially conformant with WCAG 2.1 level AA, the standard adopted by EN 301 549. The statement names the testing method, the single issue the audit found and we fixed, and five limitations we have not closed.

    Read the accessibility statement
  • Vulnerability disclosure

    A machine-readable security contact in the RFC 9116 format, so a researcher who finds a problem can reach us without hunting for an address.

    square.al/.well-known/security.txt
  • Open-source security practices

    Our public Albanian fiscalization library holds the OpenSSF Best Practices passing badge: 53 criteria met, 13 not applicable, and one unmet which we name rather than hide (no dedicated fuzzer). The assessment is self-certified against criteria published by the Open Source Security Foundation, but every answer and its evidence is public, and the facts behind them (licence, test suites, continuous integration, CodeQL static analysis, security policy) are checkable in the repository itself.

    OpenSSF Best Practices badge for fiskalizimi-utils
  • Company registration

    A real registered company, not a trading name: Square Software SH.P.K., NIPT M51418039H, registered at the QKB: Qendra Kombëtare e Biznesit.

    Public registry record

Official sources

The regulators and frameworks referenced on this page. We link to the primary sources so you can verify the obligations yourself.

Legal name
Square Software SH.P.K.
NIPT
M51418039H
Registered address
Rruga Muhamet Gjollesha, Ndërtesa 30, 1001 Tiranë, Shqipëri
Registered at
QKB: Qendra Kombëtare e Biznesit
Registration date
2025-02-11
Verify registration

Recognition and reviews

Square Software is a 2025 TechBehemoths Awards finalist in Albania, in two categories: E-Commerce Development and ReactJS.

Client reviews are published on our Clutch and TechBehemoths profiles.