Security & Compliance
Security is Our Top Priority
Learn how we protect your data and meet regulatory requirements.
Security Measures
Encryption
TLS 1.3 for data in transit, AES-256 for data at rest.
EU Server Location
All data is exclusively processed and stored in EU data centers.
Data Minimization
We only store data that is necessary for processing.
Access Control
API keys with granular permissions. No shared access.
Compliance & Certifications
GDPR
CompliantFull GDPR compliance with Data Processing Agreement (DPA).
GoBD
CompliantGoBD-compliant processing and optional long-term archiving.
KoSIT
CompliantOfficial validation against current KoSIT schemas and Schematron rules.
SOC 2 Type II
In ProgressSOC 2 Type II certification is targeted for Q3 2026.
Our Security Practices
We follow industry-leading security standards and best practices to protect your data as effectively as possible.
- Regular penetration testing by independent security firms
- Automated dependency scans and security updates
- Audit logging of all API access and data changes
- Incident response plan with <4h reaction time
- Regular backups with geo-redundant storage
- Employee security training and access reviews
Data Flow
Your Request
HTTPS / TLS 1.3
API Gateway
Auth, Rate Limiting, WAF
Processing
Isolated Container, EU-only
Response
Validated E-Invoice
What happens if we are no longer around?
A fair question to ask of a small provider — and we would rather answer it than have you ask it. It decides whether someone hangs their invoicing on us.
The formats are not ours
XRechnung, ZUGFeRD and Peppol BIS 3.0 are public standards (EN 16931). Every invoice our API produces is valid without us and can be processed by any other provider. That is the difference from a proprietary format.
Your data stays yours
The API takes invoice data in for processing and returns the result — it is not a filing cabinet. What is retained, and why, is set out above on this page and in the privacy policy. There is no data estate you would have to reclaim.
Switching is a configuration question
The API is REST behind an adapter in your system. Changing provider touches that adapter, not your invoicing. We say so openly because it is true — and because a provider who fears the exit is the wrong one.
We are two people. That is why we build on standards rather than lock-in: what you produce with us works without us.
Found a Security Vulnerability?
We appreciate responsible disclosure. Please report security vulnerabilities to:
PGP key available on request. We respond within 24 hours.