Security & Compliance

Security is Our Top Priority

Learn how we protect your data and meet regulatory requirements.

Security Measures

Encryption

TLS 1.3 for data in transit, AES-256 for data at rest.

EU Server Location

The API runs in EU regions (Vercel Inc., a US company, servers in the EU). Services based outside the EU are named in the subprocessor table below.

Data Minimization

We only store data that is necessary for processing.

Access Control

API keys with granular permissions. No shared access.

Compliance & Certifications

GDPR

Compliant

Full GDPR compliance with Data Processing Agreement (DPA).

GoBD

Compliant

GoBD-compliant processing. Audit-proof long-term archiving stays with you until the Archive API ships (planned 2027).

KoSIT

Compliant

Official validation against current KoSIT schemas and Schematron rules.

SOC 2 Type II

Not held

We hold no SOC 2 attestation, and we are not promising one. What we actually do is listed below under "Our Security Practices" — that is checkable; a promised seal would not be.

Subprocessors

This list mirrors the processors named in our privacy policy — same purpose, same region. It is maintained together with it: what is there is here.

ProviderPurposeLocation / processing
Vercel Inc.Hosting and delivery of this websiteUS company, servers in the EU
Google Analytics 4Audience measurement, loads only after your consent (Consent Mode v2)not stated in the privacy policy
PostHog Inc.Product analytics, loads only after your consentUS company, processing on EU servers (Frankfurt)
Microsoft Clarity (Microsoft Corporation)Heatmaps and session recordings, load only after your consentUSA, transfer based on the EU standard contractual clauses
SuperX GmbH (Superchat)Live chat, loads only after your consentGermany (Berlin), DPA under Art. 28 GDPR

Where no region is given here, none is given in the privacy policy either — we will add it there rather than invent it here.

Data processing agreement (DPA)

We provide a DPA under Art. 28 GDPR on request — today as a document by email, not as a self-service download. Once it exists as a PDF it will be linked here.

Request the DPA

Our Security Practices

We follow industry-leading security standards and best practices to protect your data as effectively as possible.

  • No external penetration-test attestation: we have not commissioned one and do not promise one — what we actually do is in the points below
  • Automated dependency scans and security updates
  • Audit logging of all API access and data changes
  • Incidents and maintenance windows are published on our public status page; a promised response time only applies within your plan's support (Starter 48 h, Premium 8 h)
  • TLS 1.3 on every API connection — checkable from the outside, without asking us
  • Exactly two people hold production access; there is no wider group that would need a training program

Data Flow

Your Request

HTTPS / TLS 1.3

API Gateway

Auth, Rate Limiting, WAF

Processing

Isolated Container, EU-only

Response

Validated E-Invoice

What happens if we are no longer around?

A fair question to ask of a small provider — and we would rather answer it than have you ask it. It decides whether someone hangs their invoicing on us.

The formats are not ours

XRechnung, ZUGFeRD and Peppol BIS 3.0 are public standards (EN 16931). Every invoice our API produces is valid without us and can be processed by any other provider. That is the difference from a proprietary format.

Your data stays yours

The API takes invoice data in for processing and returns the result — it is not a filing cabinet. What is retained, and why, is set out above on this page and in the privacy policy. There is no data estate you would have to reclaim.

Switching is a configuration question

The API is REST behind an adapter in your system. Changing provider touches that adapter, not your invoicing. We say so openly because it is true — and because a provider who fears the exit is the wrong one.

We are two people. That is why we build on standards rather than lock-in: what you produce with us works without us.

Found a Security Vulnerability?

We appreciate responsible disclosure. Please report security vulnerabilities to:

PGP key available on request. We respond within 24 hours.

Questions?

Our team is happy to answer all your questions about security and compliance.