Security & privacy
Where your data lives — and who can see it
No seals, no certification logos. This page states what is actually in place today and how you can check it.
Where things stand today
Hosted in the EU
Application and database run inside the European Union. That is a fixed commitment, not a default that can quietly change.
Encrypted in transit
Every connection uses HTTPS. Unencrypted requests are redirected to the secure connection.
Tenant separation in the database
Separation between companies is enforced by the database itself rather than by the application — and every change to it is checked automatically.
DPA under Art. 28 GDPR
We provide a data processing agreement. An informal e-mail to us is enough.
No cookies, no tracking
This website uses cookieless analytics on EU servers and serves fonts from its own origin — no third-party requests.
Sessions really end
Signing out blocks the session on the server. A signed-out device cannot return with an old token.
Transparency
What we do not claim
Are you ISO 27001 certified?
No. We hold no certification and therefore show no seal. If that changes it will be stated here, with the auditor and the date.
Is the data in Germany?
We deliberately say "EU" rather than "Germany". Application and database run inside the European Union; a narrower claim would not currently be provable, and an unprovable promise is not a promise.
Who can see my data?
Only users of your own company. The database separates tenants technically; administrative access happens solely for operations and fault fixing.
Can I get my data back out?
Yes — export and deletion are a fixed part of the product and ship with the official launch. Until then an e-mail to us is enough.
Start before you have to.
Create a free account, receive your first e-invoice and get to know the formats — long before they become mandatory.
No credit card required