Skip to main content

Security

Your data belongs to you. The most important safeguards are listed below. Operational and technical specifics are documented in the Data Processing Agreement (AVV).

Hosting in Germany

  • Application, database, and object storage are configured for operation in Germany. Approved operational and provider evidence governs the public statement.
  • The current approved DPA lists infrastructure providers, purposes, and safeguards.
  • Incoming traffic is additionally protected against DDoS (denial-of-service) attacks.
  • The current approved DPA contains the applicable subprocessor information.

Encryption

  • Encrypted transport between your browser and our servers.
  • Especially sensitive values such as IBAN or VAT ID are additionally encrypted at application level. Approved TOM documentation describes productive storage and disk encryption.
  • Passwords are never stored in plaintext; sign-in flows are protected against automated enumeration.
  • Key-management details are documented in the approved TOM appendix to the DPA.
  • Single-session protection: one active session per account; multiple logins require explicit device confirmation.

Backups and recovery

  • Create backups daily, monthly, or manually at any time.
  • Backups are stored separately in configured object storage and checked for integrity before restore.
  • Choose the schedule in the Compliance Center and start a controlled restore when needed.
  • Approved TOM documentation defines storage locations, retention windows, and restore procedures.

GoBD and immutability

  • Posted records are immutable. Corrections happen only as traceable reversal postings.
  • Closed fiscal years are sealed; movements in locked periods are excluded at the system level.
  • Business- and security-relevant actions record time and actor; postings add integrity and cancellation history.
  • Exports and controlled deletion workflows support your retention processes.

Data rights and deletion

  • GDPR data-subject access directly from the app: on request, you get all data stored about a person (incl. debtors, creditors, members, invitations) as a file export.
  • After contract end, product access is blocked and the client remains reactivatable through billing for 90 days. Create required exports before contract end.
  • Operational client data is removed after the grace period. Records subject to retention duties remain segregated and access-restricted until their applicable period ends.
  • Automatic deletion cron runs daily; T-30, T-7, and T-1 reminder emails notify you in advance.

What we don't (yet) have

We don't sell compliance fairy tales. These points are currently not fulfilled; we communicate them openly because their absence may be relevant:

  • No IDW PS 880 audit certificate for GoBD compliance. We design for traceable workflows based on GoBD principles, but no external auditor attestation is currently available.
  • No ISO 27001 / SOC 2 certification. No such certification is currently available.
  • No public bug-bounty program. Report security issues directly to [email protected]. There is no formal bug-bounty program with payouts at this time.

Questions?

For specific security inquiries, audit requests, or pen-test requests, write to [email protected].

Security · accuno