Security
Your data belongs to you. The most important safeguards are listed below. Operational and technical specifics are documented in the Data Processing Agreement (AVV).
Hosting in Germany
- Application, database, and object storage are configured for operation in Germany. Approved operational and provider evidence governs the public statement.
- The current approved DPA lists infrastructure providers, purposes, and safeguards.
- Incoming traffic is additionally protected against DDoS (denial-of-service) attacks.
- The current approved DPA contains the applicable subprocessor information.
Encryption
- Encrypted transport between your browser and our servers.
- Especially sensitive values such as IBAN or VAT ID are additionally encrypted at application level. Approved TOM documentation describes productive storage and disk encryption.
- Passwords are never stored in plaintext; sign-in flows are protected against automated enumeration.
- Key-management details are documented in the approved TOM appendix to the DPA.
- Single-session protection: one active session per account; multiple logins require explicit device confirmation.
Backups and recovery
- Create backups daily, monthly, or manually at any time.
- Backups are stored separately in configured object storage and checked for integrity before restore.
- Choose the schedule in the Compliance Center and start a controlled restore when needed.
- Approved TOM documentation defines storage locations, retention windows, and restore procedures.
GoBD and immutability
- Posted records are immutable. Corrections happen only as traceable reversal postings.
- Closed fiscal years are sealed; movements in locked periods are excluded at the system level.
- Business- and security-relevant actions record time and actor; postings add integrity and cancellation history.
- Exports and controlled deletion workflows support your retention processes.
Data rights and deletion
- GDPR data-subject access directly from the app: on request, you get all data stored about a person (incl. debtors, creditors, members, invitations) as a file export.
- After contract end, product access is blocked and the client remains reactivatable through billing for 90 days. Create required exports before contract end.
- Operational client data is removed after the grace period. Records subject to retention duties remain segregated and access-restricted until their applicable period ends.
- Automatic deletion cron runs daily; T-30, T-7, and T-1 reminder emails notify you in advance.
What we don't (yet) have
We don't sell compliance fairy tales. These points are currently not fulfilled; we communicate them openly because their absence may be relevant:
- No IDW PS 880 audit certificate for GoBD compliance. We design for traceable workflows based on GoBD principles, but no external auditor attestation is currently available.
- No ISO 27001 / SOC 2 certification. No such certification is currently available.
- No public bug-bounty program. Report security issues directly to [email protected]. There is no formal bug-bounty program with payouts at this time.
Questions?
For specific security inquiries, audit requests, or pen-test requests, write to [email protected].