Skip to content
Rechnungskit

Your documents.
Triple-secured, in two countries, every minute.

Before you trust a service with invoices, customer data and payments, you want to know: where is the data, who can get to it, and what happens during an outage or if you cancel? Each question below starts with the short answer. Expand the details if you need them.

Automatically monitored, around the clock

At a glance

Last updated: September 2026
  • Server location Germany Hetzner, Falkenstein data center, certified under ISO/IEC 27001
  • Providers EU only Backup in Helsinki (Finland), no US cloud provider, no transfer to third countries
  • Encryption TLS and AES-256 All connections encrypted, plus the document archive and backups
  • Backups Continuous At most about one minute of data loss, three copies in two countries
  • Sign-in Passkey or 2FA Passwordless or with a second factor, rate limit against guessing
  • Data protection DPA under Art. 28 Data processing agreement (AVV), publicly available
  • GoBD archive Immutable Write-protected (WORM), SHA-256 checksum on every retrieval, 8 years
  • Export Any time Complete archive, free for 90 days after you cancel

Certificates: Rechnungskit itself has no certificate of its own such as ISO 27001 or SOC 2. The data center where your data lives is certified. Why that is

Where is my data stored?

In Germany, with Hetzner in the Falkenstein data center. An encrypted backup copy is kept in Helsinki (Finland). All service providers are based in the EU, and no data goes to a third country.

  • Production system Germany Application and database, backed up every minute
  • Immutable archive Germany Finalized documents, write-protected and versioned
  • Encrypted backup Finland (EU) Encrypted in Germany, only then transferred
Show details
  • No US cloud provider: The application, database, document archive and backups run exclusively at European companies. US providers remain subject to the US CLOUD Act even with servers in Frankfurt; our service providers do not.
  • Three copies, two storage systems: If a system, a server or an entire data center fails, no data is lost.
  • Only encrypted data at the backup location: Everything that leaves Germany is encrypted client-side with AES-256 first. Without the separately stored keys, nobody there can read the data, not even the data center operator.
  • Protective layer in front: Bunny.net (based in Slovenia) checks and speeds up traffic but does not store customer data permanently.

How is data protection handled?

Through a data processing agreement (AVV) under Art. 28 GDPR that you can read in advance. Rechnungskit processes the data only on your instructions and never for its own purposes. All service providers involved are based in the EU.

Service providers that process data on our behalf
ProviderTaskBased in
Hetzner Online GmbHServers, database, object storage, encrypted backupsGermany, Finland
Bunny (BunnyWay d.o.o.)CDN, DNS and web application firewallSlovenia
Brevo (Sendinblue GmbH)Sending transactional emailsGermany
Nebius B.V.Answers from the AI assistant Kit, from chat input onlyNetherlands

Source: DPA (AVV), Annex 1 and privacy policy. You connect payment services and shop systems such as Stripe, PayPal or Shopify with your own account. They are your contractual partners, not processors of Rechnungskit. PDF and ZUGFeRD generation run on our own infrastructure.

Show details
  • New service providers: Rechnungskit announces planned changes with reasonable notice. You can object for good cause.
  • Data breaches: If a personal data breach becomes known, Rechnungskit notifies you without undue delay.
  • Audits: You or an auditor you appoint can check compliance with the DPA, including inspections, with reasonable notice.
  • Confidentiality: Anyone who processes data is bound to confidentiality, including after their work ends.
  • Technical and organizational measures: The measures are listed in Annex 2 of the DPA. The sections on this page explain what they mean in practice.

Who can access my data?

The people you invite, with the role you give them. The database technically separates each customer's data. You revoke access for your tax advisor, agency or support with one click, and every action is logged.

Show details
  • Tenant separation in the database: Row-level security in PostgreSQL, enforced on all tenant tables. Without a valid tenant context, the database returns not a single row (fail-closed).
  • Roles: Owner, bookkeeping, tax audit and read-only. Permissions are enforced centrally and tested automatically: the read-only role can neither change nor download anything.
  • Tax advisor: Your tax advisor works in a separate area, sees documents and exports and maintains the DATEV settings. Every one of their actions is logged immutably.
  • Agency and support: This access ends automatically after 30 days. You also grant access for Rechnungskit support yourself, under Settings → Access.

How is the data protected?

All connections run over TLS, and the document archive and backups are also encrypted with AES-256. You sign in with a passkey or with two-factor authentication. A firewall in front of the server catches attacks and overload.

Show details
  • Encryption: TLS for every connection, AES-256 for archived documents and for everything that leaves Germany as a backup. Rechnungskit stores the credentials for your connected services with AES-256-GCM.
  • Sign-in: Passwordless with a passkey or with a second factor. Passwords need at least 12 characters, and a rate limit slows down guessing. Changing your password signs you out on all other devices.
  • Firewall and DDoS protection: Web application firewall, DDoS protection and rate limiting via Bunny.net. The server itself can only be reached through this layer, not directly from the internet.
  • Hardened servers: Default-deny firewall, key-only SSH, automatic security updates.
  • Verified events and API: Webhooks from payment providers are verified by signature. The public API is rate-limited per access key.
  • Source code and operations: Security audit of the source code in July 2026, all findings fixed. Keys and passwords are kept outside the source code, and development and production are separated.

How is the data backed up?

Continuously: every change to the database is backed up in under a minute. Every document exists three times, one copy encrypted in Finland. Independent monitoring watches the backups, and recovery is practiced regularly.

Show details
  • Three copies, two storage systems, a second location (3-2-1): The database is backed up continuously, plus independent daily dumps. The document archive and volumes are mirrored, encrypted, to Helsinki every night, and there is also a weekly server snapshot.
  • Ransomware protection: The application has no credentials for the backup location. A compromised server could neither read nor delete backups.
  • Monitored: Every backup run is checked for integrity and reports to independent monitoring. If the report is missing, an alert goes out automatically.
  • Practiced: Recovery drills (database restore, sample documents with checksum comparison) run regularly and are logged.
  • Backup retention: Tiered by daily, weekly, monthly and yearly. Backups are overwritten after three years at the latest.

What happens during an outage?

An outage delays new documents by minutes to a few hours, but no document is lost. Three layers that work independently of each other make sure of that.

  1. Your data lives at the shop and the payment provider
  2. Providers keep ringing for up to three days
  3. Rechnungskit additionally reconciles on its own
Show details
  • Your data lives at the shop and the payment provider: A webhook is just the doorbell: the order or payment itself lives durably at Shopify, WooCommerce, Stripe, Mollie and co. If the doorbell does not reach us, nothing is lost, because we can always look it up directly at the source.
  • Providers keep ringing for up to three days: If a notification does not reach our server, providers repeat it automatically: Stripe and PayPal for up to three days, Shopify for about 48 hours, others similarly. Rechnungskit reliably detects duplicate deliveries and never books twice.
  • Rechnungskit additionally reconciles on its own: Independent of webhooks, Rechnungskit actively polls all connections: Shopware every 15 minutes, all others several times a day. Even a completely missed webhook costs at most a few hours of delay. And where a correction needs human review, a visible task appears in your account, nothing happens silently.
  • Updates: Updates also run without a gap: the previous server keeps serving until the new one is fully ready. A notification only counts as processed once it is completely stored, otherwise it is delivered again.

How are documents archived (GoBD)?

Immutably: finalized documents sit write-protected in the archive, each with a SHA-256 checksum that is verified on every retrieval. Corrections go through a cancellation invoice (Storno) and a new invoice.

Show details
  • WORM storage: Versioned object storage with Object Lock. Overwriting or deleting is technically blocked, even for Rechnungskit itself.
  • Locks in the database: Archived documents, line items, template versions and the log are protected against changes and deletion by triggers.
  • Gapless number sequences: Number assignment and archiving are one transaction. A document that fails validation does not use up a number.
  • Retention: 8 years (§ 147 (3) AO, the period for accounting records since 2025).
  • DATEV export: Standard DATEV EXTF format (SKR03/SKR04). A locked export stays unchanged, and every later download is byte-identical (SHA-256 verified). If an account mapping is missing, the line is skipped with a warning and never booked wrongly.
  • Process documentation: Rechnungskit provides the technical description for your process documentation (Verfahrensdokumentation; link below).

What happens to my data if I cancel?

You can export your complete archive at any time, and free of charge for 90 days after you cancel. The retention duty under § 147 AO stays with you, so the export is complete and machine-readable.

Show details
  • Contents: The original ZUGFeRD XML files (the legally binding version) and all DATEV exports, plus PDF copies of every invoice for easy reading if you want them. The VAT evidence for your deliveries is included too.
  • Standard formats: Invoices come as XML under EN 16931, bookings in the open DATEV EXTF format that any tax advisor can import without activation.
  • How it works: The export runs in the background. As soon as it is ready, you get an email with the download link.
  • Deletion and return: What happens after the contract ends is set out in section 8 of the DPA.

What certificates are there?

The data center is certified under ISO/IEC 27001. Rechnungskit itself has no certificate of its own such as ISO 27001 or SOC 2. No software has a GoBD certificate.

Questions and answers
Is there a GoBD certificate?
No, and none exists for any software: the tax authorities issue no attestations, and third-party certificates are not binding (GoBD, para. 179 to 181). What matters are the actual measures (above) and your process documentation. Rechnungskit provides the technical description for it.
Is Rechnungskit itself ISO 27001 certified?
No. A certification of our own is a multi-month process that only makes sense from a certain company size. What is certified is the infrastructure that physically holds your data; the measures above it are documented and available in detail on request.
Is Rechnungskit a “DATEV-certified interface”?
No. Rechnungskit produces the open DATEV standard format EXTF, which every tax firm imports without any activation. No certification is required for that.
Who bears the responsibility?
The retention obligation under Section 147 AO lies with you as the business. Rechnungskit provides the archive, the integrity proof and an export at any time so you can meet this obligation, regardless of whether you remain a customer.

Documents for your review

We answer questions about security and data protection by email: support@rechnungskit.de

No tax or legal advice. Information as of September 2026.

Rechnungskit
SECURITY · HOSTING · COMPLIANCE
Last updated: September 2026 · rechnungskit.de

Where your documents live, and why they are safe there

Rechnungskit does not hold its own certificate (such as ISO 27001 or SOC 2). What it has instead: an ISO 27001 certified data centre in Germany, technical safeguards that can be verified, and GoBD and DATEV requirements implemented directly in the system. This page summarises what that means in practice.

100% EU
Servers in Germany, backup in Finland, no US cloud provider
ISO 27001
Certified data centre (Hetzner, Falkenstein)
WORM + SHA-256
Immutable document archive, checksum on every retrieval
DATEV EXTF
Lockable exports, provably byte-identical

Hosting and data location

EU ONLY
  • Production system in Germany: Hetzner Online, Falkenstein data centre, certified to ISO/IEC 27001.
  • No US cloud provider in the processing chain: application, database, document archive and backups run exclusively with EU providers.
  • Backup in Helsinki (Finland, EU): Everything that leaves Germany is encrypted client-side before transfer (AES-256). The backup location only ever sees ciphertext.
  • Protective layer: web application firewall and bot protection via a European provider (Bunny, Slovenia).
  • Data processing: DPA under Art. 28 GDPR at rechnungskit.de/avv. All subprocessors are based in the EU.

GoBD archive

IMMUTABLE
  • WORM storage: Every finalised document (ZUGFeRD PDF/A-3 with EN 16931 XML) lives in versioned object storage with Object Lock. Overwriting or deleting is technically blocked, even for Rechnungskit itself.
  • Integrity proof: SHA-256 checksum per document, verified on every retrieval. A tampered document would be detected immediately.
  • Database-side locks: Archived documents, line items, template versions and the audit log are locked against UPDATE and DELETE (triggers). Corrections only via cancellation and reissue.
  • Sequential number ranges: Number assignment and archive write are one transaction. A document that fails validation never consumes a number.
  • Retention: 8 years (Section 147(3) AO, the period for accounting documents since 2025). The complete archive export is available to you at any time, free of charge even 90 days after the contract ends.

DATEV export and tax firm

LOCKING
  • Standard format DATEV EXTF (posting batch, SKR03/SKR04): your tax firm imports the file directly into DATEV without extra software.
  • Locking: A locked export is immutable, every later download byte-identical (SHA-256 verified). Only the owner and the tax-firm role may lock.
  • Tax-firm access with audit trail: the firm works in its own area, sees documents and exports and maintains account mappings. Every action is immutably logged, access is revocable in one click.
  • No silent mispostings: If an account mapping is missing, the line is skipped with a warning, never posted incorrectly.

Application and access

LAYERED
  • Tenant isolation at the database level: row-level security in PostgreSQL, enforced on all tenant tables. Without a valid tenant context the database returns no row (fail-closed).
  • Roles and rights: owner, accounting, tax firm, tax audit (time-limited read access), read. The permission matrix is enforced centrally and covered by automated tests: the read role can change nothing and download nothing.
  • Time-limited third-party access: support and agency access expires automatically after 30 days.
  • Transport and storage: TLS for all connections, archive documents additionally AES-256 encrypted, minimum password length and rate limiting against brute force.
  • Server hardening: default-deny firewall, SSH by key only, automatic security updates. Source-code security audit in July 2026, all findings resolved.

Backup and recovery

3-2-1
  • Three copies, two storage systems, one second location: database backed up continuously (max. about 1 minute of data loss) plus daily independent dumps; document archive and volumes mirrored to Helsinki encrypted every night; weekly server snapshot.
  • Ransomware-resistant: the application holds no credentials for the backup location. A compromised server could neither read nor delete backups. The archive is additionally protected by versioning and Object Lock.
  • Practised, not just planned: recovery drills are performed and logged regularly (database restore, sample documents with checksum comparison). Independent monitoring alerts if a backup fails to appear.

Frequently asked questions about certifications Honestly stated: what Rechnungskit does not have, and why that is fine

TRANSPARENCY

Is there a GoBD certificate?

No, and none exists for any software: the tax authorities issue no attestations, and third-party certificates are not binding (GoBD, para. 179 to 181). What matters are the actual measures (above) and your process documentation. Rechnungskit provides the technical description for it.

Is Rechnungskit itself ISO 27001 certified?

No. A certification of our own is a multi-month process that only makes sense from a certain company size. What is certified is the infrastructure that physically holds your data; the measures above it are documented and available in detail on request.

Is Rechnungskit a “DATEV-certified interface”?

No. Rechnungskit produces the open DATEV standard format EXTF, which every tax firm imports without any activation. No certification is required for that.

Who bears the responsibility?

The retention obligation under Section 147 AO lies with you as the business. Rechnungskit provides the archive, the integrity proof and an export at any time so you can meet this obligation, regardless of whether you remain a customer.

Rechnungskit · Questions about security and privacy: support@rechnungskit.de No tax or legal advice. Information as of September 2026.

Technical and organisational measures in the contractual context: Data processing agreement (DPA)

Manual work you can forget about.

Compliant e-invoices, audit-proof archive and DATEV export, automatically from your payments. Safely stored is included.

Try it now
de en