Security
What we can evidence, and what we cannot
A security page is quickly filled with badges. This one says what actually happens technically, and where we deliberately promise nothing.

Encrypted in transit
The connection between your device and the cloud is encrypted. The site also sets HSTS, a content security policy and prevents embedding in other sites.
Tenants are separated
Your data belongs to a tenant. Separation is enforced server-side on every request and additionally secured at database level through row-level rules. A hidden menu is not security, so we check on the server, not in the browser.
Secrets are stored encrypted
Credentials you enter, for email sending or a shop, are encrypted before being stored. A look into the database does not reveal them.
Locked, not deletable
A locked invoice is never changed and never deleted. Corrections run through cancellation and reissue. Every action is recorded with a timestamp.
Per-person permissions
You invite staff by email and give each exactly the areas they need. Access can be time-limited. Only owners and full-access admins see team management.
What we deliberately do not claim
- No statement about server location. Where and by which processors your data is handled is set out in the privacy policy, and only there.
- No backup promise. Until we have verified the scope, we do not promise it.
- No full offline operation. A local cache bridges short connection drops, nothing more.
- No certification. There is no GoBD certification for software, and we do not pretend otherwise.
Applies to every plan
Encryption, tenant separation, locking and the audit trail are not a plan question. They apply in the free Start plan just as in Business. Team roles and time-limited access come with Business.
Write your first invoice.
The Start plan is free with no time limit. No bank connection, no installation, no credit card.