Automation MCP Server Features Blog Pricing Contact
Zero data retention by architecture

Compliance and Security

Your invoices are processed in memory and never stored. Zero data retention is not a policy we enforce, it is an architecture we built.

Your system
InvoiceXML Processed in memory · EU servers
Your system

Nothing stored on our servers

GDPR compliant
EU-only processing
No AI training
Zero data retention
Stateless by design

Zero Data Retention Policy

Every invoice you send to our API is processed entirely in memory. The document is received over an encrypted connection, transformed or validated, and returned to you as a file stream in the same response. It is never written to disk, never queued in storage, never used for analytics or AI training, and never backed up.

Retention period, invoice content
None

The document exists only for the duration of the request.

Backups of invoice content
None

There is no stored copy to include in a backup set.

Uptime
99.95%

Server redundancy, load balancing and auto-scaling behind every request.

Invoice data submitted to InvoiceXML is processed in volatile memory only, is not written to persistent storage, and is irrecoverable by us once the API response has been delivered.

For vendor assessments and security questionnaires.

Data location and transfers

Your data never leaves the EU

All processing takes place on servers located in Frankfurt, Germany. There are no data transfers outside the European Economic Area, and no US-based processing of invoice content.

Frankfurt
Germany
Sole processing region
Infrastructure provider DigitalOcean
Jurisdiction Germany, EU
Transfers outside the EEA None
US-based processing None
Invoice content stored here None
Map of Europe with Germany marked on it

Germany · Frankfurt

No transfers outside the European Economic Area. No US-based processing of invoice content.

Infrastructure

Built on certified infrastructure

InvoiceXML runs on DigitalOcean datacenters in the EU. DigitalOcean maintains independently audited certifications, including SOC 2 Type II and ISO/IEC 27001, and publishes its audit reports and compliance documentation publicly.

Physical security, hardware lifecycle, network infrastructure, and datacenter disaster recovery are covered by DigitalOcean's certified controls. Our stateless application layer runs on top of that foundation.

Certifications and attestations held by DigitalOcean Independently audited · reports published by the provider
SOC 2 & SOC 3
Type II
Audited reports
ISO/IEC 27001 Certified
CIS Benchmarks Hardening baseline
Global PRP Certification Certified
PCI-DSS Compliant
CSA Self-Assessment CAIQ / STAR Level 1
These certifications, attestations and reports are held and published by DigitalOcean, our infrastructure provider. They cover the datacenter and platform layer our stateless application runs on; the audit reports are available directly from DigitalOcean below.

Certifications held and published by DigitalOcean, our infrastructure provider.

Encryption and access

Encrypted in transit, minimized by design

In transit

All API traffic is encrypted with TLS. Plain HTTP is not accepted, so an invoice is never transmitted in the clear. The response carries the same protection: your document is streamed back over that same encrypted connection.

At rest

Invoice content is never at rest on our systems, so at-rest exposure of your documents is eliminated rather than mitigated. Account and billing records, the only data we do hold, are stored encrypted.

Access

Production access is restricted to a minimal set of authorized personnel, protected by strong authentication. No employee can access your invoice content, because it does not persist anywhere to be accessed.

Use of your data

No secondary use. Ever.

We never

  • use your data for analytics or product development
  • use your data to train AI or machine learning models
  • share your data with third parties
  • retain your invoice content after the response is delivered

We only

  • process the document you send, for the operation you requested
  • validate every generated invoice against the official Schematron artefacts before it leaves our API
  • retain your account and billing details, for as long as you hold an account
Subprocessors

One subprocessor, and it never sees an invoice

We do not use subprocessors for invoice processing. Our processing pipeline runs on our own code, on infrastructure we control.

One third party is involved in the service, Paddle, our merchant of record, which handles checkout, billing and payments only. Paddle never receives or touches your invoice content.

Subprocessor Purpose Data involved
Paddle Billing and payments (merchant of record) Billing details only
This is the complete list. No other third party processes data on our behalf, and no subprocessor is involved in invoice processing.
Reliability and response

Continuity, and what happens if something goes wrong

Business continuity and disaster recovery

Our infrastructure runs with server redundancy, load balancing and auto-scaling. Datacenter-level disaster recovery is provided under DigitalOcean's certified controls.

Because no invoice data is retained, a recovery scenario never involves your invoice content: there is nothing of yours held to lose or restore. Recovery concerns service availability only.

Incident response and breach notification

We monitor the service continuously. In the event of a security incident, we investigate immediately, contain the issue, and notify affected customers without undue delay, in line with GDPR requirements. Because invoice content is never stored, the scope of any conceivable personal data incident is limited to account and billing information.

Responsible disclosure. Security researchers are welcome to report vulnerabilities to [email protected]. We respond promptly and appreciate coordinated disclosure.

Your controls

You stay in control

Delete your account any time

Directly from your account dashboard. Since no invoice content is stored, deletion removes everything we hold about you: your account and billing records.

Data Processing Agreement

Our Data Processing Agreement, including a Non-Disclosure agreement is available for Enterprise customers. Contact us if you want us to arrange it.

Questions from your security team?

Send your vendor assessment to [email protected] and we will complete it.

Compliance without custody

Generate, validate and convert compliant e-invoices without handing your data to anyone, including us.