Your invoices are processed in memory and never stored. Zero data retention is not a policy we enforce, it is an architecture we built.
Nothing stored on our servers
Every invoice you send to our API is processed entirely in memory. The document is received over an encrypted connection, transformed or validated, and returned to you as a file stream in the same response. It is never written to disk, never queued in storage, never used for analytics or AI training, and never backed up.
The document exists only for the duration of the request.
There is no stored copy to include in a backup set.
Server redundancy, load balancing and auto-scaling behind every request.
Invoice data submitted to InvoiceXML is processed in volatile memory only, is not written to persistent storage, and is irrecoverable by us once the API response has been delivered.
For vendor assessments and security questionnaires.
All processing takes place on servers located in Frankfurt, Germany. There are no data transfers outside the European Economic Area, and no US-based processing of invoice content.
Germany · Frankfurt
No transfers outside the European Economic Area. No US-based processing of invoice content.
InvoiceXML runs on DigitalOcean datacenters in the EU. DigitalOcean maintains independently audited certifications, including SOC 2 Type II and ISO/IEC 27001, and publishes its audit reports and compliance documentation publicly.
Physical security, hardware lifecycle, network infrastructure, and datacenter disaster recovery are covered by DigitalOcean's certified controls. Our stateless application layer runs on top of that foundation.
Certifications held and published by DigitalOcean, our infrastructure provider.
All API traffic is encrypted with TLS. Plain HTTP is not accepted, so an invoice is never transmitted in the clear. The response carries the same protection: your document is streamed back over that same encrypted connection.
Invoice content is never at rest on our systems, so at-rest exposure of your documents is eliminated rather than mitigated. Account and billing records, the only data we do hold, are stored encrypted.
Production access is restricted to a minimal set of authorized personnel, protected by strong authentication. No employee can access your invoice content, because it does not persist anywhere to be accessed.
We do not use subprocessors for invoice processing. Our processing pipeline runs on our own code, on infrastructure we control.
One third party is involved in the service, Paddle, our merchant of record, which handles checkout, billing and payments only. Paddle never receives or touches your invoice content.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Paddle | Billing and payments (merchant of record) | Billing details only |
Our infrastructure runs with server redundancy, load balancing and auto-scaling. Datacenter-level disaster recovery is provided under DigitalOcean's certified controls.
Because no invoice data is retained, a recovery scenario never involves your invoice content: there is nothing of yours held to lose or restore. Recovery concerns service availability only.
We monitor the service continuously. In the event of a security incident, we investigate immediately, contain the issue, and notify affected customers without undue delay, in line with GDPR requirements. Because invoice content is never stored, the scope of any conceivable personal data incident is limited to account and billing information.
Responsible disclosure. Security researchers are welcome to report vulnerabilities to [email protected]. We respond promptly and appreciate coordinated disclosure.
Directly from your account dashboard. Since no invoice content is stored, deletion removes everything we hold about you: your account and billing records.
Our Data Processing Agreement, including a Non-Disclosure agreement is available for Enterprise customers. Contact us if you want us to arrange it.
Send your vendor assessment to [email protected] and we will complete it.
Generate, validate and convert compliant e-invoices without handing your data to anyone, including us.