Security by Design. Your Data, Your Control.
EU Trace is built secure from the ground up – with encryption, isolation, and transparency.
Encryption
Your data is always protected – in transit and at rest.
- TLS 1.3 for all connections
- AES-256-GCM encryption at rest
- SHA-256 hash chain for audit integrity
Multi-Tenant Isolation
Each tenant is strictly isolated – at database and key level.
- Schema-per-tenant in PostgreSQL
- Tenant-specific KMS keys
- Cross-tenant read tests in CI
GDPR Compliance
Data protection is built into our architecture.
- PII in separate encrypted table
- Erasure via key destruction
- Chain integrity preserved
Open Source SDKs
Our SDKs are published on GitHub – your team can audit every line.
- TypeScript, Python, and Go
- MIT license
- Regular security audits
Local CLI
Offline validation mode: no data leaves your network.
- Single Go binary
- Embedded XSDs and rules
- Zero telemetry
Published Specs
Transparency through public documentation.
- JSON→XML mapping spec
- GDPR procedure
- DPA template
Security FAQ
Common questions about the security of the EU Trace platform.
Exclusively in German data centers (Frankfurt, Hetzner/Equinix). No data leaves the EU.
Yes, we provide a GDPR-compliant Data Processing Agreement (DPA) upon request.
Yes, the Enterprise plan supports BYOK (Bring Your Own Key) for audit ledger and encryption.
We have a formal incident response procedure with 4h response time and notify affected customers within 24h.
ISO 27001 is in preparation (Q3 2026). Our architecture follows BSI IT-Grundschutz.
Still have questions? Contact our team
Ready to Integrate? Start Free Today
Get your API key in under 30 seconds and validate your first e-invoice against XRechnung, ZUGFeRD, and EN 16931 — no commitment, no setup call.
