Trust · Proof as data

What we check, what we change, what we keep

No badges. The validator that runs, the rules it runs against, what leaves your file, what is stored and for how long, and what the public proof contains.

What is checked, by which validator
FormatRuleset versionValidator
XRechnung3.0.2KoSIT Validator 1.5.0, XRechnung configuration (XSD + Schematron)
EN 169311.3.11UBL/CII XSD + CEN EN 16931 Schematron
Peppol BIS Billing3.0.17UBL XSD + CEN EN 16931 Schematron + Peppol BIS Schematron
Factur-X1.0.07CII XSD + CEN EN 16931 Schematron + profile Schematron
FatturaPA1.2.2FatturaPA XSD + national rules
SimplerInvoicing2.0.3UBL XSD + SI-UBL rules
Belgian e-FFF3.0UBL XSD + e-FFF rules

XRechnung files are checked with the same KoSIT validator German public-sector recipients use. Every change is followed by a new check; a file is only offered for download after it passes.

What we change. And what we don't.
—We never change amounts, line items or taxes.
+From your PDF or Excel file we take the details as they stand. If the totals disagree, we say so.
+We only add missing mandatory details that you confirm yourself.
+Every output is checked with the KoSIT validator, the one public authorities use.
+What becomes public: only checksum, time and result. Never the invoice content.
What is stored, and for how long

Your file is used only to check and fix your invoice and to deliver your result. Results are kept so you can download a verified file again for 90 days; validation logs are deleted after 90 days. You can request deletion at any time.

DataRetention
Uploaded invoices and results (XML/PDF)Kept for your 90-day re-download window; deleted on request at any time
Validation and API logs90 days, then deleted
PDF/Excel extraction drafts24 hours, then deleted
Account dataUntil you delete your account
API usage logs90 days

Deletion requests: hello@invoicenavigator.eu. Full policy: Privacy policy.

What the proof contains
SHA-256Checksum of the checked file. Identifies the file without revealing its content.
ValidatorWhich validator ran, with its version.
RulesetWhich rules and which version the file was checked against.
TimeWhen the check completed, UTC.
ResultPassed or not passed.
Public link/verify/{sha-256}: anyone with the hash can confirm the result. No invoice content is shown.

Proven: this file passed this check at this time. Not proven: tax correctness or acceptance by the recipient. The proof contains no invoice content.

Signed evidence-pack certificates carry a key id; the public key is served at /.well-known/evidence-pack-keys.

Which services process the data
ServicePurposeWhat it receives
SupabaseDatabase and sign-in (email one-time codes)Results, hashes, account data
VercelHosting; the checks run hereThe uploaded file while it is checked
StripePaymentPayment details; we never see the card
ResendTransactional emailYour email address, the messages we send
Anthropic (US)Reading fields from PDF, image, CSV and Excel on /convert; proposing values for missing mandatory fields on the checkerThe uploaded file or the relevant part of the invoice
UpstashRate limits and daily spend countersCounters keyed by IP; no invoice content
SentryError monitoringStack traces; no invoice content
PostHogProduct analyticsPage and funnel events

The checker itself does not send your invoice to Anthropic; only the converter and the optional proposal for a missing mandatory field do. All connections use TLS.

Who is behind it
CompanyCCC Impact BV, trading as Invoice Navigator
AddressApeldoorn, the Netherlands
Chamber of Commerce90941284
VAT ID[USt-IdNr.]
Contacthello@invoicenavigator.eu · reply within one working day