Security & Compliance
Everything you need to know about how Invoice Navigator handles your data, maintains security, and ensures compliance with EU regulations.
Company Information
Legal Entity
Company: CCC Impact BV
Trading as: Invoice Navigator
Location: Apeldoorn, The Netherlands
Founded: 2024
Contact
General: hello@invoicenavigator.eu
Security: security@invoicenavigator.eu
Legal/DPA: legal@invoicenavigator.eu
Business Continuity
Your data is always accessible
If Invoice Navigator ceases operations:
- 90-day notice period for all customers
- Full data export tools available
- Evidence Packs remain verifiable (public keys archived)
- API versioning ensures integration stability during transition
Data Handling
What we store
Invoice files
Temporarily stored for processing, auto-deleted
Validation results
Error counts, metadata, compliance status
Evidence Packs
Cryptographically signed validation certificates
Account information
Email, company name, subscription details
Where it's stored
European Union (Frankfurt, Germany)
All data is stored on Supabase infrastructure, which runs on AWS eu-central-1.
Retention periods
| Data Type | Retention |
|---|---|
| Uploaded invoices (XML/PDF) | 24 hours, then auto-deleted |
| Validation history (Free tier) | 7 days |
| Validation history (Pro tier) | 1 year |
| Validation history (Business tier) | Unlimited |
| Evidence Packs | Per plan (30 days to 7 years) |
| API usage logs | 90 days |
| Account data | Duration of service + 90 days |
Data deletion
Users can delete their data at any time from the dashboard. Account deletion removes all associated data within 30 days. Contact legal@invoicenavigator.eu for data export or deletion requests.
AI and data training
We do NOT use your data to train AI models
Data handling by feature
Different features process data in different locations. Most features are 100% EU-based. Only the PDF Converter uses US-based AI processing.
| Feature | Processing Location | Data Stored |
|---|---|---|
| Invoice Validator | πͺπΊEU only (Frankfurt) | Validation results only |
| Invoice Fixer | πͺπΊEU only (Frankfurt) | Validation results only |
| PDF Converter | πΊπΈUS (Anthropic API) | Transient only (not stored) |
| Evidence Packs | πͺπΊEU only (Frankfurt) | Signed PDFs stored per plan |
| Dashboard / History | πͺπΊEU only (Frankfurt) | Validation history per plan |
| API Access | πͺπΊEU only (Frankfurt) | Usage logs (90 days) |
100% EU Data Residency
Sub-processors
We use the following third-party services to provide Invoice Navigator. All processors are GDPR-compliant and bound by data processing agreements.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (Frankfurt)EU |
| AWS S3 | File storage (invoices, evidence packs) | EU (Frankfurt)EU |
| Vercel | Application hosting and CDN | EU edge nodesEU |
| Stripe | Payment processing | EUEU |
| Resend | Transactional email delivery | US |
| Anthropic | AI chat assistant (transient processing only) | US |
| Upstash | Rate limiting and caching | EU (Frankfurt)EU |
| Sentry | Error monitoring (no PII) | EUEU |
We notify customers 30 days before adding new sub-processors that process customer data. Subscribe to updates at legal@invoicenavigator.eu.
Security
Encryption
- In transit:TLS 1.3 for all connections
- At rest:AES-256 encryption
Authentication
- Email/password with bcrypt hashing
- API keys with SHA-256 hash storage
- Session tokens with 30-day expiry
- Secure cookies (HttpOnly, Secure, SameSite)
Rate limiting
All API endpoints are protected by tier-based rate limiting using a sliding window algorithm:
Anonymous
10/day
Free
10/hour
Pro
100/hour
Business
1,000/hour
Infrastructure
- All infrastructure runs on SOC 2 Type II + ISO 27001 certified providers (Vercel, AWS, Supabase)
- Automated security updates and patching
- DDoS protection via Vercel edge network
- Continuous monitoring and alerting
MFA and SSO coming soon
Evidence Pack Verification
Every Evidence Pack is cryptographically signed to prove authenticity and prevent tampering. This provides audit-ready proof of compliance.
How it works
We create a SHA-256 hash of your invoice content
We sign the validation result with our RSA-2048 private key
The signature is embedded in the Evidence Pack
Anyone can verify the signature using our public key
Verify an Evidence Pack
Online
www.invoicenavigator.eu/verify/[id]API
GET /api/v1/verify/[id]Public key
Current signing key
Key ID: ep-signing-2025-01
Algorithm: SHA256-RSA-PKCS1
API & Reliability
Uptime Commitment
99.9%
Uptime SLA
<100ms
Avg Response
EU
Primary Region
Status & Monitoring
We monitor service health 24/7. For current status or incident reports, contact status@invoicenavigator.eu
API Versioning Policy
Rate Limits
Generous limits designed to support real-world usage without throttling legitimate traffic.
Free
100/mo
10/min
Startup
1K/mo
60/min
Growth
5K/mo
120/min
Scale
25K/mo
300/min
Incident Response
We take security incidents seriously. Here's our commitment to transparency and rapid response.
Response Timeline
Initial assessment and internal escalation
Customer notification if data affected
Detailed incident report to affected customers
GDPR notification to authorities if required
Notification Channels
Email Notifications
Direct notification to account owners for any incidents
In-App Alerts
Dashboard notifications for service updates
Incident History
No security incidents to date
Compliance Monitoring
We monitor official sources across 27 EU countries to keep compliance data current. This is our core differentiator - you always have the latest regulatory requirements.
What we monitor
- Tax authority websites (BMF, DGFiP, Agenzia delle Entrate, etc.)
- EUR-Lex for EU directives and regulations
- Official gazettes and government announcements
- Peppol and OpenPeppol specifications
How updates work
Automated system detects changes (checked daily)
AI classifies the change type and urgency
Human reviews and approves before anything goes live
All changes logged with source attribution
Transparency
Last verified dates
Every country page shows when data was last verified
Public changelog
View all regulatory updates βSource attribution
Every fact links to its official source
RSS feed
Subscribe to updates βCertifications & Compliance
Data Protection & Privacy
Infrastructure Provider Certifications
Invoice Navigator runs on certified cloud infrastructure. While these are our providers' certifications (not ours directly), your data benefits from their security controls.
Vercel
Application hosting & CDN
Amazon Web Services (eu-central-1)
Database, storage, and compute infrastructure
Supabase
Database and authentication
E-Invoicing Standards Conformance
Invoice Navigator validates and fixes invoices against the official European e-invoicing standards. Our validation engine implements the complete rule sets published by CEN TC/434 and OpenPeppol.
| Standard | Version | Rules Implemented | Status |
|---|---|---|---|
| EN 16931 | v1.3.11 | 65+ business rules (BR-01 to BR-65) | Conformant |
| Peppol BIS Billing | v3.0.17 | 120+ Peppol-specific rules | Conformant |
| XRechnung | v3.0.2 | BR-DE rules + Schematron | Conformant |
| Factur-X / ZUGFeRD | v1.0.07 | CII + PDF/A-3 profiles | Conformant |
| FatturaPA | v1.2.2 | Italian SDI format rules | Conformant |
Validation tested against official test suites
EU Regulatory Compliance
Validates invoices against the EN 16931 semantic data model required by the EU e-invoicing directive.
Supports structured e-invoicing formats required by the VAT in the Digital Age initiative (adopted March 2025).
Full implementation of CEN TC/434 business rules with 450+ test invoice verification.
Validates Peppol BIS Billing 3.0 invoices for cross-border e-invoicing compliance.
Planned Certifications
Cloud Security Alliance self-assessment (free, public registry)
Official observer status with the OpenPeppol association
Independent audit of security controls
Information security management system certification
Contact
Security concerns
security@invoicenavigator.euDPA requests
legal@invoicenavigator.euVulnerability disclosure
Responsible disclosure β