Security & Compliance
Invoices are sensitive — they contain payment data, IBANs and business contacts. Beleggo is therefore built so that this data never leaves your device in the first place. This page explains exactly how that works and how you can verify it yourself.
Local processing — no transmission
Opening, checking, repairing, creating and converting e-invoices runs entirely in your browser or local app via the Saxon-JS engine. Invoice contents, uploaded files and the XML/PDF documents you generate are not sent to our servers, not stored and not accessible to us. After the first load, Beleggo also works offline.
Verify it yourself
You don't have to take our word for it: open your browser's developer tools (the "Network" tab), load an invoice and run a validation. You'll see that no invoice data leaves the device. As a test, disconnect from the internet — the check keeps working.
What is stored in the browser
Your seller profile, saved customers and any Pro licence are kept in your browser'slocalStorage and remain solely on your device. You can remove them at any time via "Clear data" in the tool or your browser settings. localStorage is not a tamper-proof archive — export invoices to your DMS for statutory retention.
Sub-processors
To operate the website and process Pro purchases we use a few providers — none of which have access to your invoice data:
- Cloudflare Pages — website hosting (delivery, server logs).
- Stripe — payment processing for Pro licence purchases.
See the privacy policy for details.
Validation engine and currency
Our engine is cross-checked against the official KoSIT test invoices and the official KoSIT validator — automatically, in our CI. The rule sets in use (KoSIT, XRechnung, Peppol) are bundled with versions and monitored against the official sources, so changes don't go unnoticed.
Responsible disclosure
If you find a security vulnerability, please report it confidentially to[email protected] before disclosing it publicly. We will acknowledge receipt and work on a timely fix. See also oursecurity.txt.
Certifications (roadmap)
Beleggo is not currently ISO 27001 or SOC 2 certified. The local, server-less approach significantly reduces the attack surface, since invoice data never leaves the device. We are evaluating formal certifications as the product grows.
Last updated: July 2026.