Security & compliance
What we protect, and how
VatForge handles revenue data from five platforms and prepares your quarterly EU VAT figures. This page states exactly what is in place today, what we are building, and which certifications we do not hold. Last updated September 4, 2026.
No certifications are claimed here. VatForge holds no SOC 2, ISO 27001, PCI DSS or HIPAA attestation today, and no third-party penetration test report exists yet. Where a control comes from a subprocessor, we say so — their attestations are theirs, not ours.
In place today
Running in VatForge right now
Built to GDPR requirements
Published privacy policy, documented lawful basis, and data subject rights honored (access, deletion, portability, rectification, objection). GDPR is a legal framework, not a certification — no one issues a "GDPR certificate" and we don't claim one.
Data Processing Agreement available
Read the DPA or email dpa@vatforge.com for a counter-signed copy.
EU data hosting
EU-hosted via Supabase in Ireland (eu-west-1). Customer data stays in the EU. Pseudonymous site-usage analytics (Google Analytics 4) is processed in the US under the EU-US Data Privacy Framework and SCCs, only after analytics consent. VatForge is not self-hosted or on-premises.
Encryption in transit and at rest
TLS 1.2+ on every connection; AES-256 encryption of the database at rest — both provided and operated by Supabase, our EU infrastructure provider.
Row-Level Security enforced in the database
Access rules live at the data layer, so you can only ever reach your own rows — even if application code has a bug.
10-year retention archive
Transactions and OSS returns are retained for the 10-year period required by Article 369k of the EU VAT Directive. Swedish Bokföringslagen requires 7 years for the underlying accounting records; the longer OSS period applies where both are relevant.
Article 24b evidence collection
Every sale carries two non-contradictory pieces of buyer-location evidence, stored with the transaction as the VAT Directive requires.
CESOP exposure monitoring
Cross-border payment counts per payee are tracked live against CESOP thresholds. CESOP report generation is on the roadmap — monitoring is live today, report files are not.
Read-only platform integrations
VatForge reads from Stripe, Gumroad, Patreon, Lemon Squeezy and Substack with read-only access; we do not write anything back to your source accounts.
Data export in machine-readable formats
CSV and JSON export at any time. Your data is yours; you can leave with it.
Public subprocessor list
See our subprocessors. Changes are notified as set out in our DPA.
Secrets kept out of code and logs
API keys and credentials are stored in our provider's secrets manager, never in application source or log output.
Automated backups
Daily automated, encrypted backups run by our EU infrastructure provider.
Dependency and supply-chain scanning
A weekly plus change-triggered GitHub Actions job runs a full dependency audit and fails on any high or critical advisory; Dependabot opens patch pull requests automatically.
MCP access is read-only
When you connect Claude, ChatGPT or Cursor over MCP, only read tools are exposed — no write operations exist on that surface.
VIES VAT number validation
B2B VAT numbers are checked in real time against the EU's official VIES service; a failed check flags the transaction for review instead of silently applying reverse-charge.
Reverse-charge handling
Cross-border B2B digital sales to VIES-validated buyers are treated as reverse-charge (Article 196) and excluded from the OSS aggregation.
Human approval gate on VAT rate changes
The nightly rate sync proposes changes; nothing touches your live figures until a person approves it.
In progress
Underway, no dates committed
Independent security validation
Security review today is done by the founding team; formal penetration testing is planned before we scale. No third-party pen-test or audit report exists yet — when one does, we will publish its date and scope here.
CESOP report generation
Monitoring is live (see above); the report files themselves are on the roadmap.
Full version control of the database schema
Committing every compliance-critical schema definition to git migrations so each change is reviewable.
Customer-facing audit log export
An endpoint to pull your own audit trail programmatically.
Not yet
Tracked — we do not hold these
SOC 2 Type II
Not held. Tracked, not scheduled.
ISO 27001
Not held. Tracked, not scheduled.
ISO 27701 (privacy information management)
Not held. Tracked, not scheduled.
Annual penetration-test cadence
Not established yet.
Public bug bounty program
Not open yet.
CSA STAR self-assessment
Not submitted.
Principles
Data protection principles
- Data minimisation — we import only the transaction fields needed to compute VAT: amounts, timestamps, buyer country evidence and VAT numbers. Nothing else.
- Purpose limitation — your data is used to prepare your VAT position. It is not sold, shared with advertisers, or used to train AI models.
- Built to GDPR requirements — lawful basis documented, data subject rights honored. "GDPR-certified" is not a real thing; we don't claim it.
Encryption
Encryption at rest and in transit
Every connection to VatForge is served over HTTPS with TLS 1.2+. The database is encrypted at rest with AES-256. Both controls are provided and operated by Supabase, our EU infrastructure provider — we do not run our own crypto stack, and we say so rather than borrow the credit.
Infrastructure
Hosting and infrastructure
VatForge is EU-hosted via Supabase in Ireland (eu-west-1). All customer data — transactions, evidence records, returns — stays in the EU. Pseudonymous site-usage analytics (Google Analytics 4) is processed in the US under the EU-US Data Privacy Framework and SCCs, only after analytics consent. We are not self-hosted and not on-premises; infrastructure security is provided by Supabase, which holds its own SOC 2 Type II attestation. That attestation is theirs, not ours.
Access control
Who can reach your data
- Row-Level Security — enforced in the database on every table, so one account can never read another's rows, even if application code has a bug.
- Read-only integrations — platform connections (Stripe, Gumroad, Patreon, Lemon Squeezy, Substack) use read-only credentials; VatForge cannot write back to your accounts.
- Read-only MCP surface — AI clients connected over MCP get read tools only; no write operations exist on that surface.
- Secrets management — API keys live in our provider's secrets manager, never in source code or logs.
Continuity
Backup and disaster recovery
Daily automated, encrypted backups are run by our EU infrastructure provider. Your own exports (CSV/JSON) are available at any time, so you are never locked in while a restore is in progress.
Subprocessors
Who processes data for us
VatForge runs on a short, public list of subprocessors: Supabase (database and hosting, EU), Stripe (subscription payments), Vatstack (VAT rate reference data), Resend (transactional email), Lovable (application hosting), AWS Route 53 (DNS) and Plausible (cookieless, aggregate website analytics). The full list with purposes, locations and transfer safeguards lives at /security/subprocessors; changes are notified as set out in our DPA.
Incident response
If something goes wrong
Security issues are reviewed and answered without undue delay via security@vatforge.com. If a personal-data breach occurs, we follow GDPR Article 33: the supervisory authority is notified within 72 hours where required, and affected users are informed without undue delay.
Audit trail & retention
How long records are kept
Transactions and OSS returns are retained for 10 years per Article 369k of the EU VAT Directive — we retain the audit trail for that full period. Underlying accounting records are kept at least 7 years per Swedish Bokföringslagen; where both apply, the longer OSS period governs. These windows match our terms, privacy policy and DPA exactly.
Privacy by design
What we deliberately don't do
- No advertising or behavioural tracking inside the app — marketing pixels are blocked on every signed-in route; our website analytics are cookieless and aggregate-only.
- No customer VAT data sent to AI model training — an AI client connected over MCP queries your data with your own credentials; VatForge does not forward that data anywhere.
- No US-based CRM — customer enquiries route to email only.
Disclosure
Reporting a security issue
Found something concerning? Email security@vatforge.com. We review and respond without undue delay.
We do not run a formal bug bounty yet. We are happy to acknowledge good-faith disclosures publicly, with your permission, once the issue is resolved.
Contact
Questions about compliance?
- General — hello@vatforge.com
- DPA requests — dpa@vatforge.com
- Security issues — security@vatforge.com
- Privacy / data protection — privacy@vatforge.com
- More detail — Security FAQ · Subprocessors
If any claim on this page turns out to be inaccurate, email security@vatforge.com — we will correct it publicly and log the correction here.
Last updated September 4, 2026