Taxdoo closed its VAT services April 2026. Migrating your EU OSS setup? VatForge is where creators and micro-SaaS founders land.

Migration playbook

Security & compliance

What we protect, and how

VatForge handles revenue data from five platforms and prepares your quarterly EU VAT figures. This page states exactly what is in place today, what we are building, and which certifications we do not hold. Last updated September 4, 2026.

No certifications are claimed here. VatForge holds no SOC 2, ISO 27001, PCI DSS or HIPAA attestation today, and no third-party penetration test report exists yet. Where a control comes from a subprocessor, we say so — their attestations are theirs, not ours.

In place today

Running in VatForge right now

  • Built to GDPR requirements

    Published privacy policy, documented lawful basis, and data subject rights honored (access, deletion, portability, rectification, objection). GDPR is a legal framework, not a certification — no one issues a "GDPR certificate" and we don't claim one.

  • Data Processing Agreement available

    Read the DPA or email dpa@vatforge.com for a counter-signed copy.

  • EU data hosting

    EU-hosted via Supabase in Ireland (eu-west-1). Customer data stays in the EU. Pseudonymous site-usage analytics (Google Analytics 4) is processed in the US under the EU-US Data Privacy Framework and SCCs, only after analytics consent. VatForge is not self-hosted or on-premises.

  • Encryption in transit and at rest

    TLS 1.2+ on every connection; AES-256 encryption of the database at rest — both provided and operated by Supabase, our EU infrastructure provider.

  • Row-Level Security enforced in the database

    Access rules live at the data layer, so you can only ever reach your own rows — even if application code has a bug.

  • 10-year retention archive

    Transactions and OSS returns are retained for the 10-year period required by Article 369k of the EU VAT Directive. Swedish Bokföringslagen requires 7 years for the underlying accounting records; the longer OSS period applies where both are relevant.

  • Article 24b evidence collection

    Every sale carries two non-contradictory pieces of buyer-location evidence, stored with the transaction as the VAT Directive requires.

  • CESOP exposure monitoring

    Cross-border payment counts per payee are tracked live against CESOP thresholds. CESOP report generation is on the roadmap — monitoring is live today, report files are not.

  • Read-only platform integrations

    VatForge reads from Stripe, Gumroad, Patreon, Lemon Squeezy and Substack with read-only access; we do not write anything back to your source accounts.

  • Data export in machine-readable formats

    CSV and JSON export at any time. Your data is yours; you can leave with it.

  • Public subprocessor list

    See our subprocessors. Changes are notified as set out in our DPA.

  • Secrets kept out of code and logs

    API keys and credentials are stored in our provider's secrets manager, never in application source or log output.

  • Automated backups

    Daily automated, encrypted backups run by our EU infrastructure provider.

  • Dependency and supply-chain scanning

    A weekly plus change-triggered GitHub Actions job runs a full dependency audit and fails on any high or critical advisory; Dependabot opens patch pull requests automatically.

  • MCP access is read-only

    When you connect Claude, ChatGPT or Cursor over MCP, only read tools are exposed — no write operations exist on that surface.

  • VIES VAT number validation

    B2B VAT numbers are checked in real time against the EU's official VIES service; a failed check flags the transaction for review instead of silently applying reverse-charge.

  • Reverse-charge handling

    Cross-border B2B digital sales to VIES-validated buyers are treated as reverse-charge (Article 196) and excluded from the OSS aggregation.

  • Human approval gate on VAT rate changes

    The nightly rate sync proposes changes; nothing touches your live figures until a person approves it.

In progress

Underway, no dates committed

  • Independent security validation

    Security review today is done by the founding team; formal penetration testing is planned before we scale. No third-party pen-test or audit report exists yet — when one does, we will publish its date and scope here.

  • CESOP report generation

    Monitoring is live (see above); the report files themselves are on the roadmap.

  • Full version control of the database schema

    Committing every compliance-critical schema definition to git migrations so each change is reviewable.

  • Customer-facing audit log export

    An endpoint to pull your own audit trail programmatically.

Not yet

Tracked — we do not hold these

  • SOC 2 Type II

    Not held. Tracked, not scheduled.

  • ISO 27001

    Not held. Tracked, not scheduled.

  • ISO 27701 (privacy information management)

    Not held. Tracked, not scheduled.

  • Annual penetration-test cadence

    Not established yet.

  • Public bug bounty program

    Not open yet.

  • CSA STAR self-assessment

    Not submitted.

Principles

Data protection principles

  • Data minimisation — we import only the transaction fields needed to compute VAT: amounts, timestamps, buyer country evidence and VAT numbers. Nothing else.
  • Purpose limitation — your data is used to prepare your VAT position. It is not sold, shared with advertisers, or used to train AI models.
  • Built to GDPR requirements — lawful basis documented, data subject rights honored. "GDPR-certified" is not a real thing; we don't claim it.

Encryption

Encryption at rest and in transit

Every connection to VatForge is served over HTTPS with TLS 1.2+. The database is encrypted at rest with AES-256. Both controls are provided and operated by Supabase, our EU infrastructure provider — we do not run our own crypto stack, and we say so rather than borrow the credit.

Infrastructure

Hosting and infrastructure

VatForge is EU-hosted via Supabase in Ireland (eu-west-1). All customer data — transactions, evidence records, returns — stays in the EU. Pseudonymous site-usage analytics (Google Analytics 4) is processed in the US under the EU-US Data Privacy Framework and SCCs, only after analytics consent. We are not self-hosted and not on-premises; infrastructure security is provided by Supabase, which holds its own SOC 2 Type II attestation. That attestation is theirs, not ours.

Access control

Who can reach your data

  • Row-Level Security — enforced in the database on every table, so one account can never read another's rows, even if application code has a bug.
  • Read-only integrations — platform connections (Stripe, Gumroad, Patreon, Lemon Squeezy, Substack) use read-only credentials; VatForge cannot write back to your accounts.
  • Read-only MCP surface — AI clients connected over MCP get read tools only; no write operations exist on that surface.
  • Secrets management — API keys live in our provider's secrets manager, never in source code or logs.

Continuity

Backup and disaster recovery

Daily automated, encrypted backups are run by our EU infrastructure provider. Your own exports (CSV/JSON) are available at any time, so you are never locked in while a restore is in progress.

Subprocessors

Who processes data for us

VatForge runs on a short, public list of subprocessors: Supabase (database and hosting, EU), Stripe (subscription payments), Vatstack (VAT rate reference data), Resend (transactional email), Lovable (application hosting), AWS Route 53 (DNS) and Plausible (cookieless, aggregate website analytics). The full list with purposes, locations and transfer safeguards lives at /security/subprocessors; changes are notified as set out in our DPA.

Incident response

If something goes wrong

Security issues are reviewed and answered without undue delay via security@vatforge.com. If a personal-data breach occurs, we follow GDPR Article 33: the supervisory authority is notified within 72 hours where required, and affected users are informed without undue delay.

Audit trail & retention

How long records are kept

Transactions and OSS returns are retained for 10 years per Article 369k of the EU VAT Directive — we retain the audit trail for that full period. Underlying accounting records are kept at least 7 years per Swedish Bokföringslagen; where both apply, the longer OSS period governs. These windows match our terms, privacy policy and DPA exactly.

Privacy by design

What we deliberately don't do

  • No advertising or behavioural tracking inside the app — marketing pixels are blocked on every signed-in route; our website analytics are cookieless and aggregate-only.
  • No customer VAT data sent to AI model training — an AI client connected over MCP queries your data with your own credentials; VatForge does not forward that data anywhere.
  • No US-based CRM — customer enquiries route to email only.

Disclosure

Reporting a security issue

Found something concerning? Email security@vatforge.com. We review and respond without undue delay.

We do not run a formal bug bounty yet. We are happy to acknowledge good-faith disclosures publicly, with your permission, once the issue is resolved.

Contact

Questions about compliance?

If any claim on this page turns out to be inaccurate, email security@vatforge.com — we will correct it publicly and log the correction here.

Last updated September 4, 2026