Security

In short: invoices you have us validate or generate are processed in the memory of a server in the EU and discarded afterwards. All we store is what an account needs to work. The binding version, with every measure, is the data processing agreement.

Hosted in the EU

The website, the API and the database run at the hosting provider Railway in the EU West region (Amsterdam, Netherlands). NormAPI runs no servers of its own; physical security of the data centres lies with the provider.

NormAPI is operated by Dmytro Yalanskyi, based in Ukraine (see the legal notice). He alone has administrative access. There is no EU adequacy decision for Ukraine, which is why the data processing agreement includes the EU Standard Contractual Clauses.

Encrypted connections

  • normapi.de, normapi.com and api.normapi.de are reachable over TLS only; unencrypted requests are redirected to HTTPS.
  • HSTS instructs browsers to connect only over encryption for a year, including all subdomains.
  • The database has no public address. API and database are connected over the hosting provider's private, WireGuard-encrypted network.

Invoice content is not stored

A submitted invoice — XML, PDF or data to generate one from — is processed in memory and discarded after the response. It ends up neither in the database nor in log files, and it is not passed on to third parties.

All we store is:

  • Account: email address, sign-in method and acceptance of the terms
  • API keys, as a hash only
  • daily usage counters per key, for billing and abuse control
  • a request log with time, key name, endpoint, status code and duration — deleted after seven days
  • anonymous daily counts per triggered rule, with no link to a document or account

You can delete your account and export your data yourself at any time in the account area.

API keys stored only as hashes

Keys are generated randomly by the server (192 bits). You see a key exactly once; we store only its SHA-256 hash and therefore cannot read it ourselves. You can revoke keys in the account at any time. Because every request checks the key against the database directly, with no cache in between, a revoked key is refused from that moment on.

Sign-in links sent by email are valid for 24 hours and consumed on first use.

Availability

Availability is monitored externally; the status page shows the current state. Failed services restart automatically. Rate limits and caps on concurrent validations and PDF renderings protect against overload: under load the API answers quickly with 503 and Retry-After instead of timing out.

Sub-processors

These providers process data you hand us to process:

  • Railway Corporation

    548 Market St PMB 68956, San Francisco, CA 94104, USA

    Purpose
    Hosting of the website, the API and the database. Invoices are processed there in memory and not stored.
    Location
    EU West region (Amsterdam, Netherlands)
    Safeguards
    Data processing agreement under Art. 28 GDPR; EU Standard Contractual Clauses, as the provider is based in the USA
  • Zoho Corporation B.V.

    Utrecht, Netherlands

    Purpose
    Mailbox for support and correspondence — involves your data only if you send us some by email.
    Location
    Data centres in the EU
    Safeguards
    Data processing agreement under Art. 28 GDPR; processing in the EU

For NormAPI's own purposes — billing, sign-in emails, usage analytics — we also work with these providers:

  • Paddle.com Market Limited

    London, United Kingdom

    Purpose
    Payment processing as merchant of record. Paddle is a controller in its own right for this.
    Location
    United Kingdom
    Safeguards
    European Commission adequacy decision for the United Kingdom
  • Mailjet SAS

    13-13 bis rue de l'Aubrac, 75012 Paris, France

    Purpose
    Sending sign-in links and ruleset notifications; the email address is processed.
    Location
    European Union
    Safeguards
    Data processing agreement under Art. 28 GDPR; processing in the EU
  • PostHog, Inc.

    San Francisco, USA

    Purpose
    Usage analytics for the website and the account area. Invoice content is not captured.
    Location
    EU cloud (Frankfurt am Main)
    Safeguards
    Data processing agreement under Art. 28 GDPR; EU Standard Contractual Clauses
  • GitHub, Inc.

    88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA

    Purpose
    Sign-in with GitHub, only if you choose it. GitHub is a controller in its own right for this.
    Location
    USA
    Safeguards
    GitHub's own responsibility; the transfer happens at your request

We announce changes to the sub-processors at least 30 days in advance, and you can object (data processing agreement, § 5).

Data processing agreement and TOMs

The data processing agreement under Art. 28 GDPR forms part of the terms of service, so it applies to every customer, whatever the plan. The text, the technical and organisational measures (annex 1) and the sub-processors (annex 2): data processing agreement. We send a signed copy on request to kontakt@normapi.de.

Reporting a security issue

Please report vulnerabilities and incidents to kontakt@normapi.de with the subject "Security". We confirm receipt and come back with an assessment. In the event of a personal data breach we inform affected customers without undue delay, and no later than 48 hours after becoming aware of it. The contact is also available machine-readably at /.well-known/security.txt.