Security
In short: invoices you have us validate or generate are processed in the memory of a server in the EU and discarded afterwards. All we store is what an account needs to work. The binding version, with every measure, is the data processing agreement.
Hosted in the EU
The website, the API and the database run at the hosting provider Railway in the EU West region (Amsterdam, Netherlands). NormAPI runs no servers of its own; physical security of the data centres lies with the provider.
NormAPI is operated by Dmytro Yalanskyi, based in Ukraine (see the legal notice). He alone has administrative access. There is no EU adequacy decision for Ukraine, which is why the data processing agreement includes the EU Standard Contractual Clauses.
Encrypted connections
- normapi.de, normapi.com and api.normapi.de are reachable over TLS only; unencrypted requests are redirected to HTTPS.
- HSTS instructs browsers to connect only over encryption for a year, including all subdomains.
- The database has no public address. API and database are connected over the hosting provider's private, WireGuard-encrypted network.
Invoice content is not stored
A submitted invoice — XML, PDF or data to generate one from — is processed in memory and discarded after the response. It ends up neither in the database nor in log files, and it is not passed on to third parties.
All we store is:
- Account: email address, sign-in method and acceptance of the terms
- API keys, as a hash only
- daily usage counters per key, for billing and abuse control
- a request log with time, key name, endpoint, status code and duration — deleted after seven days
- anonymous daily counts per triggered rule, with no link to a document or account
You can delete your account and export your data yourself at any time in the account area.
API keys stored only as hashes
Keys are generated randomly by the server (192 bits). You see a key exactly once; we store only its SHA-256 hash and therefore cannot read it ourselves. You can revoke keys in the account at any time. Because every request checks the key against the database directly, with no cache in between, a revoked key is refused from that moment on.
Sign-in links sent by email are valid for 24 hours and consumed on first use.
Availability
Availability is monitored externally; the status page shows the current state. Failed services restart automatically. Rate limits and caps on concurrent validations and PDF renderings protect against overload: under load the API answers quickly with 503 and Retry-After instead of timing out.
Sub-processors
These providers process data you hand us to process:
Railway Corporation
548 Market St PMB 68956, San Francisco, CA 94104, USA
- Purpose
- Hosting of the website, the API and the database. Invoices are processed there in memory and not stored.
- Location
- EU West region (Amsterdam, Netherlands)
- Safeguards
- Data processing agreement under Art. 28 GDPR; EU Standard Contractual Clauses, as the provider is based in the USA
Zoho Corporation B.V.
Utrecht, Netherlands
- Purpose
- Mailbox for support and correspondence — involves your data only if you send us some by email.
- Location
- Data centres in the EU
- Safeguards
- Data processing agreement under Art. 28 GDPR; processing in the EU
For NormAPI's own purposes — billing, sign-in emails, usage analytics — we also work with these providers:
Paddle.com Market Limited
London, United Kingdom
- Purpose
- Payment processing as merchant of record. Paddle is a controller in its own right for this.
- Location
- United Kingdom
- Safeguards
- European Commission adequacy decision for the United Kingdom
Mailjet SAS
13-13 bis rue de l'Aubrac, 75012 Paris, France
- Purpose
- Sending sign-in links and ruleset notifications; the email address is processed.
- Location
- European Union
- Safeguards
- Data processing agreement under Art. 28 GDPR; processing in the EU
PostHog, Inc.
San Francisco, USA
- Purpose
- Usage analytics for the website and the account area. Invoice content is not captured.
- Location
- EU cloud (Frankfurt am Main)
- Safeguards
- Data processing agreement under Art. 28 GDPR; EU Standard Contractual Clauses
GitHub, Inc.
88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA
- Purpose
- Sign-in with GitHub, only if you choose it. GitHub is a controller in its own right for this.
- Location
- USA
- Safeguards
- GitHub's own responsibility; the transfer happens at your request
We announce changes to the sub-processors at least 30 days in advance, and you can object (data processing agreement, § 5).
Data processing agreement and TOMs
The data processing agreement under Art. 28 GDPR forms part of the terms of service, so it applies to every customer, whatever the plan. The text, the technical and organisational measures (annex 1) and the sub-processors (annex 2): data processing agreement. We send a signed copy on request to kontakt@normapi.de.
Reporting a security issue
Please report vulnerabilities and incidents to kontakt@normapi.de with the subject "Security". We confirm receipt and come back with an assessment. In the event of a personal data breach we inform affected customers without undue delay, and no later than 48 hours after becoming aware of it. The contact is also available machine-readably at /.well-known/security.txt.