What stands up to a tax audit under GoBD
| Building block | What ZepDesk does |
|---|---|
| Bookings | No booking can be deleted, not even by our operations team. Corrections are made with a reversal that swaps debit and credit, carries a reason and points to the original. |
| Locked periods | After the period closing, nobody changes amounts, dates or accounts of bookings, receipts and invoices of that period any more; only a status such as “paid” may still change. If our operations team does intervene, it needs a reason, and the intervention is recorded in the change log. |
| Receipts | Every file is stored with a SHA-256 checksum, so it can later be shown that it is unchanged. |
| Change log | Always on, on every plan. Each entry names the user, the time, the changed fields and the content before and after; for an action via the AI assistant also who confirmed it. Filter by period, document type and user, export as CSV. |
| Tax audit | The data carrier under section 147 (6) AO for one year: a ZIP with CSV files and the description in index.xml. The administration creates it under the tax audit export. |
| Process documentation | With the Compliance plugin, as a template from your company data, in versions, with a completeness check and as a PDF, plugins. |
| Till | With the Cash Book plugin: security device under section 146a AO through your own fiskaly account and export in DSFinV-K format for a cash inspection. |
Why nothing can change unnoticed.
Each of these actions writes an entry to the change log, and each entry carries the checksum of its predecessor, one chain per company and document type. If an entry is changed afterwards, the chain no longer matches from that point; the overview checks it in the Compliance tab.
Example: one chain for the document type booking
- Entry 1Booking createdChecksum
9f1c27a4 - Entry 2Booking finalisedEntry altered afterwardsPredecessor
9f1c27a4Checksum4d2fb871 - Entry 3Reversal booking with a reasonPredecessor
4d2fb871Checksumc0e5913b - Entry 4New booking createdPredecessor
c0e5913bChecksum07e5c3a1
Checksums shortened, as sample values.
Section 146 (4) AO requires that the original content of a record remains ascertainable. That is why every entry holds the content before and after.
What an entry looks like

Real view from ZepDesk: an entry in the change log with the content before and after.
Who may do what
What someone sees and changes depends on their role in each company: Administration, Accounting, Sales, Tax, Read-only or Employee, roles and collaboration.
Each person switches it on in their profile, with an authenticator app or a code by e-mail. It applies to the central sign-in and therefore to all of that person's companies.
A key has the rights of this company's administration. Only the administration may create and revoke it; the secret is shown exactly once.
For your own customers, ZepDesk compiles a person's data or anonymises it on the administration's instruction; invoices and receipts remain unchanged because of the retention obligation. Access requests and deletion rules are handled by the Compliance plugin.
Signable online inside your account, with no separate negotiation, including the list of subprocessors.
Real recording from ZepDesk: users with search and the history of sign-ins.Real view from ZepDesk: roles per company, here the Tax role for the tax advisor.Real view from ZepDesk: creating and revoking API keys.
Questions on security and compliance
All questions and answersIs ZepDesk certified?
The operator's data centers are certified to ISO 27001. For the software itself we do not hold our own ISO certification, and we say so openly; the GoBD requirements (Germany's rules for proper digital bookkeeping) are implemented technically and documented.
Who can see my data?
The users you invite, and our operations team: in the event of a fault, a security incident or on your instruction, it can access your instance without asking for your approval each time (privacy policy, section 7a.3). Signing in as a user requires a reason on our side and is logged. You cannot view that log yourself; information is available from datenschutz@zepdesk.de.
What happens in the event of a data breach?
We notify the admin roles without delay, stating the scope and the measures taken, so that you can meet your reporting obligations under Art. 33 GDPR.
What ZepDesk does not take on
Compliance with evidence.
Create an account, sign the AVV, enable two-factor. After that the audit trail is in place from the start.