ZepDesk accounting software
Home / Security

What stands up to an audit, and who may change what.

Audit-proof bookkeeping, traceable changes, clear roles and a data processing agreement that you sign inside your account. Here is what that means in practice.

Secure early access Data locations and backups

What stands up to a tax audit under GoBD

Building blockWhat ZepDesk does
BookingsNo booking can be deleted, not even by our operations team. Corrections are made with a reversal that swaps debit and credit, carries a reason and points to the original.
Locked periodsAfter the period closing, nobody changes amounts, dates or accounts of bookings, receipts and invoices of that period any more; only a status such as “paid” may still change. If our operations team does intervene, it needs a reason, and the intervention is recorded in the change log.
ReceiptsEvery file is stored with a SHA-256 checksum, so it can later be shown that it is unchanged.
Change logAlways on, on every plan. Each entry names the user, the time, the changed fields and the content before and after; for an action via the AI assistant also who confirmed it. Filter by period, document type and user, export as CSV.
Tax auditThe data carrier under section 147 (6) AO for one year: a ZIP with CSV files and the description in index.xml. The administration creates it under the tax audit export.
Process documentationWith the Compliance plugin, as a template from your company data, in versions, with a completeness check and as a PDF, plugins.
TillWith the Cash Book plugin: security device under section 146a AO through your own fiskaly account and export in DSFinV-K format for a cash inspection.
Real recording from ZepDesk: the booking journal with finalised bookings.

Why nothing can change unnoticed.

Each of these actions writes an entry to the change log, and each entry carries the checksum of its predecessor, one chain per company and document type. If an entry is changed afterwards, the chain no longer matches from that point; the overview checks it in the Compliance tab.

Example: one chain for the document type booking

  1. Entry 1Booking createdChecksum9f1c27a4
  2. Entry 2Booking finalisedEntry altered afterwardsPredecessor9f1c27a4Checksum4d2fb871
  3. Entry 3Reversal booking with a reasonPredecessor4d2fb871Checksumc0e5913b
  4. Entry 4New booking createdPredecessorc0e5913bChecksum07e5c3a1

Checksums shortened, as sample values.

Section 146 (4) AO requires that the original content of a record remains ascertainable. That is why every entry holds the content before and after.

What an entry looks like
Entry in the ZepDesk change log: action, user, document type, time, changed field and the content before and after

Real view from ZepDesk: an entry in the change log with the content before and after.

Who may do what

What someone sees and changes depends on their role in each company: Administration, Accounting, Sales, Tax, Read-only or Employee, roles and collaboration.

Two-factor sign-in

Each person switches it on in their profile, with an authenticator app or a code by e-mail. It applies to the central sign-in and therefore to all of that person's companies.

A key has the rights of this company's administration. Only the administration may create and revoke it; the secret is shown exactly once.

Access and erasure

For your own customers, ZepDesk compiles a person's data or anonymises it on the administration's instruction; invoices and receipts remain unchanged because of the retention obligation. Access requests and deletion rules are handled by the Compliance plugin.

Data processing agreement (AVV) under Art. 28 GDPR

Signable online inside your account, with no separate negotiation, including the list of subprocessors.

User Klaus Berater in ZepDesk: under companies and roles, the Tax role is active for the sample company, alongside Administration, Accounting, Sales, Read-only and Employee API access in ZepDesk: creating a new key with a name, below it an existing key with the revoke button

Real recording from ZepDesk: users with search and the history of sign-ins.Real view from ZepDesk: roles per company, here the Tax role for the tax advisor.Real view from ZepDesk: creating and revoking API keys.

Questions on security and compliance

All questions and answers
Is ZepDesk certified?

The operator's data centers are certified to ISO 27001. For the software itself we do not hold our own ISO certification, and we say so openly; the GoBD requirements (Germany's rules for proper digital bookkeeping) are implemented technically and documented.

Who can see my data?

The users you invite, and our operations team: in the event of a fault, a security incident or on your instruction, it can access your instance without asking for your approval each time (privacy policy, section 7a.3). Signing in as a user requires a reason on our side and is logged. You cannot view that log yourself; information is available from datenschutz@zepdesk.de.

What happens in the event of a data breach?

We notify the admin roles without delay, stating the scope and the measures taken, so that you can meet your reporting obligations under Art. 33 GDPR.

What ZepDesk does not take on

No read access in the log. The change log records what was changed, not who looked at something.
No mandatory two-factor sign-in. The administration cannot require it for its users; each person switches it on themselves.
No finished process documentation. ZepDesk fills the template from your company data; how your business captures and checks receipts is yours to describe.

Compliance with evidence.

Create an account, sign the AVV, enable two-factor. After that the audit trail is in place from the start.