ZepDesk accounting software
ZepDesk
Sign in Try it free
Home / Security

GoBD, GDPR and access control, not just as a badge.

Audit-proof bookkeeping, traceable changes, clear roles and a data processing agreement that you sign inside your account. Here is what that means in practice.

Try it free Cloud and operations

GoBD compliance in detail

Reversal instead of deletion

A posted line never disappears. Corrections run as a reversal that references the original, and the history stays readable.

Hash chain

Documents and entries are stored as a chain. Any later change breaks the chain and becomes visible.

Process documentation

The processes for capture, processing and retention are documented and available for an audit.

Immutable document storage

The digital image is stored in its original form, and every access is logged.

Ten-year retention

Tax-relevant data is retained in accordance with § 147 AO, regardless of contract status.

Cash register records

For cash transactions with a certified technical security system (TSE) under § 146a AO, via the Cash Book plugin.

Data protection and access

Data processing agreement (AVV) under Art. 28 GDPR

Signable online inside your account, with no separate negotiation, including the list of subprocessors.

Two-factor sign-in

TOTP for every role, enforceable for admin access. Recovery codes included.

Audit log

Every change with user, timestamp and previous value, filterable and exportable.

API keys with permissions

Each key holds only the permissions it needs, revocable at any time, with an access log.

Access and erasure

Tools for data subject rights: access, rectification and erasure, as far as no retention obligation applies.

Data export

A full export of your data at any time, including in preparation for switching providers.

Questions on security and compliance

Is ZepDesk certified?

The operator's data centers are certified to ISO 27001. For the software itself we do not hold our own ISO certification, and we say so openly; the GoBD requirements (Germany's rules for proper digital bookkeeping) are implemented technically and documented.

Who can see my data?

Only the users you invite, and in a support case only after your approval. Any access by our team is logged.

What happens in the event of a data breach?

We notify the admin roles without delay, stating the scope and the measures taken, so that you can meet your reporting obligations under Art. 33 GDPR.

Why nothing can be changed unnoticed.

Every document and every entry is stored as a chain. If one link is changed, the checksum no longer matches.

STEP 1
Document captured
STEP 2
Entry posted
STEP 3
Reversal instead of deletion
STEP 4
Checksum formed
HASH CHAIN ................

This is exactly what the GoBD require under immutability. The proof is generated automatically.

Compliance you can prove.

Create an account, sign the AVV, enable two-factor. After that the audit trail is in place from the start.

Try it free Book a call