EU-sovereign by construction.
Provenance you can check.
No audit-badge theatre. Trust here is two things you can verify: where your data lives, and exactly which authority artefacts every validation runs against. Each one is pinned by version, dated, and re-checked on a calendar.
100% EU, zero US subprocessors
100% EU. Primary hosting is Hetzner, spread across several EU data centers, and every subprocessor is EU-based. No Google Analytics, no session recording, no US subprocessors. That last point is a checkable claim, listed below, not a marketing line.
Authority-pinned provenance
Every Schematron and schema is pinned by version and re-verified on a calendar against the authority's own published artefact. The pinned set is public, with the date each is next due for a check.
Processed in memory
Today Beliq builds and validates the file and you send it through your own provider; managed delivery is coming in Q4 2026. Invoice content is processed in memory, never retained, and never used to train models.
Where your data is, and what we do with it.
All primary infrastructure runs in the EU. No US region, no US failover.
Every API call and dashboard session is encrypted in transit.
Processed in memory by the validation engine and not persistently stored; any temporary file a request creates is deleted as soon as it completes.
Account and job metadata stay in the EU; database backups use encrypted object storage.
Invoice content is not stored and is never used to train models.
Privacy-focused Umami, self-hosted in the EU. No Google Analytics, no session recording, no advertising or cross-site tracking, and no cookies.
Client-side errors on our site are reported to our own self-hosted GlitchTip in the EU so we can find and fix bugs. Stack traces and browser context only, no cookies and no session recording, and invoice content is stripped before anything is sent.
Live chat runs on our own Chatwoot server in the EU (Hetzner). Its AI assistant uses Mistral (Paris, France), which generates the reply on EU/EEA infrastructure per its published subprocessor list and never trains on support messages. Mistral's own security and traffic-routing layers do operate globally, so this is the one place we cannot promise EU-only, and it is why invoice content is never part of a chat.
Every subprocessor is established in the EU.
| Subprocessor | Purpose | Location | US transfer |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure (servers, Kubernetes, database, backups, error tracking) | Germany (EU) | None |
| Scaleway SAS | Transactional email, static-site object storage, off-site backup (account data only; no invoice content) | France (EU) | None |
| BunnyWay d.o.o. | CDN in front of the websites and the dashboard (traffic is carried through, never cached or stored at the edge; EU locations only) | Slovenia (EU) | None |
| OVH SAS | Self-managed monitoring host (logs and metrics; operational metadata only) | France (EU) | None |
| Mistral AI SAS | AI assistant in our self-hosted support chat (generates replies from support messages; no invoice content) | France (EU) | None for the reply itself; the provider's own security and routing layers are global, under the standard contractual clauses |
| Armitage Labs OÜ (Creem) | Subscription checkout, billing, payments (account data only) | Estonia (EU) | None |
| Brevo (Sendinblue SAS) | Newsletter delivery and subscriber list management (email address and opt-in metadata only; no invoice content). Consent-based, double opt-in. | France (EU) | None |
| Lightkeeper OÜ (Phare) | Public status page at status.beliq.eu (your browser reaches the provider only when you open that page; no cookies, no invoice content). The monitoring calls two health endpoints and never sees processed data. | Estonia (EU) | Only if you open the status page; the provider's delivery, DNS and security layer is global and its routing filter is not ours to set, under the standard contractual clauses |
Signing in with Google, GitHub, or Microsoft is initiated by you and handled by those providers as identity providers you choose, not as data subprocessors. Full subprocessor change-notice terms are in the Data Processing Agreement. Section 14 of the Privacy Policy sets out where each processing takes place, including the three exceptions: the AI support chat, the newsletter, and the status page.
Pinned, dated, checkable.
The artefacts Beliq pins per format. Sourced from each authority's own repository or distribution, versioned, and re-checked on a calendar. Every validation response names the artefacts that actually ran for that document.
| Format | Authority | Artefact | Version | Released | Source | Re-verification |
|---|---|---|---|---|---|---|
| XRechnung | KoSIT | XRechnung Schematron | 2.6.0 | 2026-08-31 | itplr-kosit/xrechnung-schematron @ v2.6.0 | Next check 2026-10-31 |
| Factur-X | FNFE-MPE - DGFiP | Factur-X Schematron | 1.09.2 | 2026-09-04 | FNFE-MPE / FeRD Factur-X 1.09.2 package | Next check 2026-12-15 |
| ZUGFeRD | FeRD | EN 16931 CII Schematron | 1.3.16 | 2026-04-04 | ConnectingEurope/eInvoicing-EN16931 @ validation-1.3.16 | Next check 2026-12-17 |
| Peppol BIS Billing 3.0 | OpenPeppol | Peppol BIS Billing Schematron | 3.0.21 | 2026-05-20 | OpenPeppol BIS Billing 3.0 release notes | Verified |
| NLCIUS | NPa - NEN | NLCIUS Schematron | 2.0.3.13 | 2026-05-21 | peppolautoriteit-nl/validation | Verified |
| FatturaPA | Agenzia delle Entrate (SdI) | FatturaPA XSD | 1.4-runtime-2026-05-01 | Agenzia delle Entrate (SdI) | Next check 2026-12-17 | |
| Facturae | MINECO / MINHAP (Facturae) | Facturae XSD | 3.2.2-research-2026-05-24 | MINECO / MINHAP (Facturae) | Next check 2026-11-24 | |
| e-SLOG | GZS (Slovenian Chamber of Commerce) | e-SLOG XSD | 2.0-08-2020 | GZS (Slovenian Chamber of Commerce) | Next check 2026-12-17 |
"Verified" means the profile passes the authority's own golden fixtures with no open upstream gap. Every artefact above is published with the SHA-256 of its exact bytes at the public /v1/rulesets catalog, so the ruleset hash on a /v1/validate response can be reconstructed and matched against what we pin for everyone. Full coverage and provenance live in the standards reference.
Why no SOC 2 badge
We are not SOC 2 audited and won't imply otherwise. SOC 2 is a US-centric attestation and the wrong signal for EU buyers. Trust here is EU sovereignty and published provenance, not a badge we don't hold. If an enterprise contract ever requires a formal certification, the EU-native path is ISO 27001.
Security contact
Found a vulnerability? Email hello@beliq.eu with steps to reproduce. Please give us reasonable time to remediate before public disclosure.