Laden...
Laden...
cashwerk relies on EU server locations, a GDPR-native architecture and granular access control – so your business data stays safe.
At cashwerk, security is not an add-on but the foundation of the platform. From sign-in through storage to the API – every layer is built to protect your business data.
Meets the requirements of the DACH region.
Processing under the General Data Protection Regulation. Organizations are isolated from each other, privacy settings exist per profile; data subject requests are handled on demand.
Audit-proof invoices with XRechnung and ZUGFeRD. Sequential numbering, audit trail and PDF/A archiving.
Storage and processing exclusively in the EU, governed by a data processing agreement.
Every change to contacts, invoices, projects, tasks, deals and time entries is logged: who changed what, and when.
Several layers protect your account.
Signed tokens with automatic renewal via refresh tokens. When a session expires, it is over – no password in circulation.
Single sign-on through the account you already have – without managing another password.
During onboarding and password reset you confirm yourself with a code that only you receive.
Overview of all active sessions with geo-IP. Every session can be ended individually.
You decide who can see and edit what.
cashwerk has a role and permission system that controls access down to the individual record. With the three levels Own, Assigned and All you define which records a team member may view, create, edit or delete.
You grant permissions per module – from CRM through invoices and projects to the AI assistant. Presets set the rights in one step, custom roles are available from the Starter plan. Before saving, cashwerk shows what will change.
You manage roles, presets and invitations on the team page. Go to team management
Whether REST, MCP or n8n: no call reaches your data without passing these steps.
The call identifies itself with an OAuth token or an API key of your organization. Without valid proof it ends here.
The key may only do what its scopes allow. A read-only key writes nothing.
The requests per minute of your plan are counted per organization. Above that, the API answers with a clear error message.
Every query is bound to your organization. Foreign records are unreachable, even through guessed IDs.
Only then does cashwerk execute the command or query – under the same rules as the interface – and write to the database.
The foundation of your data protection.
All transfers run over TLS. Database connections are encrypted.
Cloud-native architecture on Google Cloud, region europe-west4 (Netherlands). All data stays in the EU.
Credentials and keys live in dedicated secret management – never in plain text in code or environment variables.
Availability of 99.5 %. Errors and anomalies are captured in real time; in case of incidents the team is notified immediately.
Transparency and control over your data.
Hosted in the EU, developed in Europe
Fully data protection compliant
Servers only in the EU
Records, audit logs and exports
Try cashwerk for free – with tenant isolation, audit trail and permissions from day one.