Laden...
Laden...
cashwerk relies on German server locations, GDPR-native architecture, and granular access control – keeping your business data safe.
Security at cashwerk is not an afterthought. It is the foundation of the entire platform. From authentication to data storage to API communication – every layer is designed to protect your business data.
Meets the strictest requirements of the German market.
Full compliance with the General Data Protection Regulation. Organization isolation and profile privacy settings; data subject rights are handled on request in line with the GDPR.
Tamper-proof invoicing with XRechnung and ZUGFeRD. Automatic number sequences, audit trail, and PDF/A archiving ensure full GoBD compliance.
All data is processed on ISO 27001 certified servers in Frankfurt am Main. No data sharing with third countries.
Every change to contacts, invoices, projects, and tasks is logged – who changed what, when, and why.
Multiple security layers protect your accounts.
Secure token-based authentication with automatic renewal via refresh tokens.
Sign in via Google, Microsoft, or Apple – without managing separate passwords.
One-time passwords via email for additional security during critical actions and initial verification.
Device overview with Geo-IP detection. View all active sessions and revoke individual ones remotely. Automatic invalidation on inactivity.
Control exactly who can see and edit what.
cashwerk features a fine-grained role-based access control system (RBAC) that manages access down to the individual entity level. With the three-tier permission model – Own, Assigned, and Any – you precisely determine which records an employee can view, create, edit, or delete.
Permissions can be individually assigned per module – from CRM to invoices and projects to the AI assistant. Create custom roles with individual permission profiles and flexibly assign them to your team members.
Enterprise-grade technology for your data protection.
All data transfers are TLS encrypted. Database connections use encrypted PostgreSQL connections.
Cloud-native architecture on Google Cloud Platform, EU region Frankfurt am Main (europe-west3). All data stays in the EU.
Sensitive configurations and API keys are managed via a dedicated secret-management system – no plaintext in code or environment variables.
Automatic error and anomaly detection in real time. Notifications for performance bottlenecks or security incidents.
Transparency and control over your data.
Hosted in the EU – developed in Europe
Fully data protection compliant
Servers only in Germany
Sustainable & responsible
Try cashwerk for free and experience enterprise-grade data protection from day one.