Security and compliance, in every market you operate in
Data residency you choose, statutory tax and payroll maintained per jurisdiction, and the governance controls on every plan rather than an enterprise tier. Status below is stated exactly, not aspirationally.
Coverage at a glance
- 150+
- Countries
- 135
- Currencies
- 80+
- Tax jurisdictions
- 60+
- Payroll countries
- 30
- Languages
- 7
- Data regions
Tax and statutory filing
One tax engine covering indirect tax, withholding and statutory returns, with rates maintained centrally so a rule change is not your problem to notice.
VAT, GST, sales tax and consumption tax in 80+ jurisdictions
Statutory e-invoicing: Peppol, EN 16931, CFDI, NF-e, IRN and more
Withholding tax and reverse charge applied at transaction level
Filing calendars per entity, with the Compliance Agent preparing returns
Payroll and employment
Statutory payroll across 60+ countries, with the contribution, threshold and filing rules maintained for each one.
Social insurance, pension and income tax withholding per country
Statutory leave, working time and overtime rules
Multi-country payroll runs in one cycle, in local currency
Year-end reporting: P60, W-2, Form 16, payment summaries and equivalents
Data protection and residency
Choose the region your tenant data lives in, and keep it there. Cross-border transfers are documented, not incidental.
Seven data regions across three continents
GDPR, UK GDPR, LGPD, PIPEDA, PDPA and DPDP handling
Data subject access, rectification and erasure in-product
Sub-processor register published, with change notification
Security controls
The governance a large enterprise expects, on every plan rather than reserved for an enterprise tier.
SSO (SAML and OIDC), SCIM provisioning and MFA on all plans
Role-based access down to the field level, with segregation of duties
Immutable audit logs and full change history on every record
Encryption in transit and at rest, with customer-managed keys available
Certifications and frameworks
We publish exact status rather than implying audits we have not completed. “Certified” means an audit is finished and a report is available under NDA. “Aligned” means we operate to the framework without claiming an audit against it.
SOC 2 Type II
Audit in progressObservation window underway; report expected before general availability.
ISO/IEC 27001
Audit in progressStage 1 assessment complete, Stage 2 scheduled.
GDPR
AlignedDPA, standard contractual clauses and records of processing available on request.
ISO/IEC 27701
AlignedPrivacy information management practices follow the standard.
PCI DSS
AlignedCard data is never stored; payments are tokenised through certified processors.
HIPAA
AlignedBAA available for Healthcare Pack customers in the United States.
Regions and data residency
You choose the region your tenant data is stored in, and it stays there. Cross-border transfers are documented rather than incidental, and our sub-processor register is published with change notification.
Europe, Middle East & Africa
58 countries · data in Frankfurt and Dublin
GDPR-aligned processing, EU e-invoicing mandates, and payroll across 40+ jurisdictions.
- GDPR data subject requests handled in-product
- EN 16931 e-invoicing and Peppol network delivery
- VAT registration, OSS/IOSS and reverse charge
- SEPA direct debit and instant payments
Americas
32 countries · data in Virginia and São Paulo
US sales tax nexus, Canadian GST/HST, Brazilian NF-e and LATAM electronic invoicing.
- US sales tax with economic nexus tracking
- Canadian GST, HST, PST and QST
- Brazil NF-e, NFS-e and SPED reporting
- Mexico CFDI 4.0 stamping
Asia Pacific
44 countries · data in Mumbai, Singapore and Sydney
India GST, Australian STP and BAS, Singapore InvoiceNow, Japanese consumption tax.
- India GST, e-invoicing and e-way bills
- Australia Single Touch Payroll and BAS
- Singapore InvoiceNow (Peppol) and GST F5
- Japan qualified invoice system
Transparency and incident response
Security documentation, penetration test summaries and our incident response procedure are available to customers and prospects under NDA. We commit to notifying affected customers of a confirmed personal data breach without undue delay, within the window our data processing agreement specifies.
Questions from your security team are welcome before you buy, not only at renewal. Send us a questionnaire and we will complete it.