Security and data processing
You are trusting this application with your income figures. This page says what happens technically, who apart from you gets to see anything — and what is not yet provided here. The last part is the most important.
What can be verified in the code
These statements can be checked in the open source code:
| Item | Implementation |
|---|---|
| Passwords | Stored as a bcrypt hash, never in plain text. |
| Sign-in | JSON Web Token, valid for 30 days. |
| Password change | Invalidates all older tokens immediately — anyone still signed in is signed out. |
| Forgotten password | At most three requests per email address per hour. The token is stored in the database only as a SHA-256 hash. |
| Transport | HTTPS enforced, HSTS for one year including subdomains. |
| Headers | X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin, no identifier of the application or of the storage — only Server: CloudFront, which the delivery service sets itself. |
| Database and backups | Stored encrypted. Backups are made automatically every day, kept for 14 days and are encrypted as well. |
| Reachability | The database has no access to the internet. The application can only be reached through the address of this website, not directly. |
| Cookies | None. Neither on this site nor in the application — the sign-in is kept in your browser's localStorage. |
| Statistics and tracking | None. No analytics service, no tracking pixel, no fonts embedded from third-party servers. |
Because no cookies are set and no data is passed to third parties, there is no consent banner here either. That is not a sacrifice, but the consequence of loading nothing that would need consent.
What is stated openly here instead of being kept quiet
- There is no certification. Neither ISO 27001 nor SOC 2 nor a penetration test. Where other providers cite the certificate of their data centre, let it be said: that certifies the data centre, not the software in it.
Hosting and service providers
| Purpose | Service provider | Location |
|---|---|---|
| Application and database | Amazon Web Services | Frankfurt am Main |
| Backups | Amazon Web Services | Frankfurt am Main, copy in Ireland (EU) |
| Sending email | Amazon Simple Email Service | Frankfurt am Main |
| Email to info@kuenstlerfinanzen.de | Amazon Simple Email Service, forwarded to Google (Gmail) | Ireland (EU); Google also outside the EU |
| Delivery of this website | Amazon CloudFront | Caches in Europe and North America |
| Payment processing | Stripe (Stripe Payments Europe, Limited) | Dublin, Ireland |
Only if you use the one-time fetch from Lexware Office or sevDesk: Künstlerfinanzen uses the API key you paste for it to fetch your paid vouchers from your own account there. The key is used for that one fetch only and is neither stored nor logged; nothing is taken over until you confirm it in the preview.
Data processing agreements under Art. 28 GDPR (DSGVO) are in place with Amazon Web Services and Stripe as part of their terms. Which data goes where is set out in the privacy policy (Datenschutzerklärung, in German).
What this application does not do
- It transmits no data to the Künstlersozialkasse. You file the report yourself.
- It passes your figures to no third party not named above.
- It does not analyse your entries for advertising, because there is no advertising.
- It makes no classification under §2 KSVG and gives no legal advice.
Found something?
If you notice a vulnerability, please report it to info@kuenstlerfinanzen.de. We confirm receipt and get back to you, even if the report turns out not to be confirmed.
Page last checked: 2026-10-03.