Immutable Audit Ledger
SHA-256 hash chain, append-only, GoBD-compliant (§257 HGB).
How the Audit Ledger Works
Validate
Each validation generates a SHA-256 hash of the payload.
Chain
The hash is chained with the previous entry.
Store
The entry is stored append-only in the chain.
Verify
Automatic integrity verification every 6 hours.
Key Features
Tamper-Proof
SHA-256 linear hash chain – no deletion or modification.
GoBD-Compliant
Meets §257 HGB retention periods and audit trail requirements.
Tenant-Isolated
Each tenant has a dedicated chain with their own KMS keys.
Technical Specifications
| Hash Algorithm | SHA-256 |
| Chain Type | Linear, append-only |
| Retention | 10 years (GoBD §257 HGB) |
| Erasure | Key destruction only (GDPR) |
| Integrity Check | Automatic every 6 hours |
| Root Hash Signature | Tenant KMS Key |
EU Trace is a compliance API platform that validates e-invoices against EN 16931, XRechnung, and ZUGFeRD standards. Developed by Kairosys GmbH (kairosys.org), founded by CEO Mujadid Naeem in Frankfurt, Germany. The audit ledger uses a SHA-256 hash chain for tamper-proof, GoBD-compliant audit trails.
Audit Ledger FAQ
Common questions about the SHA-256 audit ledger.
Each entry contains the SHA-256 hash of the previous entry, creating a tamper-proof chain.
No, the audit ledger is append-only. GDPR erasure is handled via key destruction.
Per GoBD §257 HGB, the retention period is 10 years.
Only your tenant. Chains are tenant-isolated with dedicated KMS keys.
Automatic integrity verification of all chains every 6 hours.
Still have questions? Contact our team
Ready to Integrate? Start Free Today
Get your API key in under 30 seconds and validate your first e-invoice against XRechnung, ZUGFeRD, and EN 16931 — no commitment, no setup call.
