SECURITY & COMPLIANCE

Built for audits. Operated with professional paranoia.

DGII-certified compliance, data sovereignty by design, and the operational rigor your finance team demands.

DGII e-CF Compliance

Mosce ERP is certified by the Dirección General de Impuestos Internos as an authorized electronic issuer. Our implementation complies with Formato e-CF v1.0 and the Informe Técnico e-CF to the letter.

Your path to electronic invoicing

  1. RNC registered in TESTECF

    Your company is registered in the DGII's testing environment.

  2. Digital certificate acquired

    You obtain your electronic signature certificate to issue valid e-CF documents.

  3. Certification environment testing

    Mosce ERP validates each voucher type against DGII servers before going live.

  4. Production go-live

    Your company starts issuing electronic fiscal vouchers with full legal validity.

Data Sovereignty · BYOS

Your data is yours. From the first byte to the last backup, you decide where it lives and who has access.

Your bucket, your keys

Your backups always go to your own storage account (S3, R2, or compatible); they never permanently reside in our infrastructure. You decide the jurisdiction.

Per-tenant encryption

Each tenant has its own encryption key for sensitive fiscal data. Cryptographic isolation from minute one.

No lateral access

Strict database-level isolation. Your data never coexists with another customer's.

Access & Authorization

Modular role control

Per-module permissions (sales, purchases, fiscal, settings, accounting) assignable granularly. Your administrator defines who sees and modifies what.

Enterprise sign-on

Enterprise SSO, mandatory MFA for administrative roles, SAML support for your corporate IdP.

Complete audit trail

Every sensitive action is logged with who, what, when, and from where. Retention varies by plan; see the pricing page for exact days.

stripe
PCI-DSS Level 1

Payments without touching cards

Stripe processes all subscription payments. We never see or store card numbers. PCI-DSS Level 1 compliance guaranteed by Stripe.

Privacy Posture

Data processing agreement available upon signing Enterprise plans. Explicit commitments on retention, deletion, subprocessor access, and data residency. GDPR-compliant for customers with EU operations.

Active subprocessors

  • Auth0

    Authentication and identity management.

  • Stripe

    Subscription payment processing.

  • Cloudflare

    CDN, DDoS protection, and WAF.

  • Brevo

    Transactional email notifications.

Incident Response

Any confirmed security incident is communicated to affected accounts within 72 hours. Our internal process covers triage, containment, public post-mortem (when applicable), and direct customer communication. Report vulnerabilities responsibly to security@mosce.io - we thank the security community and publicly acknowledge researchers who contribute.

Does your audit team have questions?

We'll connect you with the security team for a technical session.