Terms of service

For the hosted API at api.attestwire.com. Short, in plain English, and without the clauses that exist only to be unreadable. The open-source library is not covered here — it is MIT-licensed, and the MIT licence is the whole agreement for it.

1. Who this is between

These terms are between you (the person or company using the API) and Ben Harborne, a sole proprietor in Woodside, California, USA, trading as Attestwire ("we", "us"). A company will be formed before the first enterprise contract; if the business is transferred to that company, these terms transfer with it and we will tell you.

You accept these terms by creating an API key or by calling the API. If you are agreeing on behalf of a company, you are confirming you may do so.

2. What the service is

An HTTP API that validates and generates electronic invoices against EN 16931 and its national restrictions. What each endpoint does, what it accepts and what it returns is described in the API documentation and on the rule reference, and those documents form part of these terms. Where they conflict with this page, this page wins.

The service does not transmit invoices. We are not a Peppol access point, a French PDP or a KSeF connector, we do not deliver documents to any authority or counterparty, and nothing here should be read as us doing so.

We do not promise an uptime percentage. There is no SLA on any plan today; if you need one, ask and we will talk about what is honest.

3. Not a compliance guarantee

This is the most important clause on the page, so it is not buried.

The service performs a technical conformance check. It tells you whether a document satisfies the rules we have implemented, as we have implemented them. It does not and cannot tell you that a tax authority, a portal, an access point or your customer will accept the document.

A result of valid: true means our implemented checks found no fatal error. It does not mean the invoice is correct, that its VAT treatment is right, that the figures are right, or that you have met your obligations in any country. Rules change, portals apply their own additional checks, and our coverage is partial and stated as partial — every rule page says where our check is stricter or narrower than the published rule.

Nothing we produce is tax, accounting or legal advice. We are not your adviser. You remain responsible for your invoices and for your compliance, and you should check your obligations with someone qualified in your jurisdiction.

To the extent the law allows, the service is provided "as is", without warranties of merchantability, fitness for a particular purpose, or acceptance by any authority or counterparty.

4. Accounts and API keys

A key is issued to one email address and returned to you once. We keep only its SHA-256 hash, so we cannot recover it for you — if you lose it, create another. Keep your keys secret; calls made with your key are treated as yours, and you are responsible for usage under it until you tell us it is compromised. Tell us at hello@attestwire.com and we will revoke it.

Do not share one key across unrelated customers or resell access as if it were your own API without telling us. Ask instead; the answer is usually yes on sensible terms.

5. Acceptable use

Do not:

If something breaks the service or is clearly abusive we may suspend a key immediately and tell you why. For anything less clear-cut, you get a message first.

6. Fees and billing

Prices are in US dollars and billed monthly in advance through Stripe. The current plans and their allowances are on the homepage; if a price changes, section 8 applies.

Quota is documents per calendar month, counted per key, resetting at 00:00 UTC on the 1st. A validate call and a generate call are one document each. A call we refuse — a bad key, a rate limit, a malformed request — does not consume a document. Quota does not roll over and unused documents are not refunded. When you reach the limit, further calls are refused until the reset or an upgrade; we do not silently bill overage.

Prices exclude tax. You are responsible for any VAT, GST or sales tax due in your jurisdiction, and for any reverse-charge accounting where it applies to you.

7. Cancellation and refunds

Cancel any time through the Stripe billing portal. No email, no retention call, no "are you sure" sequence. Cancellation takes effect at the end of the period you have already paid for, and your key keeps working until then; after that it falls back to the free tier rather than being deleted.

If the API materially failed you, ask and we refund the month. An outage, a validation result that was wrong in a way that cost you, a month you paid for and could not use — email hello@attestwire.com and say what happened. We would rather refund a month than argue about one.

8. Changes to the API and to prices

Breaking API changes: 30 days' notice by email to the address on the account, before the change takes effect. Additive changes — a new endpoint, a new optional field, a new rule that returns an additional error — are not breaking and ship without notice. Validation coverage improving is the product working, not a breaking change, though we will note significant coverage changes in the documentation.

Price increases: 30 days' notice by email. They never apply to a period you have already paid for, and you can cancel before the new price starts.

We may change these terms; material changes get the same 30 days' notice and the date at the bottom of this page changes.

9. Liability

Our total liability to you, for everything, is capped at the fees you paid us in the 12 months before the claim. On the free tier that is zero, which is the honest consequence of a free tier.

Neither of us is liable to the other for indirect or consequential loss — lost profits, lost revenue, lost or corrupted data, business interruption, or a fine or penalty imposed by an authority — even if we were told it was possible.

Nothing here limits liability that cannot lawfully be limited, including for fraud or for death or personal injury caused by negligence. This cap is a deliberate allocation of risk and it is why the price is what it is: read section 3 and decide accordingly.

10. Your data

Invoice payloads are processed in memory and never stored. What we do hold, and what our subprocessors touch, is set out on the security page; personal data on this site is covered by the privacy notice.

If you need a GDPR Article 28 processor agreement, one is written and ready: the data processing addendum. Email us with your company details and it is in place.

You keep all rights in everything you send. We claim no licence over your invoice data beyond processing the request you made.

11. Governing law

These terms are governed by the laws of the State of California, USA, without regard to its conflict-of-laws rules. The courts of San Mateo County, California have exclusive jurisdiction, and both of us submit to them.

We know that is a real cost for a European buyer, and we are not going to pretend otherwise: it reflects where the operator is, not a preference for making disputes expensive. Enterprise agreements are negotiable, including this clause.

12. If we stop

If the hosted API is discontinued, every account gets at least 60 days' notice by email before it stops answering, and no further charges after the notice goes out.

The library @attestwire/en16931 is MIT-licensed. That licence is irrevocable for versions already released: the code keeps working, offline, with no account and no calls home, and you or anyone else may fork and maintain it. That is the continuity plan, and it does not depend on our goodwill. More on this on the about page.

Odds and ends

If a clause is unenforceable, the rest still stands. Not enforcing something once does not waive it. You may not assign these terms without us; we may assign them to the company formed to operate Attestwire, or to a buyer of the business, and we will tell you if that happens. These terms plus the documents they reference are the whole agreement about the hosted API.

Questions about any of this go to hello@attestwire.com and reach a person, not a legal department.

Last updated . If this page changes materially we will say so here rather than silently swapping it.