Where it runs
Two independent, ISO 27001–aligned data centers with redundant power, fire protection, and multiple fiber/ISP connections for internet redundancy. Nothing about the Swedish service depends on a single facility.

Locked down by default
- X.509 security, handled by fiskaly
TLS encryption on every request. The X.509-certificate security toward the Swedish control system is handled entirely by fiskaly in the background — no request reaches the system unauthenticated.
- Application-layer firewalls
On top of standard network protection, filtering at the data level, not just the perimeter.
- Every request logged
Logged for audit purposes, with all traffic monitored by a third-party security provider around the clock.
- Yearly external audits
Covering both operational and security practices — the same audit that keeps our SKVFS 2020:9 certification current.
Certified, and re-certified
We run two independent, certified SaaS clusters: one for SKVFS 2020:9 (the current standard, and we were the first provider certified against it, in November 2024) and a separate one still serving the older 2009:2 standard. (What these standards actually require of your POS is covered on the VAT reporting page → — this is about how we're built to meet them.)

Operations and support
Our status page updates automatically from synthetic monitoring and is integrated with PagerDuty — you can subscribe to it directly rather than waiting to hear from us. Support is staffed 24/7 for operational issues, with a team that's as comfortable answering an SKV compliance question as a technical one.

Proven at scale
53M+
Swedish transactions p.a.
99,999%
Uptime
35 000
Registers connected every day
Frequently asked questions
Yearly, by an external auditor, covering both operational and security practices — not a one-time certification we got and stopped thinking about.
The two data centers run active/active, not active/passive — failover is part of normal operation, not a disaster-recovery plan we hope never to use.
