Trust
Built compliant, provably.
We build compliance software — so we're compliant from the ground up, and we can show it. Not as a marketing promise, but with proof: signatures, reviews, evidence. The auditor gets proofs, not promises.
Security isn't an add-on — it's the architecture
A QMS is only worth the trust in its evidence. That's why everything that makes easo secure and provable is built into the foundation — not bolted on afterwards.
-
Secure by design (CRA)
easo is secure-by-design in the sense of the EU Cyber Resilience Act: shipped SBOMs (software bills of materials), a vulnerability policy with a security.txt, and a 5-year support commitment.
-
Independently reviewed
The cryptographically critical import path was independently reviewed — source review, dynamic tests and fuzzing with over 55,000 inputs, with no exploitable findings. That review's regression suite gates our CI.
-
Signed & independently verifiable
Every release is signed to the AdES level and verifiable even without easo — the verification steps are printed on every exported PDF.
-
Revision-safe (GoBD)
Immutable, fully traceable releases meet the technical requirements of revision-safe records.
-
Accessible (WCAG 2.2 AA)
App and website are built to WCAG 2.2 AA: keyboard-operable, sufficient contrast, no meaning conveyed by colour alone.
-
Archival exports
Exports as PDF/A-2b with a verification annex — long-term archivable and self-explanatory in an audit.
-
Data sovereignty & privacy
Your documents live in your own git, never on our infrastructure. The website runs on Swiss hosting, with no trackers and no external fonts or CDNs.
Honestly framed
easo is young software. The security reviews are point-in-time records, not certificates, and we claim no level we don't technically meet. The CRA reporting duties apply from 2026-09-11. Whatever we promise, we can prove — and where something is still outstanding, we say so.
Report a security vulnerability
Security research against your own easo installation is explicitly welcome. Report findings to security@manovis.com — we acknowledge receipt within 2 business days and return an initial assessment within 5 business days. We ask for coordinated disclosure and credit reporters who wish to be named. Contact details are also in our security.txt.
Frequently asked questions about security & compliance
Is easo GoBD-compliant?
easo provides the technical revision-safety the GoBD require — immutable, fully traceable releases. The GoBD bind the company, not the software, and there is no official GoBD certification; the organisational responsibility stays with you.
Has easo been independently security-reviewed?
Yes. The cryptographically critical import path was independently reviewed — source review, dynamic tests and fuzzing with over 55,000 inputs, with no exploitable findings. That review's regression suite gates our CI. Reviews are point-in-time records, not certificates.
Does easo meet the EU Cyber Resilience Act (CRA)?
easo is secure-by-design in the sense of the CRA: shipped SBOMs, a vulnerability policy with a security.txt, and a 5-year support commitment. The CRA reporting duties apply from 2026-09-11.
How do I report a security vulnerability?
Email security@manovis.com (also listed in our security.txt). We acknowledge receipt within 2 business days and return an initial assessment within 5 business days. We ask for coordinated disclosure and credit reporters who wish to be named.
Where does my data live?
Your documents live in your own git, never on our infrastructure. The website itself runs on Swiss hosting (Infomaniak), with no trackers and no external fonts or CDNs.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.