Looking for Fakturownia alternatives? Ask 7 security questions

Choosing a secure invoicing software requires rigorous provider verification. Following the security incident in September 2026, businesses must ask critical questions regarding server location, two-factor authentication, and KSeF secret protection. Learn how to evaluate alternative solutions effectively.

11 min read 17 views
Looking for Fakturownia alternatives? Ask 7 security questions

Last updated: 5 October 2026

If you are looking for a Fakturownia alternative after the Fakturownia data leak, don't start with the price list. Start with seven questions: where your data lives, whether two-factor login is available, how KSeF certificates and tokens are encrypted, whether you can see your login history, what the data processing agreement says, how the software connects to KSeF and how long it keeps your data.

The answers will tell you more than the word "secure" on a homepage. The checklist is useful whether you switch software or stay with your current provider.

What we know about the Fakturownia leak (as of 5 October 2026)

According to Fakturownia's notices, an unauthorised person had access to its systems from 27 September 2026 (around 3:20 am) to 28 September (around 5:45 pm) and copied a large part of the database. In an update published on 1 October, the company listed the categories of data taken, including account and user data, password hashes, session identifiers and API tokens, as well as data of business partners added before 16 October 2024. For about 2,250 accounts the scope was wider and covered data from 2022–2026.

Fakturownia also stated that passwords were not stored in plain text, and that KSeF certificates, payment card data and bank login data were not taken. In its notice of 29 September 2026, the Polish Ministry of Finance said the incident did not affect data held in the National e-Invoice System (KSeF). Sources are listed at the end of the article.

This incident does not mean that one product is "bad" and another is "good". No system is 100% immune to attacks. What it does show is that you should know what to ask a provider before you trust it with your clients' data.

Why you should be the one asking: controller and processor

The business-partner data you enter into invoicing software is often personal data (for example, sole traders among your clients). You are the controller of that data, and the software provider is the processor. Article 28(1) GDPR says a controller may only use processors that provide sufficient guarantees of security.

In practice this means two things. First, choosing the software is your decision and your responsibility. Second, if a breach happens, you assess whether to notify the Polish supervisory authority (UODO), as a rule within 72 hours of becoming aware of it (Article 33 GDPR). For your specific case, it is worth consulting a lawyer or a data protection officer.

7 questions to ask: how to judge a Fakturownia alternative on facts

1. Where is my data physically stored, and who else has access to it?

Ask where the servers are (Poland, another EU/EEA country or outside it) and request the list of sub-processors: hosting companies, email, payment and AI providers. If data leaves the EEA, the transfer needs a legal basis under Chapter V GDPR (Articles 44–46), such as an adequacy decision or standard contractual clauses.

Good answer: a concrete list of sub-processors with name, role and country. Warning sign: "your data is safe in the cloud" with no details.

2. Can I turn on two-factor authentication (2FA)?

Even when passwords are stored as hashes, after a leak an attacker can try to crack weak passwords offline. Two-factor login means the password alone is not enough to get into your account.

Ask for details: does 2FA work through an authenticator app (TOTP), a hardware key or a passkey, or only via SMS? Also check whether the account owner can enforce 2FA for every user, for example for your accountant. One caveat: 2FA protects the login step, not an already active session. That is why question 4 matters.

3. How do you store KSeF certificates, tokens and API keys?

From a developer's point of view, secrets in invoicing software fall into two groups, and each needs different handling.

  • Secrets the system has to use, such as the KSeF certificate or token the software uses to log in on your behalf. These cannot be hashed, so they should be encrypted, with the encryption key kept outside the database (for example in a separate secrets manager). Then a copy of the database alone is not enough to use them.

  • Secrets the system only checks, such as your password or an API key for integrations. Here storing a hash is enough, just like with passwords. Good practice: you see an API key only once when it is created, and it has a defined scope and an expiry date.

Also ask which algorithm is used to hash passwords. An answer like "bcrypt" or "Argon2" is concrete; "we encrypt passwords" is a signal to ask more.

Timing context: under the original plan, KSeF tokens were to work until 31 December 2026, after which only KSeF certificates would remain. In June 2026 the Ministry of Finance proposed keeping tokens after that date (reply to a parliamentary question dated 21 July 2026). Check the Ministry's latest notice before you plan any change.

4. Can I see my login history and active sessions, and can I end them?

If session identifiers leaked, someone could try to get into an account without the password while the session is still valid. So ask:

  • whether account settings show login history (date, IP address, device),

  • whether you get a notification about a login from a new device,

  • whether there is a "log out of all devices" button,

  • how long a session lasts and whether changing the password invalidates other sessions.

Ask about an audit log of data changes too. After a leak, the most common scenario is fake invoices and requests to pay into a "new" bank account. If the software shows who changed the bank account number on an invoice and when, you will spot misuse faster.

5. What exactly does the data processing agreement contain?

The data processing agreement (Article 28(3) GDPR) can be a separate document or part of the terms of service. Both are acceptable. What matters is the content:

  • subject matter, duration, nature and purpose of processing, type of data and categories of data subjects,

  • a commitment to apply the security measures required by Article 32 GDPR,

  • rules on sub-processors and on informing you about changes,

  • deletion or return of data when the contract ends,

  • the right to audits and access to information.

Pay particular attention to how quickly they must notify you of a breach. GDPR says "without undue delay" (Article 33(2)). Since you have 72 hours to notify UODO, it helps when the agreement states a specific number of hours, such as 24 or 48.

6. How does the software connect to KSeF, and how can I revoke its access?

There are two basic models:

  • You hand your certificate or token to the software. The software stores your key and uses it to log in to KSeF.

  • You grant the provider a permission in KSeF. The software works on the basis of a permission you can see in KSeF and can revoke yourself at any time, without contacting the provider.

In both cases, ask about the scope of permissions. If the software only issues invoices, it does not need the right to manage other permissions. The principle of least privilege limits the impact of any incident.

7. How long do you keep my data, and how do I get it back?

The leak included, among other things, the contents of exports and imports requested in the past. It is a good example that data kept "just in case" can leak too. So ask:

  • whether export files are deleted automatically after download or after a set time,

  • how often backups are made, where they are stored and whether they are encrypted,

  • whether you can export all your data at any time (invoices as FA(3) XML, business partners, payments),

  • what happens to your data after you cancel and how soon it is deleted.

Invoices sent to KSeF are stored in the Ministry's system for 10 years from the end of the year in which they were issued. Data outside KSeF (business partners, notes, payments, pre-KSeF invoices), however, is something you need to be able to take with you.

Cheat sheet: good answer vs warning sign

Question Good answer Warning sign 1. Data location Sub-processor list with countries, data in the EEA or a documented transfer "Your data is in the cloud" 2. 2FA TOTP, hardware key or passkey; can be enforced for the team No 2FA, or SMS only with no plans to change 3. Secrets KSeF certificates encrypted, passwords and API keys hashed "We encrypt passwords" with no details 4. Sessions and logs Login history, notifications, "log out everywhere" No visibility of active sessions 5. Data processing agreement Article 28(3) elements, a specific notification deadline No agreement, or a vague "GDPR compliant" 6. KSeF connection A permission you can revoke yourself, minimal scope No information on how to cut off access 7. Retention and export Full export, file deletion, a clear deletion deadline Export only "on request" via support

What to do now if your software was affected

  1. Change your password to a unique one you don't use anywhere else.

  2. Turn on 2FA if available and log out all active sessions.

  3. Generate new API keys and remove the old ones from integrations.

  4. Check in KSeF who holds permissions for your company and revoke any you don't need.

  5. Tell your business partners that you are not changing your bank account number, and ask them to confirm any such request by phone.

  6. Assess whether you need to notify UODO. It is worth getting help from a lawyer or a DPO with this decision.

How we approach this at Biurko

Biurko connects to KSeF through a permission: you grant it in KSeF and can revoke it yourself at any time in the KSeF portal or via Profil Zaufany. We store KSeF certificates and tokens in the database in encrypted form, the database is backed up automatically every day, and security events are monitored automatically, with incident detection and blocking. We act as a data processor, and the data processing agreement is part of our terms of service. [FILL IN: server location, e.g. "Our servers are in the EU (…)".] [FILL IN: 2FA status. If not in production: "2FA is on our roadmap; we will describe it once it is available."]

If you are switching invoicing software before 1 January 2027, you can try Biurko on the FREE plan: no card required, with unlimited invoice submission to KSeF.

Summary

A good Fakturownia alternative is not the one that talks loudest about security, but the one that gives concrete answers to seven questions: data location, 2FA, how secrets are stored, login history, the data processing agreement, the KSeF connection model and data retention. Ask every provider, including your current one, and compare the answers against the same criteria.

FAQ

Did the Fakturownia leak affect data in KSeF?

No. In its notice of 29 September 2026, the Ministry of Finance said the incident did not concern data held in the National e-Invoice System. Fakturownia also stated that KSeF certificates were not taken. The leak covered data stored on the software provider's side, including account data, business partners and some documents.

Do I have to report an invoicing software leak to UODO?

It depends on the risk assessment. You are the controller of your business partners' data, so you assess whether the breach poses a risk to people, and as a rule you have 72 hours from becoming aware of it to notify (Article 33 GDPR). The provider reporting its own part does not automatically relieve you of that assessment.

Does switching invoicing software help after a leak?

Data that has already leaked won't come back, so switching does not undo the incident. It does protect your future data if the new provider gives better answers on 2FA, encryption and retention. First secure your current account: change the password, log out all sessions and replace API keys.

What is the difference between a KSeF certificate and a KSeF token?

A token is a string with assigned permissions, used to log in and authorise actions. A KSeF certificate is based on asymmetric cryptography and is used for authentication or for issuing invoices in offline mode. Tokens were originally meant to work until the end of 2026; the Ministry proposed keeping them, so check the current rules.

How do I check whether invoicing software has a data processing agreement?

Look in the terms of service for a section on entrusting personal data processing, or for a separate "data processing agreement" or "DPA". Check that it includes the Article 28(3) GDPR elements, a sub-processor list and a breach notification deadline. If you can't find it, write to the provider and ask for it in writing.

Is hosting in Poland safer than in another EU country?

Under GDPR, storing data in Poland and in any other EEA country follows the same rules. Specific safeguards matter more than the country: encryption, access control, backups and the sub-processor list. Additional requirements only apply when data is transferred outside the EEA.


This article is for information only and is not legal or tax advice. For your specific situation, consult a lawyer, a data protection officer or a tax adviser.

Author: Artem Shevchenko, Senior Full-Stack Developer with 7+ years of experience, founder of Biurko.io. He builds KSeF integration every day.

Tags

#cybersecurity
Share

Previous article

Which tax form should a B2B programmer in Poland choose for 2027?

Stay in the loop

An email when we publish a new article — and nothing else.

We respect your privacy. Unsubscribe at any time.

Cookies

We use only essential cookies. Visit statistics are kept on our server, with nothing saved on your device. Website Policy