Invoicing · VeriFactu

Invoice, sign and register with the AEAT in one click

XML per the HAC/1177/2024 spec, chained SHA-256 hash, signed with your FNMT certificate, QR on every PDF, and an official AEAT CSV in under 30 seconds. RD 1007/2023 isn't optional for Cofactu — it's the reason we exist.

RD 1007/2023 compliant FNMT certificate Data hosted in the EU CSV in under 30s
Anatomy of a record

The journey of an invoice

You approve the draft and the chain begins: AEAT validation, XML per Orden HAC/1177/2024, XAdES signature with your certificate, chained SHA-256 hash, submission to the AEAT and an official CSV in under 30 seconds. Every step, archived only in your vault.

  1. 1

    Draft

    You create it with the form or the AI assistant.

  2. 2

    AEAT validation

    Client, type, date and amount — checked before you can send it.

  3. 3

    XML

    Generated per Orden HAC/1177/2024, no adapters.

  4. 4

    XAdES signature

    With your FNMT .p12 certificate, AES-256-GCM encrypted.

  5. 5

    Chained SHA-256 hash

    Includes the hash of the previous invoice.

  6. 6

    Sent to the AEAT

    Through the VeriFactu channel — SOAP · mTLS.

  7. 7

    Official CSV

    The AEAT accepts it and returns the CSV in under 30s.

  8. 8

    Vault

    PDF with QR, signed XML and CSV — 5 years, stored in the EU.

Tamper-proofing

Tamper-proof by design, not by promise

Every invoice cryptographically links to the previous one through its SHA-256 hash. If someone alters a past invoice, the chain breaks and it's detected. It's the tamper-proofing mechanism required by RD 1007/2023 — and we verify it ourselves.

  • SHA-256 fingerprint + the previous invoice's hash on every record
  • Chain verifier: detects any break
  • Automatic repair of error 4171, no manual intervention
AI Assistant

One sentence. One draft ready to approve.

Describe the invoice in plain language and the assistant generates the full draft — client, description, amount, VAT and the right series. You review it, approve it, and it goes out signed to the AEAT.

  • Create the draft with one prompt, no forms from scratch
  • Always a draft — never sent without your approval
  • Reuses clients and products from your catalog
Spec sheet

Twelve capabilities, all active from the first plan

No gems, no paid add-ons. All included in every plan, even the most basic.

Compliance and format
  • XML per official AEAT spec

    Every invoice generates XML per Orden HAC/1177/2024. No adapters, no conversions.

  • Chained SHA-256 hash

    Each invoice's hash includes the previous one's. Any retroactive alteration is detected.

  • Signed with your FNMT certificate

    Signs with your own .p12, AES-256-GCM encrypted. Never travels unencrypted.

  • Mandatory QR on every PDF

    QR code with the AEAT verification URL on every invoice, per the technical spec.

Issuance and use cases
  • Official CSV in under 30s

    On approval, it goes out through the VeriFactu channel and the AEAT returns the acceptance CSV.

  • Guided R1–R4 corrective invoices

    The form guides you to the right type and links the corrected invoice for auditing.

  • Recurring and multi-series

    Periodic invoices and multiple series (F-, S-, E-) with automatic sequential numbering.

  • AEAT validations in the form

    Validates client, type, corrective link, date and amount before you can send it.

Errors, alerts and AI
  • Errors in plain language

    We translate AEAT codes (1xxx, 41xx, 5xxx) into plain language with the cause and the fix.

  • Proactive email on rejection

    If the AEAT rejects an invoice, we email you the error and how to fix it.

  • Chain repair (error 4171)

    We detect and automatically repair a broken hash chain.

  • AI assistant: draft from one sentence

    Describe the invoice in plain language and it generates the full draft for you to review.

More on Cofactu

The invoice is just the beginning

Once issued, Cofactu turns it into tax forms, journal entries and ledgers. All connected, nothing to re-enter.

FAQ

Frequently asked questions

The essentials on how Cofactu meets VeriFactu compliance.

Does Cofactu comply with VeriFactu from day one?

Yes. We generate XML per Orden HAC/1177/2024, sign with an FNMT certificate, chain SHA-256 hashes and send to the AEAT through the official channel. The AEAT itself issues the acceptance CSV. Complying with RD 1007/2023 is the core of the product. More at /verifactu.

Do I need to install any software or plugin?

No. Cofactu is 100% web-based. You only upload your electronic certificate (.p12) once — we encrypt it with AES-256-GCM and you never touch it again. Submission to the AEAT is automatic.

What happens if the AEAT rejects an invoice?

We send you a proactive email with the error code explained in plain language and the steps to fix it. The most common errors (incorrect NIF, negative amounts, broken hash chain 4171) have a guided fix right in the app.

Can I use Cofactu without sending to the AEAT (non-VeriFactu)?

Yes. Sending is technically optional — you can be 'non-VeriFactu' and still comply if you keep the record locally. But we recommend sending: you get the VeriFactu logo, the CSV as proof of compliance, and lower risk in inspections.

VeriFactu compliance, no complications

Cofactu handles the XML, the signature, the hash chain and the submission to the AEAT. You just approve the invoice.