Invoicing · VeriFactu

Invoice, sign and register with the AEAT in one click

XML per the HAC/1177/2024 spec, chained SHA-256 hash, QR on every PDF and certificate-authenticated submission to the AEAT. When the AEAT accepts the record, its official CSV stays linked to the invoice.

RD 1007/2023 compliant FNMT certificate Data hosted in the EU Automatic AEAT submission
Anatomy of a record

The journey of an invoice

You approve the draft and the chain begins: AEAT validation, XML per Orden HAC/1177/2024, chained SHA-256 hash, certificate-authenticated submission to the AEAT and its official response. Every step is archived in your account.

  1. 1

    Draft

    You create it with the form or the AI assistant.

  2. 2

    AEAT validation

    Client, type, date and amount — checked before you can send it.

  3. 3

    XML

    Generated per Orden HAC/1177/2024, no adapters.

  4. 4

    Authenticated submission

    The FNMT .p12 certificate is AES-256-GCM encrypted and authenticates the connection to the AEAT.

  5. 5

    Chained SHA-256 hash

    Includes the hash of the previous invoice.

  6. 6

    Sent to the AEAT

    Through the VeriFactu channel — SOAP · mTLS.

  7. 7

    Official response

    The AEAT processes the record and, when accepted, returns its CSV.

  8. 8

    Vault

    PDF with QR, submitted XML record and AEAT response — retained in your account.

Tamper-proofing

Tamper-proof by design, not by promise

Every invoice cryptographically links to the previous one through its SHA-256 hash. If someone alters a past invoice, the chain breaks and it's detected. It's the tamper-proofing mechanism required by RD 1007/2023 — and we verify it ourselves.

  • SHA-256 fingerprint + the previous invoice's hash on every record
  • Chain verifier: detects any break
  • Automatic repair of error 4171, no manual intervention
AI Assistant

One sentence. One draft ready to approve.

Describe the invoice in plain language and the assistant generates the full draft — client, description, amount, VAT and the right series. You review it, approve it, and it goes out signed to the AEAT.

  • Create the draft with one prompt, no forms from scratch
  • Always a draft — never sent without your approval
  • Reuses clients and products from your catalog
Spec sheet

Twelve capabilities, all active from the first plan

No gems, no paid add-ons. All included in every plan, even the most basic.

Compliance and format
  • XML per official AEAT spec

    Every invoice generates XML per Orden HAC/1177/2024. No adapters, no conversions.

  • Chained SHA-256 hash

    Each invoice's hash includes the previous one's. Any retroactive alteration is detected.

  • FNMT-authenticated connection

    Your .p12 is AES-256-GCM encrypted and used only to authenticate the communication with the AEAT.

  • Mandatory QR on every PDF

    QR code with the AEAT verification URL on every invoice, per the technical spec.

Issuance and use cases
  • Official AEAT response

    On approval, the record is submitted through the VeriFactu channel. When the AEAT accepts it, its CSV is stored with the invoice.

  • Guided R1–R4 corrective invoices

    The form guides you to the right type and links the corrected invoice for auditing.

  • Recurring and multi-series

    Periodic invoices and multiple series (F-, S-, E-) with automatic sequential numbering.

  • AEAT validations in the form

    Validates client, type, corrective link, date and amount before you can send it.

Errors, alerts and AI
  • Errors in plain language

    We translate AEAT codes (1xxx, 41xx, 5xxx) into plain language with the cause and the fix.

  • Proactive email on rejection

    If the AEAT rejects an invoice, we email you the error and how to fix it.

  • Chain repair (error 4171)

    We detect and automatically repair a broken hash chain.

  • AI assistant: draft from one sentence

    Describe the invoice in plain language and it generates the full draft for you to review.

More on Cofactu

The invoice is just the beginning

Once issued, Cofactu turns it into tax forms, journal entries and ledgers. All connected, nothing to re-enter.

FAQ

Frequently asked questions

The essentials on how Cofactu meets VeriFactu compliance.

Does Cofactu comply with VeriFactu from day one?

Yes. We generate XML per Orden HAC/1177/2024, chain SHA-256 hashes and submit through a certificate-authenticated connection to the official AEAT channel. In VeriFactu mode the individual record does not require an XAdES signature. The AEAT issues the acceptance CSV. More at /verifactu.

Do I need to install any software or plugin?

No. Cofactu is 100% web-based. You only upload your electronic certificate (.p12) once — we encrypt it with AES-256-GCM and you never touch it again. Submission to the AEAT is automatic.

What happens if the AEAT rejects an invoice?

We send you a proactive email with the error code explained in plain language and the steps to fix it. The most common errors (incorrect NIF, negative amounts, broken hash chain 4171) have a guided fix right in the app.

Can I use Cofactu without sending to the AEAT (non-VeriFactu)?

No. Cofactu's declared invoicing system operates exclusively in VeriFactu mode and submits its invoicing records to the AEAT. It does not offer a non-VeriFactu mode.

VeriFactu compliance, no complications

Cofactu handles the XML, the signature, the hash chain and the submission to the AEAT. You just approve the invoice.