{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "quaderno",
    "name": "Quaderno",
    "vendor": "Recrea Systems, SL",
    "vendorUrl": "https://quaderno.io",
    "kind": "http-api",
    "category": "tax",
    "summary": "Sales tax, VAT and GST software for online businesses from Recrea Systems, a Visma company in Spain. Its REST API calculates tax for a sale, records sales and refunds, issues invoices and credit notes and exports tax reports.",
    "url": "https://www.anchorterminal.com/tools/quaderno",
    "markdownUrl": "https://www.anchorterminal.com/tools/quaderno.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/quaderno.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/quaderno.json",
    "repo": "https://github.com/quaderno/quaderno-ruby",
    "license": "Proprietary service under Quaderno's terms of service. The Ruby library on GitHub is MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://quadernoapp.com/api",
    "packages": [
      {
        "registry": "rubygems",
        "name": "quaderno"
      },
      {
        "registry": "packagist",
        "name": "quaderno/quaderno"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve API key. Sign up at quadernoapp.com (or sandbox-quadernoapp.com for the sandbox), copy the key from the API keys page and send it as the HTTP Basic username with an empty password to https://ACCOUNT_NAME.quadernoapp.com/api. The docs say anyone holding the key can read and modify everything the account has access to. Platforms on Quaderno Connect use OAuth 2.0 authorisation code instead, with an app created in the dashboard, scopes read_only (the default) or read_write, access tokens that expire after 25 days and refresh tokens. No app review or sales approval was found for either route.",
    "pricing": "paid",
    "pricingNotes": "Four monthly plans by recorded transactions. Hobby $29 (25 transactions, 1 user, 1 jurisdiction, 1 integration), Startup $49 (250), Business $99 (1,000) and Growth $149 (2,500), with Enterprise on request above that. Yearly billing costs ten months. API calls are capped at ten times the plan's transactions, and passing the transaction limit moves the account up a plan, with no overage fee. An agent can start without a contract through the 7-day trial, which needs no card, or the free sandbox, which is capped at 200 documents. Registration and filing are sold as an add-on service (https://quaderno.io/pricing/, checked 2026-10-08).",
    "priceSummary": "$29 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 15,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.quaderno.io",
    "llmsTxt": "https://quaderno.io/llms.txt",
    "openapi": "https://developers.quaderno.io/redocusaurus/openapi-v20241028.yaml",
    "capabilities": [
      "tax.calculate",
      "tax.transactions",
      "tax.invoicing"
    ],
    "tags": [
      "hosted",
      "paid",
      "free-trial",
      "sandbox",
      "api-key",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "ruby",
      "php",
      "status-page",
      "sla",
      "vat",
      "sales-tax",
      "e-invoicing"
    ],
    "lastRelease": "2026-07-04",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 59.5,
      "grade": "C",
      "agentReady": false,
      "rank": 427,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 56,
        "maintenance": 28,
        "payments": 30,
        "reliability": 91,
        "schema": 77,
        "security": 39,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 91,
          "points": 18.2,
          "reason": "Graded on the public REST API. Statuspage at quaderno.statuspage.io with two components, Quaderno Web Application and Quaderno APIs (20). Its incident feed lists nothing after a brief API outage on 16 July 2025, so the last 90 days are clean (30). The limit is published as 100 API calls per 15 seconds, with a monthly cap of ten times the plan's transactions (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers, but no Retry-After or backoff guidance was found, there are no idempotency keys and the docs say retry logic is the integration's responsibility (6). The SLA page promises 99.99 per cent monthly uptime with service credits to customers on Quaderno Premium, a tier the pricing page doesn't name (10). GA (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "OpenAPI 3.1 spec for version 20241028 at developers.quaderno.io/redocusaurus/openapi-v20241028.yaml, 92 operations (25). quaderno.io/llms.txt routes agents to the developer docs, but the docs site has no llms.txt of its own and no Markdown pages (7). 91 of 92 operations carry a description, mostly one sentence, with fuller guidance in the reference's opening section on conventions and in the guides (12). 61 enums and required fields are marked, but amounts and dates are plain strings with no formats, patterns or length limits (9). Examples throughout, one table of status codes for the whole API, and only 9 operations document a response other than success (9). Date-named versions selectable by Accept header and a public API changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 56,
          "points": 9.1,
          "reason": "No MCP server from the vendor, so this is the REST API. Lists return 25 objects by default and up to 100 with `limit`. There is no field selection, though the tax calculation returns one small object (12). Cursor paging with `created_before` plus X-Pages-HasMore and X-Pages-NextPage headers, and filters by text, date range, state, contact and processor_id on document lists (17). Standard status codes with a JSON `error` message and 422 on invalid state changes, without a catalogue of error codes (11). No idempotency keys. A duplicate can be checked by processor_id before a retry (5). Tax calculation needs only `to_country` and falls back to account defaults. Official Ruby and PHP libraries, the Ruby gem last released on 29 July 2024, and every call needs the account subdomain (11)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 39,
          "points": 6.83,
          "reason": "An API key sent as the Basic auth username. The docs say anyone holding it can read and modify everything the account has access to. Connect apps use OAuth 2.0 authorisation code with two scopes, read_only (the default) and read_write, access tokens that expire after 25 days and refresh tokens (20). The read_only scope and custom team roles with view-only access to six areas give some least privilege. Invoices can't be deleted through the API, only credited or voided. No confirmation step was found (11). Returns customer names, notes and metadata written by others, with no injection guidance (3). No API audit log was found in the reviewed documentation (0). A security policy page, TLS 1.2 and a Visma Security Program Gold claim. The bug bounty is marked temporarily closed, security.txt returns 404 and the Visma Trust Centre lists no certificates for Quaderno (5)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Four plans are public by month, Hobby $29, Startup $49, Business $99 and Growth $149, each with a transaction allowance, and Enterprise on request. That is plan-only pricing (10). A 7-day trial with no card, stated on the pricing page and in the terms, plus a free sandbox (20). Signup is a browser form (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 28,
          "points": 2.45,
          "reason": "The newest public API version is 20241028. The PHP library's v2.1.4 came out on 4 July 2026, 96 days before the check, and the OpenAPI files were republished on 10 August 2026 with a preview of version 20260309 (10). No three dated releases or changelog entries in the last 90 days (0). Closed service. The API changelog stops at October 2024 and the product changelog at July 2025, with a help centre and support contact (6). Official Ruby and PHP libraries. The Ruby gem is 3.0.1 from 29 July 2024 (8). The Ruby repository has a test workflow. The PHP one has tests and no CI workflow (4)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 69, provenance 83",
          "reason": "Closed service under terms updated on 15 September 2026 that name Recrea Systems, SL and Spanish law. The Ruby library is MIT (17). The privacy policy and the terms both say account content is deleted within 6 months of cancellation, and the terms add a 30-day API retrieval period. The DPA lets the processor use customer data in aggregated and anonymised form for improvement, research and training (20). Old API versions are sunset with at least one month's notice, and deprecated behaviour carries a `Deprecation: true` header. No fixed schedule (12). The Visma Trust Centre lists hosting by DigitalOcean in the Netherlands and AWS in Ireland, and each processor with its country (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "No MCP server from the vendor, so this is the REST API. Lists return 25 objects by default and up to 100 with `limit`. There is no field selection, though the tax calculation returns one small object (12). Cursor paging with `created_before` plus X-Pages-HasMore and X-Pages-NextPage headers, and filters by text, date range, state, contact and processor_id on document lists (17). Standard status codes with a JSON `error` message and 422 on invalid state changes, without a catalogue of error codes (11). No idempotency keys. A duplicate can be checked by processor_id before a retry (5). Tax calculation needs only `to_country` and falls back to account defaults. Official Ruby and PHP libraries, the Ruby gem last released on 29 July 2024, and every call needs the account subdomain (11).",
          "maintenance": "The newest public API version is 20241028. The PHP library's v2.1.4 came out on 4 July 2026, 96 days before the check, and the OpenAPI files were republished on 10 August 2026 with a preview of version 20260309 (10). No three dated releases or changelog entries in the last 90 days (0). Closed service. The API changelog stops at October 2024 and the product changelog at July 2025, with a help centre and support contact (6). Official Ruby and PHP libraries. The Ruby gem is 3.0.1 from 29 July 2024 (8). The Ruby repository has a test workflow. The PHP one has tests and no CI workflow (4).",
          "payments": "No x402, MPP or L402 (0). Four plans are public by month, Hobby $29, Startup $49, Business $99 and Growth $149, each with a transaction allowance, and Enterprise on request. That is plan-only pricing (10). A 7-day trial with no card, stated on the pricing page and in the terms, plus a free sandbox (20). Signup is a browser form (0).",
          "reliability": "Graded on the public REST API. Statuspage at quaderno.statuspage.io with two components, Quaderno Web Application and Quaderno APIs (20). Its incident feed lists nothing after a brief API outage on 16 July 2025, so the last 90 days are clean (30). The limit is published as 100 API calls per 15 seconds, with a monthly cap of ten times the plan's transactions (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers, but no Retry-After or backoff guidance was found, there are no idempotency keys and the docs say retry logic is the integration's responsibility (6). The SLA page promises 99.99 per cent monthly uptime with service credits to customers on Quaderno Premium, a tier the pricing page doesn't name (10). GA (10).",
          "schema": "OpenAPI 3.1 spec for version 20241028 at developers.quaderno.io/redocusaurus/openapi-v20241028.yaml, 92 operations (25). quaderno.io/llms.txt routes agents to the developer docs, but the docs site has no llms.txt of its own and no Markdown pages (7). 91 of 92 operations carry a description, mostly one sentence, with fuller guidance in the reference's opening section on conventions and in the guides (12). 61 enums and required fields are marked, but amounts and dates are plain strings with no formats, patterns or length limits (9). Examples throughout, one table of status codes for the whole API, and only 9 operations document a response other than success (9). Date-named versions selectable by Accept header and a public API changelog (15).",
          "security": "An API key sent as the Basic auth username. The docs say anyone holding it can read and modify everything the account has access to. Connect apps use OAuth 2.0 authorisation code with two scopes, read_only (the default) and read_write, access tokens that expire after 25 days and refresh tokens (20). The read_only scope and custom team roles with view-only access to six areas give some least privilege. Invoices can't be deleted through the API, only credited or voided. No confirmation step was found (11). Returns customer names, notes and metadata written by others, with no injection guidance (3). No API audit log was found in the reviewed documentation (0). A security policy page, TLS 1.2 and a Visma Security Program Gold claim. The bug bounty is marked temporarily closed, security.txt returns 404 and the Visma Trust Centre lists no certificates for Quaderno (5).",
          "transparency": "Closed service under terms updated on 15 September 2026 that name Recrea Systems, SL and Spanish law. The Ruby library is MIT (17). The privacy policy and the terms both say account content is deleted within 6 months of cancellation, and the terms add a 30-day API retrieval period. The DPA lets the processor use customer data in aggregated and anonymised form for improvement, research and training (20). Old API versions are sunset with at least one month's notice, and deprecated behaviour carries a `Deprecation: true` header. No fixed schedule (12). The Visma Trust Centre lists hosting by DigitalOcean in the Netherlands and AWS in Ireland, and each processor with its country (20)."
        },
        "sources": [
          {
            "what": "OpenAPI 3.1 spec, version 20241028",
            "url": "https://developers.quaderno.io/redocusaurus/openapi-v20241028.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference (authentication, rate limiting, pagination, errors, versioning)",
            "url": "https://developers.quaderno.io/api/",
            "seen": "2026-10-08"
          },
          {
            "what": "API changelog",
            "url": "https://developers.quaderno.io/api-changelog/",
            "seen": "2026-10-08"
          },
          {
            "what": "preview of API version 20260309",
            "url": "https://developers.quaderno.io/api-preview/",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox guide",
            "url": "https://developers.quaderno.io/tools/sandbox/",
            "seen": "2026-10-08"
          },
          {
            "what": "SDKs page",
            "url": "https://developers.quaderno.io/tools/sdks/",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks guide (retries and signatures)",
            "url": "https://developers.quaderno.io/guides/webhooks/",
            "seen": "2026-10-08"
          },
          {
            "what": "Connect standard accounts (OAuth flow and scopes)",
            "url": "https://developers.quaderno.io/guides/connect/standard-accounts/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://quaderno.io/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents feed",
            "url": "https://quaderno.statuspage.io/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA",
            "url": "https://quaderno.io/legal/sla/",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy",
            "url": "https://quaderno.io/legal/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://quaderno.io/legal/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://quaderno.io/legal/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing agreement",
            "url": "https://quaderno.io/legal/dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "Visma Trust Centre entry for Quaderno",
            "url": "https://www.visma.com/trust-centre-products/quaderno",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://quaderno.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "product changelog",
            "url": "https://quaderno.io/blog/quaderno-updates/changelog/",
            "seen": "2026-10-08"
          },
          {
            "what": "team roles (help centre)",
            "url": "https://support.quaderno.io/article/491-managing-your-team",
            "seen": "2026-10-08"
          },
          {
            "what": "PHP library and releases",
            "url": "https://github.com/quaderno/quaderno-php",
            "seen": "2026-10-08"
          },
          {
            "what": "Ruby library",
            "url": "https://github.com/quaderno/quaderno-ruby",
            "seen": "2026-10-08"
          },
          {
            "what": "Ruby gem on RubyGems",
            "url": "https://rubygems.org/gems/quaderno",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=quaderno",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether an API key can be revoked or rotated, and whether a Custom role's view-only permissions limit that user's API key. The API keys page needs a login",
          "Which plan the SLA's Quaderno Premium refers to. The pricing page lists Hobby, Startup, Business, Growth and Enterprise",
          "Whether a 429 response carries Retry-After. The docs name only the X-RateLimit headers",
          "When API version 20260309, shown as a preview, becomes available",
          "Whether exemption certificates can be managed through the API. The spec has tax ID validation and an exempt tax code, and no certificate object",
          "Prices are shown with a dollar sign outside the EU and a euro sign inside it, with the same figures, per the pricing page's script. We read the figures from the page data, not a rendered page"
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI 3.1 spec covers 92 operations, with a free sandbox and a status page showing no incident since July 2025. The API key has full account access, there are no idempotency keys, and the newest public API version is dated October 2024.",
      "bestFor": "An agent working for a SaaS, digital-goods or e-commerce seller that needs a tax rate at checkout, a record of each sale with location evidence, and compliant invoices, including Spanish Verifactu and TicketBAI.",
      "strengths": [
        "Public OpenAPI 3.1 spec with 92 operations across tax rates, transactions, invoices, credit notes, reporting and webhooks",
        "Separate free sandbox at sandbox-quadernoapp.com with test tax IDs and a purge endpoint, and a 7-day production trial without a card",
        "Statuspage with API and web application components and no incident recorded since 16 July 2025",
        "Published rate limit of 100 calls per 15 seconds, with X-RateLimit headers and a /ping endpoint that reports remaining calls",
        "Subprocessors and hosting locations listed on the Visma Trust Centre (DigitalOcean in the Netherlands, AWS in Ireland)"
      ],
      "weaknesses": [
        "One API key reads and writes everything its user can reach. Scopes exist only on Connect OAuth tokens (read_only, read_write)",
        "No idempotency keys, and the docs say retry logic is the integration's responsibility",
        "The newest public API version is 20241028. A preview of 20260309 is in the docs but not yet available",
        "No security.txt, the bug bounty is marked temporarily closed, and no SOC 2 or ISO 27001 report was found for Quaderno itself",
        "Registration and filing are a done-for-you service booked by call, not API operations. Monthly API calls are capped at ten times the plan's transactions"
      ],
      "agentNotes": [
        "Call GET https://quadernoapp.com/api/authorization first. Its `href` gives the account subdomain that every other call needs",
        "Before retrying a failed POST /transactions, list invoices by `processor_id` to check whether the sale was recorded. There is no idempotency key",
        "Treat GET /invoices/{id}/deliver as a write. It emails the invoice to the customer",
        "Correct a final invoice with a credit note. DELETE on invoices returns 410 and PUT accepts only notes, tags, metadata and address fields",
        "Read X-RateLimit-Remaining and X-RateLimit-Reset, and page with `created_before` and `limit` up to 100"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 59.5
        }
      ],
      "editorialScores": {
        "ergonomics": 56,
        "maintenance": 28,
        "payments": 30,
        "reliability": 91,
        "schema": 77,
        "security": 39,
        "transparency": 69
      },
      "provenanceScore": 83
    },
    "connect": {
      "install": "gem install quaderno",
      "http": "curl \"https://ACCOUNT_NAME.quadernoapp.com/api/tax_rates/calculate?to_country=US\u0026to_postal_code=10128\" \\\n  -u YOUR_API_KEY:x"
    },
    "letme": {
      "capability": "https://letme.dev/tax.calculate",
      "tool": "https://letme.dev/quaderno"
    },
    "notable": [
      "GET /tax_rates/calculate needs only `to_country` and returns the rate, tax amount and a status of taxable, non_taxable, not_registered or reverse_charge (https://developers.quaderno.io/api/)",
      "POST /transactions records a sale or refund and creates the contact, invoice or credit note and payment in one call (https://developers.quaderno.io/guides/record-sales/)",
      "The sandbox is a separate environment with its own signup, test tax IDs, US local rates for four ZIP codes only, a 200-document cap and a /purge endpoint (https://developers.quaderno.io/tools/sandbox/)",
      "Invoices and credit notes can't be deleted through the API. A final invoice is corrected with a credit note, and PUT accepts only notes, tags, metadata and address fields (https://developers.quaderno.io/api-changelog/)",
      "Webhooks are signed with HMAC-SHA1 in X-Quaderno-Signature and retried hourly for up to 72 hours (https://developers.quaderno.io/guides/webhooks/)",
      "The vendor publishes no MCP server. The official MCP registry lists one third-party server, io.usefulapi/quaderno (https://registry.modelcontextprotocol.io/v0.1/servers?search=quaderno)",
      "The terms name Recrea Systems, SL, and the DPA describes it as a company in the Visma Group (https://quaderno.io/legal/dpa/)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST over HTTPS at https://ACCOUNT_NAME.quadernoapp.com/api, 92 operations in an OpenAPI 3.1 spec. Groups are transactions, contacts, products, tax rates, tax IDs, jurisdictions, tax codes, evidence, invoices, receipts, credit notes, proformas, expenses, recurring documents, checkout sessions, coupons, Connect accounts, reporting and webhooks"
      },
      {
        "label": "Credentials",
        "value": "API key as the Basic auth username, with the account's full access. OAuth 2.0 authorisation code for Connect apps, scopes read_only and read_write, access tokens valid 25 days"
      },
      {
        "label": "Rate limits",
        "value": "100 API calls per 15 seconds, with X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers and 429 on excess. Monthly API calls are capped at ten times the plan's transactions"
      },
      {
        "label": "Pagination",
        "value": "25 objects by default, `limit` up to 100, cursor by `created_before`, with X-Pages-HasMore and X-Pages-NextPage headers"
      },
      {
        "label": "Sandbox",
        "value": "https://sandbox-quadernoapp.com, free, separate credentials, 200-document cap, POST /purge to clear it. Tax ID DE111111111 tests an invalid ID and IE222222222 an unavailable validator"
      },
      {
        "label": "Trial",
        "value": "7 days, no card"
      },
      {
        "label": "Versioning",
        "value": "Versions named by date, 20160602 to 20241028, chosen in account settings or per request with `Accept: application/json; api_version: 20241028`. A preview of 20260309 is in the docs. Sunsetting with at least one month's notice"
      },
      {
        "label": "Reports",
        "value": "POST /reporting/requests builds a tax_summary, invoices_list or credits_list file for a date range, ready some minutes later at `report_url`"
      },
      {
        "label": "Tax ID validation",
        "value": "GET /tax_ids/validate returns true, false or null when the external service is down. Covers the EU, United Kingdom, Switzerland, Quebec, Australia and New Zealand"
      },
      {
        "label": "Webhooks",
        "value": "HMAC-SHA1 signature in X-Quaderno-Signature, hourly retries for up to 72 hours, threshold.warning, threshold.exceeded and threshold.eu.100k events for registration alerts"
      },
      {
        "label": "SDKs",
        "value": "Ruby gem quaderno 3.0.1 (29 July 2024, MIT) and PHP quaderno/quaderno v2.1.4 (4 July 2026)"
      },
      {
        "label": "SLA",
        "value": "99.99 per cent monthly uptime for Quaderno Premium customers, with credits of ten times the hourly rate for a day with an outage over 5 minutes"
      },
      {
        "label": "Hosting",
        "value": "DigitalOcean in the Netherlands and AWS in Ireland, per the Visma Trust Centre"
      },
      {
        "label": "Filing",
        "value": "Registration and return filing are a done-for-you service booked through a call, not API operations"
      }
    ],
    "unitPrices": [
      {
        "item": "Hobby plan, 25 transactions",
        "unit": "month",
        "usd": 29,
        "note": "1 user, 1 jurisdiction, 1 integration. $24 a month billed yearly"
      },
      {
        "item": "Startup plan, 250 transactions",
        "unit": "month",
        "usd": 49,
        "note": "$41 a month billed yearly"
      },
      {
        "item": "Business plan, 1,000 transactions",
        "unit": "month",
        "usd": 99,
        "note": "$83 a month billed yearly"
      },
      {
        "item": "Growth plan, 2,500 transactions",
        "unit": "month",
        "usd": 149,
        "note": "$124 a month billed yearly"
      }
    ],
    "provenance": {
      "legalEntity": "Recrea Systems, SL",
      "domain": "quaderno.io",
      "domainRegistered": "2012-10-22",
      "endpointOnVendorDomain": true,
      "terms": "https://quaderno.io/legal/terms/",
      "privacy": "https://quaderno.io/legal/privacy/",
      "statusPage": "https://quaderno.statuspage.io",
      "changelog": "https://developers.quaderno.io/api-changelog/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms (updated 15 September 2026, effective 1 October 2026) name Recrea Systems, SL, company registration number B35635648, Venegas 2A, Local 1, 35003 Las Palmas, Spain, under Spanish law. The DPA calls it a company in the Visma Group.",
        "The API and dashboard answer at quadernoapp.com and its account subdomains, a second domain the vendor's docs and terms point to. RDAP gives its registration date as 2012-04-27.",
        "RDAP for quaderno.io gives a registration date of 2012-10-22 and an expiry of 2026-10-22.",
        "quaderno.io/.well-known/security.txt and quadernoapp.com/.well-known/security.txt both return 404. The security policy says the bug bounty programme is temporarily closed.",
        "Subprocessors are listed on the Visma Trust Centre at https://www.visma.com/trust-centre-products/quaderno, which shows the legal unit as Recrea Systems SL, ES."
      ],
      "score": 83,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Recrea Systems, SL",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "quaderno.io, registered 2012-10-22 (13 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "quadernoapp.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "quaderno.statuspage.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://quaderno.io/legal/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-15",
          "words": 3393,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Updated at 15 September, 2026 · Effective as of 1 October, 2026",
              "says": "Last updated 2026-09-15"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "You and Recrea agree to be subject to the exclusive jurisdiction of the Las Palmas de Gran Canaria Courts in order to resolve any legal issue concerning or associated with the agreement."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Recrea’s total aggregate liability shall not exceed the total net fees paid by you to Recrea for the use of our services in the twelve (12) calendar months immediately preceding the event giving rise to the claim."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Should You breach any of the terms in this Terms of Service, your account will be terminated without prior notice."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Recrea reserves the right to change their fees with 15 days notice.",
              "says": "Gives 15 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not copy, edit, adapt, reproduce, distribute, reverse engineer, decompile, or disassemble any aspect of the Service which Recrea, its affiliates or its suppliers own."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "You also agree and undertake to not use robots, spiders, other automated devices, or manual processes to control or copy any content or parts of the Service.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Direct competitors of Recrea may not access the Services under any arrangement.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Recrea reserves the right to update and edit the Terms of Service without any prior notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Recrea reserves the right to temporarily or permanently edit or suspend the Services at any time for any reason."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer grants a licence to use, copy, transmit, store, analyse and back up all submitted data, including personal data, for a list of purposes that follows the sentence.",
              "quote": "When You enter or upload your data into our Services, we don’t own that data but You grant us a licence to use, copy, transmit, store, analyse, and back up all data You submit to us through our Services, including personal data of yourself and others, to:"
            },
            {
              "date": "2026-10-08",
              "text": "The account and all its content are deleted six months after the customer cancels.",
              "quote": "Your account and all of its content will be deleted 6 months after Your cancellation."
            },
            {
              "date": "2026-10-08",
              "text": "Customer content, including invoices, payment reminders and personal messages, may travel unencrypted over the Internet during processing.",
              "quote": "You understand that the Service can be used for transmission of your content, and that during processing, your content, including invoices, payment reminders, and personal messages, may be transferred unencrypted over the Internet."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://quaderno.io/legal/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-05-16",
          "words": 3279,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "This policy is revised at least yearly. Last updated: 16 May, 2024",
              "says": "Last updated 2024-05-16"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect information about your browsing activity for analytics and statistical purposes such as conversion rate testing and experimenting with new product designs."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "If you delete your account, we’ll delete the content within 6 months.",
              "says": "Names a period of 6 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Quaderno does not rent or sell your information, but we do disclose your information to a limited set of trusted third parties in the situations explained below, for which you, by using our services or sites, hereby explicitly consent:"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We will NEVER sell your personal data to anyone.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "On grounds relating to your particular situation, you have the right to object to our processing of your personal data on the basis of legitimate interests or for direct marketing purposes."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Please use [email protected] or fill in this online form to file requests as mentioned in this section.",
              "says": "Gives an email address, hidden from our reader by the page"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "If processors are located outside the EU/EEA, we ensure legal grounds for such international transfers on your behalf, hereunder by using the EU Model Clauses."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/quaderno.json",
    "live": {
      "slug": "quaderno",
      "probe": {
        "target": "https://quadernoapp.com/api",
        "method": "get",
        "lastAt": "2026-10-08T19:52:59.819657163Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 119,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 107,
        "p95ms24h": 154,
        "samples24h": 50,
        "samples30d": 50,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 50,
            "ok": 50
          }
        ]
      },
      "vendorStatus": {
        "page": "https://quaderno.statuspage.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:51:00.100256822Z"
      },
      "githubStars": 15,
      "securityTxt": {
        "url": "https://quaderno.io/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:48.301371426Z"
      },
      "pages": [
        {
          "url": "https://developers.quaderno.io/api-changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:58.645813139Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "69ea7b5187a7"
        },
        {
          "url": "https://quaderno.io/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:37.065141515Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "0674c9e74b70"
        },
        {
          "url": "https://quaderno.io/legal/privacy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:32.930235875Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "02d941cfbb26"
        },
        {
          "url": "https://quaderno.io/legal/terms/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:35.074640255Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "9b2392893a86"
        }
      ],
      "updatedAt": "2026-10-08T19:52:59.819657163Z"
    }
  }
}
