Fortress Invoice is the sovereign checking and approval layer for the invoice inbound ahead of SAP S/4HANA: it receives XRechnung, ZUGFeRD, UBL/CII and PDF, validates against EN 16931, codes with local AI and posts via the official SAP APIs — on-premises, in your own cloud tenant or in a German data center. No document leaves your sovereignty boundary.
They are already in your inbox: XRechnung, ZUGFeRD. Not PDFs — data sets with amounts, tax rates, IBAN and purchase-order number, machine-readable down to the line item. You can have them typed off like paper, forward them into someone else's cloud — or put them to work in your own house.
Reception mandate: every domestic B2B company must be able to receive and process e-invoices (EN 16931).
Issuing mandate (phased): paper and plain PDF invoices disappear from B2B traffic — the structured inbound becomes the norm.
ViDA digital reporting (EU): digital VAT reporting based on structured invoice data. Whoever checks and posts cleanly already owns the data basis.
Each pillar backed by evidence instead of an adjective — put us to the test.
On-premises, air-gap-capable or in a German data center. The AI for coding, PDF extraction and fraud detection runs locally too — no document, no prompt leaves your house. No US jurisdiction, no cloud obligation.
EN 16931 checking proven rule by rule against the official standard corpus — including more than 600 official negative test cases. Tamper-evident audit chain (hash-linked, append-only), GoBD export, four-eyes workflow.
Fixed prices without transaction fees — formats, tenants and mappings included, no cost surprises per country or document type. Exit without lock-in: standard stack, complete data export.
Fortress Invoice reads supplier master data and purchase orders from your S/4HANA (three-way match against the real PO) and posts the approved document via the official OData APIs — purchase-order-based or against a G/L account, with duplicate protection and plain-text error messages from SAP. With or without BTP. If you prefer your own middleware, the verified handover package goes there instead — including the original, the validation report and attachments.
You name your test system, we enter it together in the frontend — connection test, post a document, and you see the document number in your SAP. The proof happens in your system, not on our slides.
Not an ERP replacement, not a Peppol network operator, not a mere format validator: Fortress Invoice decides what gets posted — posting happens in S/4HANA.
A ZUGFeRD invoice arrives in the mailbox.
Checked: standards-compliant, IBAN known, no duplicate, purchase order 4500071233 matches down to the line item. Coding suggestion 6815, confidence 0.93. Cash-discount deadline noted: 14 Aug.
Waiting with the right colleague for approval — original, check results and reasoning side by side.
Approved. Posted. Document number in your S/4HANA.
Nobody typed anything off. No document left the house. And the invoice that suddenly shows a different IBAN? It does not get through.
Email mailbox (IMAP), Peppol, upload, watched folder. Plain PDF invoices too: AI extraction with OCR fallback, review view with per-field confidence — never posted automatically.
EN 16931 and XRechnung rule by rule, IBAN, EU VIES, master-data reconciliation, duplicates, sanctions lists (EU, OFAC, UK, CH, UN), fraud and anomaly signals, 3-way match, hybrid check XML ↔ PDF visual part.
Four-eyes principle enforced server-side, amount-based dual approval, delegation rules, clarification thread per document, due-date and cash-discount monitoring with escalation.
Two-stage coding against SKR03/04 or the real chart of accounts of your SAP system, confidence with reasoning, every AI decision in the audit log. Touchless posting only behind a conservative gate.
WORM original archive, tamper-evident audit chain (HMAC, append-only via DB trigger), GoBD/Z3 export, selectable retention modes archive or transit.
OIDC/SSO and SCIM 2.0 with your IdP, role-based access, hard tenant isolation, five interface languages, Prometheus metrics — shipped as a hardened container.
From the incoming e-invoice through standards checking and local AI to posting in SAP — shown on the real system.
Product walkthrough on the real system (demo data) · AI-generated audio · German narration · 4:20
From signature to go-live: four phases, each with acceptance criteria. To start in shadow mode, read access to one invoice mailbox is enough.
Operation where your data belongs: on-premises, air-gapped or in a German data center. TLS, backups with rehearsed restore, alerting.
Connection to S/4HANA via the official OData APIs, or handover to your middleware — including attachments and the validation report. Master-data sync, inbound channels, approval workflow mapped to your roles.
Your real documents in a test run, acceptance against defined criteria — production starts only once everything demonstrably works.
Production cut-over with a defined update and rollback path. Operated by us or by your team — continuity via verified software escrow.
In shadow mode: read access to one invoice mailbox is enough, and Fortress Invoice checks your real invoices alongside your existing process — without touching it. You see the results on your own documents; after that comes the four-phase rollout to go-live.
No. Fortress Invoice reads master data and purchase orders and posts the approved document via the official SAP OData APIs — with or without the Business Technology Platform. Alternatively it hands the verified package (data, original, validation report, attachments) over to your existing middleware.
Entirely with you: on-premises, air-gapped or in a German data center. The AI checking and coding run locally too — no document and no prompt ever crosses your sovereignty boundary. Regulatory standards maintenance (new XRechnung/ZUGFeRD versions) is part of ongoing operation.
A transparent fixed-price model: one-off setup plus a predictable annual fee — no transaction fees, no surcharges per format, country or tenant. We lay the complete price sheet open in the first meeting; you recalculate every variant yourself.
That is what the verified software escrow with our independent partner VERYGOOD GmbH is for: the trustee does not merely store the source code, it continuously proves it can build, maintain and operate it. Together with the standard stack (Rust, PostgreSQL) and the complete data export, you stay in control in every scenario.
Request the live demo: 30 minutes, your test system, one posted document. Or start in shadow mode — read access to one invoice mailbox is enough. We get back to you personally, without funnels and without newsletter spam.
Prefer email? service@bruchmann-tec.com