Trust

Security & privacy

PainXML is built so your payment data stays yours — end to end.

Files never leave your device

Validation and generation run entirely in your browser via WebAssembly. PainXML makes no network calls for your payment data — nothing is uploaded, logged, or stored.

No telemetry

We do not collect usage telemetry, keystrokes, or file contents. The only client-side analytics (Google Analytics) track anonymous page views, never payment data.

Server-side processing is minimal

The Cloudflare Pages Functions only handle authentication emails (via Resend) and Stripe webhooks. Your payment files never touch them.

Open source

The full codebase is on GitHub, so you can audit exactly what runs. No black boxes.

Architecture

  • Client — static Next.js app. XSD validation via libxml2 (WASM), CSV/Excel parsing, and XML generation all in-browser.
  • Backend — Cloudflare Pages Functions for Supabase auth emails (Resend) and Stripe webhooks only.
  • Database — Supabase stores accounts, subscription metadata, and your saved column mappings. Never payment files.