Ironfang builds on open-source software and on public invoice standards. This page lists what Ironfang uses, the licence each is offered under, the notices its authors ask to be kept, and where its source code is published. It covers the engines that validate invoices for Ironfang Finance, the code Ironfang Analytics sends to browsers, and the code and font this website sends to yours. Other services will be added as their review is completed.
Acknowledgements
Ironfang Finance is an application of the European standard on electronic invoicing, EN 16931-1:2017 and CEN/TS 16931-2:2017. Its use of that publication, including the rule texts it shows in validation results and rule explanations, is made with the permission of CEN and DIN as the owners of the copyright. CEN and DIN assume no liability with regard to the use of the content and the use of such derivative applications, and give no express or implied warranties for any use of them. In case of doubt, consult the publications of DIN (EN 16931-1:2017-06, CEN/TS 16931-2:2017-06), which provide the official text of the European standard.
This statement follows the conditions under which DIN permits the free use of these parts of the standard, as published in FeRD's disclaimer and rights of use.
The EN 16931 validation artefacts are licensed under the European Union Public Licence (EUPL) version 1.2. Their exact source, and how the copies Ironfang runs were produced from it, are set out under Source code and changes.
Names such as Peppol, XRechnung, ZUGFeRD, Factur-X, PHIVE, Saxon and veraPDF identify the standards and software Ironfang uses. Their owners have not certified, endorsed or reviewed Ironfang or its services, and none of them warrants the results Ironfang gives for your invoices.
Invoice standards and validation rules
Ironfang Finance checks invoices by executing the official rule sets of each standard, unchanged. These are the rules and schemas it runs, the exact releases, and where their source is published.
EN 16931 validation artefacts
The business rules of the European e-invoicing standard (the BR-* rules) for UBL and UN/CEFACT CII invoices.
- Used for
- Ironfang Finance: every Peppol BIS Billing 3 and XRechnung validation.
- Version
- Release 1.3.16 (tag validation-1.3.16)
- Licence
- EUPL-1.2
- Notice
- CEN/TC 434. "Licensed under European Union Public Licence (EUPL) version 1.2."
- Changes
- None by Ironfang. XRechnung validation runs the rules as compiled by KoSIT and Peppol validation runs them as compiled by OpenPeppol, both from this release: see Source code and changes.
Peppol BIS Billing 3 rules
OpenPeppol's additional rules for invoices and credit notes exchanged over the Peppol network (the PEPPOL-EN16931-* rules).
- Used for
- Ironfang Finance: every Peppol BIS Billing 3 validation.
- Version
- Release 2026.5 (BIS Billing 3.0.21), as packaged by phive-rules-peppol 4.5.5 and 4.5.6
- Licence
- No licence file is published with these rules. Ironfang executes them inside its service and does not redistribute them.
- Notice
- OpenPeppol AISBL.
- Changes
- None by Ironfang.
XRechnung Schematron
The German CIUS rules (the BR-DE-* rules) that XRechnung adds to EN 16931.
- Used for
- Ironfang Finance: every XRechnung 3.0.2 validation.
- Version
- 2.6.0, within the XRechnung 3.0.2 bundle of 31 August 2026
- Licence
- Apache-2.0
- Notice
- Koordinierungsstelle für IT-Standards (KoSIT).
- Changes
- None by Ironfang. Ironfang runs the compiled rules exactly as KoSIT ships them in the validator configuration below.
KoSIT validator configuration for XRechnung
The official configuration of the KoSIT validator: which rules apply to which document, and the level at which each rule decides acceptance.
- Used for
- Ironfang Finance: every XRechnung 3.0.2 validation applies its official rule levels.
- Version
- Release 2026-08-31 (tag v2026-08-31)
- Licence
- Apache-2.0
- Notice
- KoSIT XML-Validator Configuration for XRechnung. Copyright 2020 Koordinierungsstelle für IT-Standards. This product includes software developed by Coordination Office for IT-Standards (http://www.xoev.de/).
- Changes
- None. Ironfang reads the official levels from its unmodified scenarios.xml.
ZUGFeRD / Factur-X profile rules
The schemas and rules of the Franco-German hybrid invoice standard, for its MINIMUM, BASIC WL, BASIC, EN 16931 and EXTENDED profiles.
- Used for
- Installed in Ironfang Finance. ZUGFeRD and Factur-X validation is not yet offered.
- Version
- ZUGFeRD 2.5.2 / Factur-X 1.09.2, as packaged by phive-rules-zugferd 4.5.6
- Licence
- Apache-2.0, as FeRD states: "For the use of the ZUGFeRD Technical Artifacts (Schemata and Schematron) the Apache 2.0 license conditions apply." Most of the EN 16931 profile's business rules are the CEN rules above, so Ironfang also treats that profile as covered by the EUPL 1.2 and links its source.
- Notice
- FeRD (Forum elektronische Rechnung Deutschland) and FNFE-MPE.
- Changes
- None by Ironfang. The compiled rules and code lists are byte-identical to those in FeRD's own ZUGFeRD 2.5.2 package, which also carries their Schematron source; PHIVE renames the schema files the profiles import.
OASIS UBL 2.1 schemas
The XML schemas that define the structure of UBL invoices and credit notes.
- Used for
- Ironfang Finance: the schema check of every Peppol BIS Billing 3 and XRechnung UBL validation.
- Version
- UBL 2.1, as distributed in ph-ubl21 10.2.1 and in the KoSIT XRechnung bundle of 31 August 2026
- Licence
- Published by OASIS under its copyright; no separate licence file accompanies the schemas as used. Ironfang uses them inside its service and does not redistribute them.
- Notice
- OASIS Open.
- Changes
- None.
UN/CEFACT Cross Industry Invoice schemas
The XML schemas that define the structure of CII invoices.
- Used for
- Ironfang Finance: the schema check of every XRechnung CII validation (D16B). The ZUGFeRD / Factur-X profiles carry reduced D22B schemas, not yet offered.
- Version
- D16B, as distributed in the KoSIT XRechnung bundle of 31 August 2026; D22B profile schemas from phive-rules-zugferd 4.5.6
- Licence
- Published by UNECE / UN/CEFACT; no separate licence file accompanies the schemas as used. Ironfang uses them inside its service and does not redistribute them.
- Notice
- United Nations Economic Commission for Europe (UNECE), UN/CEFACT.
- Changes
- None.
veraPDF PDF/A validation profiles
The machine-readable PDF/A-3 and PDF/A-4f rules veraPDF checks a PDF against.
- Used for
- Ironfang Finance: the PDF inspector, which reads hybrid invoices for the free invoice extraction tool. Hybrid PDF validation is not yet offered.
- Version
- Profiles PDFA-3A, PDFA-3B, PDFA-3U and PDFA-4F from veraPDF 1.30.2
- Licence
- MPL-2.0 (veraPDF is offered under GPL-3.0-or-later OR MPL-2.0-or-later; Ironfang uses it under MPL-2.0)
- Notice
- veraPDF Consortium.
- Changes
- None.
Validation engine software
The Java libraries inside the engines that validate invoices for Ironfang Finance: the Peppol validator (every generation still serving a release), the XML worker for XRechnung and ZUGFeRD / Factur-X XML, and the PDF inspector. Every library is the unmodified artefact published on Maven Central. The engine notices file lists all 76 jars with their hashes and reproduces every licence and notice file they carry; each jar's source is its -sources.jar on Maven Central.
PHIVE and phive-rules
Runs the validation rule sets and reports their findings.
- Used for
- Every Ironfang Finance validation engine.
- Version
- phive-api and phive-xml 12.1.0; phive-rules-api and phive-rules-peppol 4.5.5 and 4.5.6; phive-rules-shared 1.0.0
- Licence
- Apache-2.0
- Notice
- Philip Helger. "This product includes Open Source Software developed by Philip Helger - https://www.helger.com/"
- Changes
- None.
ph-commons, ph-schematron, ph-ubl and related libraries
The XML, Schematron and UBL support libraries PHIVE is built on.
- Used for
- Every Ironfang Finance validation engine (ph-ubl and ph-xsds in the Peppol validator only).
- Version
- ph-commons 12.3.3 (and ph-jaxb-adapter 12.1.0), ph-schematron 10.0.0, ph-ubl 10.2.1, ph-xsds 4.1.0, ph-diver-api 4.2.1, ph-telemetry 1.0.1
- Licence
- Apache-2.0
- Notice
- Philip Helger. Their NOTICE files also credit phloc systems, Findbugs (JSR 305 annotations), Robert Harder and the Apache Software Foundation; all are reproduced in the engine notices.
- Changes
- None.
Saxon-HE
The XSLT processor that executes the compiled validation rules.
- Used for
- Every Ironfang Finance validation engine: 12.10 in the Peppol validator and the XML worker, 12.8 in the PDF inspector.
- Version
- 12.10 and 12.8
- Licence
- MPL-2.0 (the source is marked "Incompatible With Secondary Licenses")
- Notice
- Copyright (c) 2018-2023 Saxonica Limited. Saxon includes code by James Clark; his notice is reproduced in the engine notices.
- Changes
- None.
SchXslt and SchXslt2
Compile Schematron rules to XSLT where PHIVE needs it.
- Used for
- The Peppol validator and the XML worker.
- Version
- SchXslt 1.10.1, SchXslt2 1.11.1
- Licence
- MIT
- Notice
- David Maus.
- Changes
- None.
Jakarta XML Binding, Jakarta Activation and their Eclipse implementations
Read and write XML as Java objects.
- Used for
- Every Ironfang Finance validation engine.
- Version
- Jakarta XML Binding API 4.0.5 and 4.0.0, Jakarta Activation API 2.1.4 and 2.1.0, Eclipse Implementation of JAXB 4.0.9 and 4.0.2, Eclipse Angus Activation 2.0.3 and 2.0.0, istack-commons 4.1.2 and 4.1.1
- Licence
- BSD-3-Clause (Eclipse Distribution License 1.0)
- Notice
- Oracle and/or its affiliates, and the Eclipse Foundation projects named. Their NOTICE files are reproduced in the engine notices.
- Changes
- None.
XML Resolver
Resolves the schemas and stylesheets the rules import, from local copies.
- Used for
- Every Ironfang Finance validation engine.
- Version
- 5.3.3
- Licence
- Apache-2.0
- Notice
- Copyright 2015-2023 Norman Walsh and contributors.
- Changes
- None.
Apache PDFBox
Reads PDF files: pages, embedded files and metadata.
- Used for
- The PDF inspector.
- Version
- PDFBox, PDFBox IO and FontBox 3.0.8
- Licence
- Apache-2.0
- Notice
- Apache PDFBox. Copyright 2002-2026 The Apache Software Foundation. This product includes software developed at The Apache Software Foundation (http://www.apache.org/). Its NOTICE files, which also credit the Adobe Glyph List and Unicode data, are reproduced in the engine notices.
- Changes
- None.
veraPDF
Checks PDF/A conformance.
- Used for
- The PDF inspector.
- Version
- core, feature-reporting, metadata-fixer, parser, pdf-model and validation-model 1.30.2 (Jakarta builds), and verapdf-xmp-core 1.30.2
- Licence
- MPL-2.0 (elected from GPL-3.0-or-later OR MPL-2.0-or-later); verapdf-xmp-core BSD-3-Clause
- Notice
- Copyright (c) 2015-2026, veraPDF Consortium. verapdf-xmp-core derives from the Adobe XMP Toolkit.
- Changes
- None.
Mozilla Rhino
A JavaScript engine veraPDF uses to evaluate its profile rules.
- Used for
- The PDF inspector.
- Version
- 1.7.15.1
- Licence
- MPL-2.0, with notices for portions from the Google V8 engine and Sun Microsystems
- Notice
- Mozilla Foundation. Its NOTICE files are reproduced in the engine notices.
- Changes
- None.
Jackson
Reads and writes JSON inside veraPDF.
- Used for
- The PDF inspector.
- Version
- jackson-core and jackson-databind 2.21.7, jackson-annotations 2.21
- Licence
- Apache-2.0
- Notice
- Copyright 2007-, Tatu Saloranta. Its NOTICE files are reproduced in the engine notices.
- Changes
- None.
Smaller libraries
Logging, annotations and XML streaming used by the libraries above.
- Used for
- SLF4J API and JSpecify: the Peppol validator and the XML worker. Commons Logging and StAX-Utils: the PDF inspector.
- Version
- SLF4J API 2.0.18, JSpecify 1.0.0, Apache Commons Logging 1.4.0, StAX-Utils 20070216
- Licence
- SLF4J API: MIT. JSpecify: Apache-2.0. Commons Logging: Apache-2.0. StAX-Utils: BSD-3-Clause
- Notice
- QOS.ch Sarl (SLF4J); the JSpecify project; The Apache Software Foundation (Commons Logging); Christian Niles, unit12.net (StAX-Utils).
- Changes
- None.
Ironfang Analytics
Ironfang Analytics ships two pieces of browser code: the recorder, which customers load on their own websites, and the replay player on replay.ironfang.uk. Every release of each (recorder 0.1.0 to 0.3.0, player 0.1.0 to 0.2.0) bundles the same open-source packages, unmodified. Each file begins with a notice naming them; the analytics notices file reproduces their licences in full.
rrweb
Records the changes to a web page as they happen, and plays them back.
- Used for
- The recorder bundles @rrweb/record, rrweb, rrweb-snapshot, @rrweb/types and @rrweb/utils. The replay player bundles rrweb-player, @rrweb/replay, @rrweb/packer, rrdom and the same core packages.
- Version
- 2.1.6 (every package)
- Licence
- MIT
- Notice
- Copyright (c) 2018 Contributors (https://github.com/rrweb-io/rrweb/graphs/contributors)
- Changes
- None. The rrweb packages publish no licence file of their own; the text is taken from rrweb's repository at the release.
Svelte runtime
The component runtime rrweb-player is built with.
- Used for
- The replay player, compiled into rrweb-player.
- Version
- 4.2.18, the version in rrweb's lockfile for its 2.1.6 release
- Licence
- MIT
- Notice
- Copyright (c) 2016-23 [these people](https://github.com/sveltejs/svelte/graphs/contributors)
- Changes
- None.
Libraries inside the replay player
A state machine, an event emitter, base64 and compression helpers, and a CSS parser that rrweb-player depends on.
- Used for
- The replay player.
- Version
- @xstate/fsm 1.6.5, mitt 3.0.1, base64-arraybuffer 1.0.2, fflate 0.4.9, postcss 8.5.28
- Licence
- MIT (each)
- Notice
- Copyright (c) 2015 David Khourshid (@xstate/fsm); Copyright (c) 2021 Jason Miller (mitt); Copyright (c) 2012 Niklas von Hertzen (base64-arraybuffer); Copyright (c) 2020 Arjun Barrett (fflate); Copyright 2013 Andrey Sitnik (postcss).
- Changes
- None.
This website
ironfang.uk sends your browser the code of 28 open-source packages, bundled and minified, and the DM Sans typeface. The list below is produced from the build itself, so it matches what is served. The website notices file reproduces each package's licence and the typeface's licence in full.
- React (react 19.2.8, react-dom 19.2.8, scheduler 0.27.0, use-sync-external-store 1.6.0): MIT. Meta Platforms, Inc. and affiliates.
- TanStack Router and Start (@tanstack/history 1.162.1, @tanstack/react-router 1.170.32, @tanstack/react-start 1.168.49, @tanstack/react-start-client 1.168.30, @tanstack/react-store 0.9.3, @tanstack/router-core 1.171.27, @tanstack/start-client-core 1.170.27, @tanstack/store 0.9.3): MIT. Tanner Linsley.
- OpenTelemetry for JavaScript (@opentelemetry/api 1.9.1, @opentelemetry/core 2.11.0, @opentelemetry/exporter-trace-otlp-http 0.222.0, @opentelemetry/otlp-exporter-base 0.222.0, @opentelemetry/otlp-transformer 0.222.0, @opentelemetry/resources 2.11.0, @opentelemetry/sdk-trace 2.11.0, @opentelemetry/sdk-trace-base 2.11.0, @opentelemetry/sdk-trace-web 2.11.0, @opentelemetry/semantic-conventions 1.43.0): Apache-2.0. The OpenTelemetry Authors.
- Zod (zod 4.5.1): MIT. Colin McDonnell.
- Seroval (seroval 1.6.4, seroval-plugins 1.6.4): MIT. Alexis Munsayac.
- class-variance-authority (class-variance-authority 0.7.1): Apache-2.0. Joe Bell.
- clsx (clsx 2.1.1): MIT. Luke Edwards.
- cookie-es (cookie-es 3.1.1): MIT. Pooya Parsa; Roman Shtylman; Douglas Christopher Wilson; Nathan Friedly.
DM Sans
The typeface of this website.
- Used for
- Served to your browser as a Latin subset of the variable font (WOFF2).
- Version
- 4.004
- Licence
- OFL-1.1 (SIL Open Font License 1.1)
- Notice
- Copyright 2014 The DM Sans Project Authors (https://github.com/googlefonts/dm-fonts)
- Changes
- The file served is the Latin subset of the font, which the licence counts as a Modified Version and permits. No glyph is redrawn and the name is unchanged, as DM Sans has no Reserved Font Name.
Source code and changes
No software or rule set on this page is modified. Each is used exactly as its publisher released it; Ironfang's own code runs them but does not change them. The one altered file is the typeface, served as a Latin subset as described above.
EN 16931 validation artefacts 1.3.16
The editable source is the Schematron published by CEN/TC 434 in release validation-1.3.16 (commit b6c9e06). Its two release archives carry the Schematron and a compiled form:
- en16931-ubl-1.3.16.zip, SHA-256
bafada015efbc5248bf5e05ad2191e1d9833ef96e9dd5f4bce420a747342da85 - en16931-cii-1.3.16.zip, SHA-256
1cd53cb8a84d38aedc82c0caede217da983a7934dd663f793a092fd66443c561
Ironfang runs the rules as compiled by the publishers of each specification:
- XRechnung, UBL: EN16931-UBL-validation.xsl, compiled by KoSIT, SHA-256
759f2d2e830c7fd1d5a6e8b4f61e5dbafc7a7805862c4ae1c749eeac6adde698 - XRechnung, CII: EN16931-CII-validation.xsl, compiled by KoSIT, SHA-256
0911e927f13f9ae2cdc7f973643f27bf0ad3c5da02483c04a5b8a47eb4822199 - Peppol BIS Billing 3: CEN-EN16931-UBL.xslt, compiled by OpenPeppol, SHA-256
a8a54aef3699057a3820cd2ebcac8ea3c364a6ebaf4a237e62064a5bc2877c4a
KoSIT compiles EN16931-UBL-validation.sch and EN16931-CII-validation.sch from the archives above with SchXslt 1.10.1 on Saxon-HE 12.8, as its build file for release 2026-08-31 sets out. On 25 September 2026 Ironfang compiled both files the same way and obtained KoSIT's output byte for byte, apart from the timestamp the compiler records:
java -cp Saxon-HE-12.8.jar:xmlresolver-5.3.3.jar:xmlresolver-5.3.3-data.jar \
net.sf.saxon.Transform -s:schematron/EN16931-UBL-validation.sch \
-xsl:'jar:file:schxslt-1.10.1.jar!/xslt/2.0/pipeline-for-svrl.xsl'OpenPeppol compiled CEN-EN16931-UBL.xslt for Peppol BIS Billing 3 release 2026.5 from CEN-EN16931-UBL.sch, which is byte-identical to schematron/preprocessed/EN16931-UBL-validation-preprocessed.sch in the UBL archive above. The same compiled file ships in phive-rules-peppol 4.5.5 and 4.5.6. Ironfang has not reproduced OpenPeppol's compilation independently.
Other rules and software
The source of every other rule set is linked from its entry above, at the tag or commit Ironfang runs. The source of every Java library is the -sources.jar published beside it on Maven Central; the engine notices file links each one. The source of each browser package, on this website and in Ironfang Analytics, is published on npm at the version listed.
Licence texts and notices
Full licence texts and notice files, reproduced as their authors publish them. Each is plain text.
- Validation rules: the EUPL 1.2 text of the EN 16931 artefacts, the KoSIT NOTICE and licences, and the phive-rules-zugferd NOTICE and licence.
- Validation engines: all 76 Java libraries with their Maven coordinates, SHA-256 and source, and every licence and notice file they carry.
- Ironfang Analytics: the licence of every package in the recorder and the replay player, including rrweb and the Svelte runtime.
- This website: the licence of each package sent to your browser, and the SIL Open Font License of DM Sans.
The licences as published by their stewards: EUPL 1.2, Apache License 2.0, Mozilla Public License 2.0, SIL Open Font License 1.1.
Corrections
If something here is missing or wrong, please tell us through the contact form and we will correct it.
