EasyxLab
Language: EN English

Studies / S1

Conformance of open-source Verifactu implementations

Do the XML records that open-source Verifactu implementations publish comply with Spain's rules?

Working draftPublished 2026-10-02 · Updated 2026-10-03

Abstract

Spain's Verifactu regime (RD 1007/2023, Orden HAC/1177/2024) requires invoicing software to emit hash-chained XML records. We searched GitHub systematically through its code and repository search APIs (1,008 repositories, 29,491 XML files), classified every file containing a Verifactu record marker before linting it, and audited the corpus with verifactu-lint 0.4.0, maintained by the authors. Only 63 third-party repositories publish such XML, and most of it does not claim to be a valid record: 81 of 191 unique files are templates, mostly copies of the AEAT's own documentation samples, whose hash fields literally read Huella or AAAA. Of the 35 files that do purport to be valid records, 10 (28.6%, 95% CI 16.3–45.1) contain at least one ERROR; 6 of 19 repositories (31.6%, 95% CI 15.4–54.0) publish at least one. The most frequent defect, in 5 of the 19 repositories, is a declared hash that does not match the one computed from the record's fields. All 22 ERROR findings were reviewed one by one by the LLM-based study agent, with hashes recomputed by an independent implementation: no false positive was found (0/22; the findings are not independent, and over the 12 distinct repository–rule situations the upper 95% bound is 24.3%). 34 of the 35 files hold a single record, so public XML examples cannot serve as a reference for the hash chain, and outside the instrument's own repository nobody publishes a deliberately invalid record.

Competing interests: the authors' organisation develops verifactu-lint and offers commercial Verifactu services.

Cite this study

Citation
EasyxLab (2026). Conformance of open-source Verifactu implementations. Study S1. EasyByte Hub S. Coop. Mad. https://github.com/easybytehub/easyxlab/tree/main/studies/s1-verifactu-conformance
BibTeX
@techreport{easyxlab_s1,
  title       = {Conformance of open-source Verifactu implementations},
  author      = {{EasyxLab}},
  institution = {EasyByte Hub S. Coop. Mad.},
  number      = {S1},
  year        = {2026},
  url         = {https://github.com/easybytehub/easyxlab/tree/main/studies/s1-verifactu-conformance}
}