Studies / S1
Conformance of open-source Verifactu implementations
Do the XML records that open-source Verifactu implementations publish comply with Spain's rules?
Abstract
Spain's Verifactu regime (RD 1007/2023, Orden HAC/1177/2024) requires invoicing software to emit hash-chained XML records. We searched GitHub systematically through its code and repository search APIs (1,008 repositories, 29,491 XML files), classified every file containing a Verifactu record marker before linting it, and audited the corpus with verifactu-lint 0.4.0, maintained by the authors. Only 63 third-party repositories publish such XML, and most of it does not claim to be a valid record: 81 of 191 unique files are templates, mostly copies of the AEAT's own documentation samples, whose hash fields literally read Huella or AAAA. Of the 35 files that do purport to be valid records, 10 (28.6%, 95% CI 16.3–45.1) contain at least one ERROR; 6 of 19 repositories (31.6%, 95% CI 15.4–54.0) publish at least one. The most frequent defect, in 5 of the 19 repositories, is a declared hash that does not match the one computed from the record's fields. All 22 ERROR findings were reviewed one by one by the LLM-based study agent, with hashes recomputed by an independent implementation: no false positive was found (0/22; the findings are not independent, and over the 12 distinct repository–rule situations the upper 95% bound is 24.3%). 34 of the 35 files hold a single record, so public XML examples cannot serve as a reference for the hash chain, and outside the instrument's own repository nobody publishes a deliberately invalid record.
Competing interests: the authors' organisation develops verifactu-lint and offers commercial Verifactu services.
Cite this study
EasyxLab (2026). Conformance of open-source Verifactu implementations. Study S1. EasyByte Hub S. Coop. Mad. https://github.com/easybytehub/easyxlab/tree/main/studies/s1-verifactu-conformance@techreport{easyxlab_s1,
title = {Conformance of open-source Verifactu implementations},
author = {{EasyxLab}},
institution = {EasyByte Hub S. Coop. Mad.},
number = {S1},
year = {2026},
url = {https://github.com/easybytehub/easyxlab/tree/main/studies/s1-verifactu-conformance}
}