Shivoraai·E-InvoicingOman
Home Fawtara E-Invoicing ERP Integration SAP Integration Security Solutions Industries Pricing How It Works FAQ About Shivoraai Contact
Security

Controls you can verify, not a promise to take on faith

We don't say "100% secure," "hack-proof" or "guaranteed" — no honest provider can. What follows are the actual controls, processes and architecture decisions behind our integration layer.

Technical controls

What's actually in place

TLS in transit, encryption at rest
Multi-factor authentication (MFA)
Role-based access control (RBAC)
Least-privilege access model
Secure API authentication, OAuth where appropriate
Secure API key handling & secrets management
Audit logs & access logging
Secure, tested backups
Disaster recovery & business continuity planning
Active monitoring & alerting
Vulnerability & patch management
Secure software development lifecycle (SDLC)
Documented incident response process
Periodic access reviews
Dev / UAT / production environment isolation
Penetration testing on the integration platform
We publish this list because it's checkable, not because it's exhaustive. Ask us for the detail behind any item — we'd rather explain a control than assert one.
Data privacy

We minimise what we hold, on purpose

We don't store data simply because a system is capable of storing it. For every category of data that passes through our integration layer, we define what's collected, why, where it's processed, whether it's temporarily stored or just passed through, who can access it, where it's hosted, how it's protected, how it's backed up, and how long it's retained before deletion.

What's collected

Only the invoice, tax and master data fields required to validate and transmit your e-invoices — nothing extra by default.

Retention & deletion

Defined retention periods per data category, with secure deletion once retention requirements are met.

Access

Access is limited to what a given role needs to do its job — reviewed periodically, not set once and forgotten.

Environment separation

Production is never the testing ground

Development, test/UAT and production environments are kept properly separated throughout every implementation. Changes are validated in test/UAT before they ever touch a live invoicing path.

Security questionnaire on request

If your IT or procurement team needs a formal security questionnaire completed as part of vendor onboarding, we provide one — ask us via Contact.

Want the detail behind any control?

Ask us directly — we'd rather show the documentation than just claim it.