Controls you can verify, not a promise to take on faith
We don't say "100% secure," "hack-proof" or "guaranteed" — no honest provider can. What follows are the actual controls, processes and architecture decisions behind our integration layer.
What's actually in place
We minimise what we hold, on purpose
We don't store data simply because a system is capable of storing it. For every category of data that passes through our integration layer, we define what's collected, why, where it's processed, whether it's temporarily stored or just passed through, who can access it, where it's hosted, how it's protected, how it's backed up, and how long it's retained before deletion.
What's collected
Only the invoice, tax and master data fields required to validate and transmit your e-invoices — nothing extra by default.
Retention & deletion
Defined retention periods per data category, with secure deletion once retention requirements are met.
Access
Access is limited to what a given role needs to do its job — reviewed periodically, not set once and forgotten.
Production is never the testing ground
Development, test/UAT and production environments are kept properly separated throughout every implementation. Changes are validated in test/UAT before they ever touch a live invoicing path.
Security questionnaire on request
If your IT or procurement team needs a formal security questionnaire completed as part of vendor onboarding, we provide one — ask us via Contact.
Want the detail behind any control?
Ask us directly — we'd rather show the documentation than just claim it.