Dine data, sikret i hjertet af Europa
Suverænt designet: baseret i Luxembourg, hostet i EU, og dine kundedata forlader aldrig EU-jurisdiktionen. Vi er transparente om vores sikkerhedsrejse og deler gerne detaljer.
Luxembourg-base, Europæisk styrke
Luxembourg-lederskab
Baseret i Luxembourg nyder vi godt af nogle af Europas stærkeste databeskyttelseslove, der giver yderligere sikkerhedslag ud over standard GDPR-krav.
EU-infrastruktur
Al databehandling sker inden for EU ved hjælp af højtilgængelige datacentre i Holland og Tyskland. Dine oplysninger forlader aldrig EU-jurisdiktionen.
Sådan beskytter vi dine data
Databeskyttelse
Kryptering
Alle data beskyttet under transport og hvile ved hjælp af industristandardkryptering
Netværkssikkerhed
Håndhævede sikkerhedspolitikker og firewall-beskyttelse
Adgangskontrol
Streng adgangsstyring og overvågning
Infrastrukturmodstandsdygtighed
Høj tilgængelighed
Redundante datacentre designet til at holde servicen tilgængelig
Overvågning
24/7 systemovervågning med automatiske alarmer
Backup & gendannelse
Flere backup-placeringer med omfattende katastrofegendannelsesplaner
Aktuel status
GDPR-compliant
Fuld overensstemmelse med EU's databeskyttelseskrav
Peppol-netværksmedlem
Officiel deltager i EU's e-faktureringsinfrastruktur
Juridisk compliance
Log-opbevaring og datahåndtering i overensstemmelse med lovkrav
I gang
ISO 27001
Udfører i øjeblikket gap-analyse som en del af vores certificeringsrejse
NIS2-direktivet
Den indledende vurdering er afsluttet, og vi implementerer nu politikker og sikkerhedstiltag under EU's cybersikkerhedsdirektiv
Vi tror på gennemsigtighed om vores sikkerhedsrejse. Vi opdaterer denne side efterhånden som vi opnår nye milepæle.
Kontroller vianvender i dag
Vi offentliggør kun det, vi kan dokumentere.
Håndtering af hændelser
Documented incident response plan
We maintain a written incident response plan that defines severity levels, assigns roles for detection and response, and sets out containment, eradication and recovery steps. It includes communication paths for notifying customers, authorities and CSIRTs.
Continuous automated monitoring
Production systems are monitored continuously rather than on a schedule. Alerting is automated, and runtime security policies detect unexpected behaviour on running workloads as well as at the network edge.
Centralised, tamper-resistant logging
Application access, authentication events, privileged activity, and changes to critical configuration and backup files are logged centrally. Archives are written to immutable, encrypted storage with a defined retention period so that records cannot be altered after the fact.
Independent availability monitoring
Availability is checked from outside our own infrastructure, by a monitoring system we run at a separate provider. If our primary environment fails, the system that notices is not part of it.
Event triage and classification
Suspicious events are assessed against criteria defined in advance to determine whether they are incidents and how severe they are. Logs are correlated as part of that assessment, and events are reclassified when new information emerges.
Security event reporting channel
Anyone can report a suspected security issue to security@invoro.lu. Reports reach the person responsible for incident response directly.
Post-incident review
After recovery we review what happened, identify the root cause, and feed the result back into our security measures rather than closing the incident and moving on.
Adgangsstyring
Single sign-on with multi-factor authentication
Access to production systems and internal tooling goes through a single identity provider that we operate ourselves, with multi-factor authentication required.
Role-based access control
Permissions are granted by role on a least-privilege basis, both for our own staff and for users within a customer account. Access is only granted to users who have been authenticated.
Identities tied to a single person
Every identity belongs to one named individual. Shared accounts are used only where there is no technical alternative, and identity lifecycle changes are logged.
Separate administrative accounts
System administration is performed with accounts dedicated to that purpose and separate credentials. Administrative privileges are individualised and kept as narrow as the task allows.
Sender-constrained API tokens
Application API access uses DPoP (RFC 9449), which binds a token to the client that requested it. A stolen token cannot be replayed from somewhere else.
Access rights are registered and logged
We keep a register of granted access rights, changes to them are authorised and logged, and access is modified or removed when someone changes role or leaves.
Controlled administrative access paths
Administration systems are reachable only over a controlled network path, are separated from application workloads, and require authentication and encryption in their own right.
Kryptografi
Encryption in transit
All connections to our services use TLS. Documents exchanged over the Peppol network use AS4 with signed and encrypted payloads.
Encryption at rest
Databases, persistent volumes and backup archives are encrypted at rest. Selected sensitive fields are additionally encrypted at application level, so they stay protected even with database access.
Centralised secret management
Credentials and keys are held in a dedicated secret management system with audited access and injected into workloads at runtime. Secrets are never stored in source code or container images.
Short-lived database credentials
Database logins are issued dynamically with a limited lifetime rather than being long-lived shared passwords, so a leaked credential expires on its own.
Key management and rotation
Key generation, distribution, storage, rotation, revocation and handling of compromised keys follow a defined approach, and key management activity is logged.
Asset management
Infrastructure defined as code
Our infrastructure is described in version-controlled configuration and deployed from it. What is running is therefore inventoried by construction, and every change has an author, a review and a history.
Asset classification
Assets are classified so that the strength of the protection applied to them, including cryptographic protection and authentication requirements, matches their sensitivity. Classifications are reviewed periodically.
Container images scanned before release
Every container image is scanned for known vulnerabilities as part of the build. Critical findings stop the release rather than being recorded and shipped.
Provider register
We keep a register of the third-party providers we rely on, recording what each one does, how critical it is, and what data it can reach. The providers that process data for our customers are published on this page.
Hvem behandler datapå dine vegne
Disse leverandører behandler data for vores erhvervskunder. Vi giver 30 dages varsel, før vi tilføjer eller udskifter en leverandør.
Sidst opdateret:
| Leverandør | Placering | Formål |
|---|---|---|
| Hetzner Online GmbH | Germany | Cloud infrastructure hosting and data storage |
| Impossible Cloud GmbH | Germany, storage in the Netherlands | Storage of encrypted backups and log archives |
| Mistral AI SAS | France | Extraction of structured fields from PDF documents you upload or receive |
| Lettermint B.V. | Netherlands | Delivery of transactional email |
Leverandører, vi bruger til egne formål, såsom fakturering, identitetsverifikation og sanktionsscreening, er anført i vores privatlivspolitik. Privatlivspolitik
Klare politikker, ingen overraskelser
Hvad vi indsamler
Kun de forretningsdata der er nødvendige for at behandle dine fakturaer og vedligeholde din konto. Ingen unødvendige personlige oplysninger.
- Forretningsfakturadata
- Kontolegitimationsoplysninger
- Servicebrugslogfiler
Hvordan vi beskytter det
Dine data er krypteret, overvåget og sikkerhedskopieret på tværs af flere EU-placeringer. Adgang er strengt kontrolleret og logget.
- Kryptering under overførsel og ved lagring
- Backups flere steder
- Adgangsovervågning
Dine rettigheder
Fulde GDPR-rettigheder gælder: adgang, korrektion, sletning og portabilitet. Kontakt os når som helst for at udøve disse rettigheder.
- Dataadgangsrettigheder
- Korrektion & sletning
- Dataportabilitet
Bygget til at holde din forretning kørende
Designet til høj tilgængelighed
Designet til høj tilgængelighed: flere datacentre, redundant infrastruktur og uafhængig ekstern overvågning.
Hændelsesrespons
Professionelle hændelsesresponsprocedurer er på plads, og vi tilstræber hurtigt at løse problemer der påvirker servicen.
Regelmæssig test
Katastrofegendannelses- og backup-systemer testes regelmæssigt for at sikre pålidelighed når du har brug for dem.
Sikkerhedsspørgsmål? Vi er her for at hjælpe
Uanset om du har brug for detaljeret teknisk dokumentation, udfyldte sikkerhedsspørgeskemaer eller vil diskutere specifikke compliance-krav, er vores team klar til at levere den information du har brug for.
Sikkerhedskontakt
For detaljeret sikkerhedsdokumentation, compliance-spørgeskemaer eller tekniske spørgsmål, kontakt vores sikkerhedsteam direkte.
- Teknisk sikkerhedsdokumentation
- Udfyldelse af sikkerhedsspørgeskema
- Diskussioner om compliance-krav
Generel support
For generelle spørgsmål om vores sikkerhedspraksis eller platformfunktioner.
- Generelle sikkerhedsspørgsmål
- Forespørgsler om platformfunktioner
- Implementeringsvejledning