Your data, secured in the heart of Europe
Sovereign by design: based in Luxembourg, hosted in the EU, and your customer data never leaves EU jurisdiction. We're transparent about our security journey and happy to share details.
Luxembourg base, European strength
Luxembourg Leadership
Based in Luxembourg, we benefit from some of Europe's strongest data protection laws, providing additional layers of security beyond standard GDPR requirements.
EU Infrastructure
All data processing occurs within the European Union using high-availability data centers in the Netherlands and Germany. Your information never leaves EU jurisdiction.
How we protect your data
Data Protection
Encryption
All data protected in transit and at rest using industry-standard encryption
Network Security
Enforced security policies and firewall protection
Access Controls
Strict access management and monitoring
Infrastructure Resilience
High Availability
Redundant data centers designed to keep the service available
Monitoring
24/7 system monitoring with automated alerting
Backup & Recovery
Multiple backup locations with comprehensive disaster recovery plans
Current Status
GDPR Compliant
Full alignment with EU data protection requirements
Peppol Network Member
Official participant in the EU e-invoicing infrastructure
Legal Compliance
Log retention and data handling aligned with regulatory requirements
In Progress
ISO 27001
Currently conducting gap analysis as part of our certification journey
NIS2 Directive
Initial assessment complete, now implementing policies and hardening measures under the EU cybersecurity directive
We believe in transparency about our security journey. We'll update this page as we achieve new milestones.
Controls weoperate today
We publish only what we can evidence.
Incident handling
Documented incident response plan
We maintain a written incident response plan that defines severity levels, assigns roles for detection and response, and sets out containment, eradication and recovery steps. It includes communication paths for notifying customers, authorities and CSIRTs.
Continuous automated monitoring
Production systems are monitored continuously rather than on a schedule. Alerting is automated, and runtime security policies detect unexpected behaviour on running workloads as well as at the network edge.
Centralised, tamper-resistant logging
Application access, authentication events, privileged activity, and changes to critical configuration and backup files are logged centrally. Archives are written to immutable, encrypted storage with a defined retention period so that records cannot be altered after the fact.
Independent availability monitoring
Availability is checked from outside our own infrastructure, by a monitoring system we run at a separate provider. If our primary environment fails, the system that notices is not part of it.
Event triage and classification
Suspicious events are assessed against criteria defined in advance to determine whether they are incidents and how severe they are. Logs are correlated as part of that assessment, and events are reclassified when new information emerges.
Security event reporting channel
Anyone can report a suspected security issue to security@invoro.lu. Reports reach the person responsible for incident response directly.
Post-incident review
After recovery we review what happened, identify the root cause, and feed the result back into our security measures rather than closing the incident and moving on.
Access management
Single sign-on with multi-factor authentication
Access to production systems and internal tooling goes through a single identity provider that we operate ourselves, with multi-factor authentication required.
Role-based access control
Permissions are granted by role on a least-privilege basis, both for our own staff and for users within a customer account. Access is only granted to users who have been authenticated.
Identities tied to a single person
Every identity belongs to one named individual. Shared accounts are used only where there is no technical alternative, and identity lifecycle changes are logged.
Separate administrative accounts
System administration is performed with accounts dedicated to that purpose and separate credentials. Administrative privileges are individualised and kept as narrow as the task allows.
Sender-constrained API tokens
Application API access uses DPoP (RFC 9449), which binds a token to the client that requested it. A stolen token cannot be replayed from somewhere else.
Access rights are registered and logged
We keep a register of granted access rights, changes to them are authorised and logged, and access is modified or removed when someone changes role or leaves.
Controlled administrative access paths
Administration systems are reachable only over a controlled network path, are separated from application workloads, and require authentication and encryption in their own right.
Cryptography
Encryption in transit
All connections to our services use TLS. Documents exchanged over the Peppol network use AS4 with signed and encrypted payloads.
Encryption at rest
Databases, persistent volumes and backup archives are encrypted at rest. Selected sensitive fields are additionally encrypted at application level, so they stay protected even with database access.
Centralised secret management
Credentials and keys are held in a dedicated secret management system with audited access and injected into workloads at runtime. Secrets are never stored in source code or container images.
Short-lived database credentials
Database logins are issued dynamically with a limited lifetime rather than being long-lived shared passwords, so a leaked credential expires on its own.
Key management and rotation
Key generation, distribution, storage, rotation, revocation and handling of compromised keys follow a defined approach, and key management activity is logged.
Asset management
Infrastructure defined as code
Our infrastructure is described in version-controlled configuration and deployed from it. What is running is therefore inventoried by construction, and every change has an author, a review and a history.
Asset classification
Assets are classified so that the strength of the protection applied to them, including cryptographic protection and authentication requirements, matches their sensitivity. Classifications are reviewed periodically.
Container images scanned before release
Every container image is scanned for known vulnerabilities as part of the build. Critical findings stop the release rather than being recorded and shipped.
Provider register
We keep a register of the third-party providers we rely on, recording what each one does, how critical it is, and what data it can reach. The providers that process data for our customers are published on this page.
Who processes dataon your behalf
These providers process data for our business customers. We give 30 days notice before adding or replacing any of them.
Last updated:
| Provider | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany | Cloud infrastructure hosting and data storage |
| Impossible Cloud GmbH | Germany, storage in the Netherlands | Storage of encrypted backups and log archives |
| Mistral AI SAS | France | Extraction of structured fields from PDF documents you upload or receive |
| Lettermint B.V. | Netherlands | Delivery of transactional email |
Providers we use for our own purposes, such as billing, identity verification and sanctions screening, are listed in our Privacy Policy. Privacy Policy
Clear policies, no surprises
What We Collect
Only the business data necessary to process your invoices and maintain your account. No unnecessary personal information.
- Business invoice data
- Account credentials
- Service usage logs
How We Protect It
Your data is encrypted, monitored, and backed up across multiple EU locations. Access is strictly controlled and logged.
- Encryption in transit and at rest
- Multi-location backups
- Access monitoring
Your Rights
Full GDPR rights apply: access, correction, deletion, and portability. Contact us anytime to exercise these rights.
- Data access rights
- Correction & deletion
- Data portability
Built to keep your business running
High Availability by Design
Designed for high availability: multi-datacenter, redundant infrastructure with independent external monitoring.
Incident Response
Professional incident response procedures are in place, and we aim to resolve any issues affecting service quickly.
Regular Testing
Disaster recovery and backup systems are regularly tested to ensure reliability when you need them.
Security questions? We're here to help
Whether you need detailed technical documentation, security questionnaires completed, or want to discuss specific compliance requirements, our team is ready to provide the information you need.
Security Contact
For detailed security documentation, compliance questionnaires, or technical questions, contact our security team directly.
- Technical security documentation
- Security questionnaire completion
- Compliance requirement discussions
General Support
For general questions about our security practices or platform features.
- General security questions
- Platform feature inquiries
- Implementation guidance