Home/Security
Security questionnaires welcome — documentation under NDA

Invoice data is tax data. We treat it that way.

The controls behind the connector layer: encryption everywhere, strict tenant isolation, immutable audit logging, in-region processing where regulation expects it — and an honest roadmap instead of borrowed badges.

01 Controls

Six controls, no hand-waving.

In transit
TLS 1.2+ everywhere

ERP to platform, platform to partner stack, platform to authority. The local bridge agent is outbound-only: no inbound ports, ever.

At rest
AES-256

For stored invoice payloads and connector credentials. Secrets live in a managed vault — never in code, configuration files or logs.

Isolation
Strict per-partner tenancy

One partner can never query, see or affect another's invoices — enforced in the architecture, not in a policy document.

Access
Least privilege + MFA

Role-based access, MFA for all internal operator access, and optional IP allowlisting on partner API keys.

Audit
Immutable logging

Every submission, validation result, delivery attempt and administrative action logged with timestamps — exportable for your own compliance reviews.

Continuity
Rehearsed recovery

Encrypted automated backups with tested restore procedures, and a 99.9% uptime target monitored 24/7.

02 Data residency

Processed where regulation expects it.

Residency requirements differ by market. Enterprise agreements support in-region processing options where your regulator or client contracts demand them.

UAE & GCC

In-region options

In-region processing options for UAE, Oman and Qatar workloads under Enterprise agreements; FTA reporting flows terminate at the authority's endpoints.

European Union

EU processing for Belgian workloads

GDPR applies in full — roles and subprocessors are covered in our privacy policy and DPAs.

Malaysia

PDPA-aligned handling

MyInvois clearance traffic terminates at LHDN endpoints in Malaysia; data handling aligns with the Personal Data Protection Act 2010.

03 Responsible practices

The parts most vendors gloss over.

DISCLOSURE

Vulnerability disclosure

Found something? Report it to security@jinacode.systems — we acknowledge within two business days and keep you informed through remediation.

SUBPROCESSORS

Subprocessors & DPAs

Data processing agreements are available on Enterprise agreements; the current subprocessor list is provided on request as part of any security review.

ROADMAP

Certifications roadmap

Our controls are aligned to ISO 27001 practices; formal certification is on the roadmap. We publish status honestly rather than displaying badges we don't hold — the same standard we apply to mandate dates.

This page summarizes our posture for evaluation. Full security documentation — architecture diagrams, policies, penetration-test summaries — is available under NDA via sales@jinacode.systems.

04 Security FAQ

What security teams ask first.

Yes — retained per the regulatory retention requirements of each market and your partner agreement, encrypted at rest with AES-256. Retention schedules and deletion procedures are documented in the agreement.

You and your clients. PeppolBridge processes invoice data as a processor under your instructions — ownership never transfers, and data is exportable throughout and at termination.

Please do. We support security questionnaires and provide architecture documentation, policies and pen-test summaries under NDA. Send yours to sales@jinacode.systems.

Every webhook payload is HMAC-signed with a per-endpoint secret and timestamped for replay protection. The developer hub covers verification.

05 Due diligence

Send us your security questionnaire.

We'd rather answer two hundred questions up front than surprise you later. That's the whole philosophy.