In-region options
In-region processing options for UAE, Oman and Qatar workloads under Enterprise agreements; FTA reporting flows terminate at the authority's endpoints.
The controls behind the connector layer: encryption everywhere, strict tenant isolation, immutable audit logging, in-region processing where regulation expects it — and an honest roadmap instead of borrowed badges.
ERP to platform, platform to partner stack, platform to authority. The local bridge agent is outbound-only: no inbound ports, ever.
For stored invoice payloads and connector credentials. Secrets live in a managed vault — never in code, configuration files or logs.
One partner can never query, see or affect another's invoices — enforced in the architecture, not in a policy document.
Role-based access, MFA for all internal operator access, and optional IP allowlisting on partner API keys.
Every submission, validation result, delivery attempt and administrative action logged with timestamps — exportable for your own compliance reviews.
Encrypted automated backups with tested restore procedures, and a 99.9% uptime target monitored 24/7.
Residency requirements differ by market. Enterprise agreements support in-region processing options where your regulator or client contracts demand them.
In-region processing options for UAE, Oman and Qatar workloads under Enterprise agreements; FTA reporting flows terminate at the authority's endpoints.
GDPR applies in full — roles and subprocessors are covered in our privacy policy and DPAs.
MyInvois clearance traffic terminates at LHDN endpoints in Malaysia; data handling aligns with the Personal Data Protection Act 2010.
Found something? Report it to security@jinacode.systems — we acknowledge within two business days and keep you informed through remediation.
Data processing agreements are available on Enterprise agreements; the current subprocessor list is provided on request as part of any security review.
Our controls are aligned to ISO 27001 practices; formal certification is on the roadmap. We publish status honestly rather than displaying badges we don't hold — the same standard we apply to mandate dates.
This page summarizes our posture for evaluation. Full security documentation — architecture diagrams, policies, penetration-test summaries — is available under NDA via sales@jinacode.systems.
Yes — retained per the regulatory retention requirements of each market and your partner agreement, encrypted at rest with AES-256. Retention schedules and deletion procedures are documented in the agreement.
You and your clients. PeppolBridge processes invoice data as a processor under your instructions — ownership never transfers, and data is exportable throughout and at termination.
Please do. We support security questionnaires and provide architecture documentation, policies and pen-test summaries under NDA. Send yours to sales@jinacode.systems.
Every webhook payload is HMAC-signed with a per-endpoint secret and timestamped for replay protection. The developer hub covers verification.
We'd rather answer two hundred questions up front than surprise you later. That's the whole philosophy.