Norvae

Security & trust

Your invoicing data, protected to the highest standard

E-invoicing sits at the heart of your business. At Norvae, security, confidentiality and compliance are not options — they are central to how the product is designed.

Our commitments

GDPR by design

Minimised data, explicit purposes, traceable consent. We only collect what your compliance requires.

Hosting in the European Union

Your data is hosted and processed within the EU, with no unframed transfer outside this area.

Evidential archiving

Timestamped, tamper-evident and compliant retention of your invoices for the required legal period.

Per-client isolation

Multi-tenant architecture with strict separation: one client's data is never accessible to another.

Encryption throughout

Encryption in transit (TLS) and at rest, with rigorous secret and access management.

ISO 27001 process

An information security management system is being structured, with certification as the goal.

Technical & organisational measures

Technical measures

  • TLS encryption in transit and encryption of data at rest
  • Regular backups and a recovery plan
  • Access logging and monitoring
  • Network segmentation and least privilege

Organisational measures

  • Need-to-know access, reviewed periodically
  • Ongoing security awareness for our teams
  • Subprocessor oversight (data processing agreements)
  • A documented incident management procedure

An architecture that separates responsibilities

Norvae is a Dematerialisation Operator: we produce and validate your EN 16931-compliant invoices and delegate their transport to a registered PDP partner. This clear separation of roles avoids lock-in and strengthens traceability.

  • Compliance with the European standard EN 16931 (Factur-X, UBL, CII)
  • Alignment with the French reform timeline
  • Transparency on data processing

Full details of personal data processing are in our privacy policy.

A specific security requirement?

Our teams answer security questionnaires and the requirements of your IT departments.

Contact us