Security & trust
Your invoicing data, protected to the highest standard
E-invoicing sits at the heart of your business. At Norvae, security, confidentiality and compliance are not options — they are central to how the product is designed.
Our commitments
GDPR by design
Minimised data, explicit purposes, traceable consent. We only collect what your compliance requires.
Hosting in the European Union
Your data is hosted and processed within the EU, with no unframed transfer outside this area.
Evidential archiving
Timestamped, tamper-evident and compliant retention of your invoices for the required legal period.
Per-client isolation
Multi-tenant architecture with strict separation: one client's data is never accessible to another.
Encryption throughout
Encryption in transit (TLS) and at rest, with rigorous secret and access management.
ISO 27001 process
An information security management system is being structured, with certification as the goal.
Technical & organisational measures
Technical measures
- TLS encryption in transit and encryption of data at rest
- Regular backups and a recovery plan
- Access logging and monitoring
- Network segmentation and least privilege
Organisational measures
- Need-to-know access, reviewed periodically
- Ongoing security awareness for our teams
- Subprocessor oversight (data processing agreements)
- A documented incident management procedure
An architecture that separates responsibilities
Norvae is a Dematerialisation Operator: we produce and validate your EN 16931-compliant invoices and delegate their transport to a registered PDP partner. This clear separation of roles avoids lock-in and strengthens traceability.
- Compliance with the European standard EN 16931 (Factur-X, UBL, CII)
- Alignment with the French reform timeline
- Transparency on data processing
Full details of personal data processing are in our privacy policy.
A specific security requirement?
Our teams answer security questionnaires and the requirements of your IT departments.
Contact us