UAE accreditation in progress · Pre-production · Not live as an accredited UAE service provider
Security claims apply to the stated entity, system and scope
Security & trust

Security that follows the entire document lifecycle.

Invocor applies governance, identity, protection, monitoring and recovery controls across document intake, transformation, exchange, reporting, evidence and customer delivery. The public model stays clear about scope; deployment-specific evidence is provided during security review.

Control model

Defence in depth, organised around real risk.

Invocor’s security model combines Abzer corporate governance with platform, deployment and operating controls. Exact configurations are documented for the contracted environment rather than implied by generic badges.

01 · Governance

Security ownership & risk

Defined roles, policies, risk assessment, personnel obligations, access governance, controlled change and management review establish accountability.

02 · Identity

Least-privilege access

MFA, role-based permissions, tenant and entity restrictions, joiner-mover-leaver processes and periodic access review control user and privileged access.

03 · Data protection

Protection in transit and at rest

Approved encryption configurations, certificate controls, credential and key protection, and minimised access reduce exposure across storage and transmission.

04 · Isolation

Separated environments & duties

Development, test and production responsibilities and environments are separated, with production access restricted and governed.

05 · Detection

Logging, monitoring & audit

Application and platform events, administrative actions and document lifecycle evidence support monitoring, investigation and accountability.

06 · Change

Secure release management

Code review, testing, dependency and vulnerability management, approved deployment and release evidence govern changes that can affect security or compliance.

Architecture layers

Protect the route, not only the application.

An e-Invoicing service crosses enterprise systems, integration channels, platform services, exchange routes and authority dependencies. Security review therefore follows the complete operating chain.

Enterprise edge

Authenticated interfaces, channel restrictions, input validation, rate and error controls, correlation and customer-side credential ownership.

Application

Role and scope enforcement, secure sessions, workflow permissions, validation boundaries, controlled exceptions and auditable administration.

Data

Encryption, tenant and entity separation, retention configuration, backup protection, controlled export and deletion obligations.

Platform

Environment segregation, hardened configuration, network controls, secrets protection, monitoring and restricted operational access.

Delivery chain

Document identifiers, certificate-dependent routes, acknowledgements, retries, reporting outcomes and evidence correlation across parties.

Operations

Support access, incident triage, escalation, recovery, change governance and customer communication under agreed procedures.

Data lifecycle

Customer data remains customer-owned.

Abzer’s processing rights are limited to the contracted service, security and support needs, and applicable legal obligations. Controller, processor and subprocessor roles are defined in the relevant agreement.

01

Receive

Accept agreed business documents and reference data through authorised channels and validate the expected source and structure.

02

Process

Validate, transform, enrich where contracted, route and correlate documents under scoped platform and user permissions.

03

Evidence

Record lifecycle events, responses and audit history required for operations, support, reconciliation and agreed retention.

04

Retain or remove

Apply contracted retention, export, return and deletion obligations, subject to applicable legal requirements.

Deployment matters: hosting location, data residency, retention, backup geography, subprocessors and permitted transfer mechanisms are disclosed for the selected service configuration. No universal location or retention period is implied by this page.
Shared responsibility

Security obligations do not stop at the platform boundary.

The final responsibility matrix belongs in the solution design and contract. It should name who owns identities, source data, endpoints, configurations, approvals, monitoring and response at every interface.

Invocor · as contracted

Platform responsibilities

  • Operate the agreed platform and technical controls
  • Protect provider-managed credentials and service access
  • Maintain platform logging, monitoring and audit history
  • Manage security incidents within the provider scope
Customer-led

Customer responsibilities

  • Govern source-system users, data and authorised instructions
  • Protect customer-managed endpoints, keys and credentials
  • Approve roles, integrations, retention and business decisions
  • Notify Invocor of relevant changes and suspected incidents
Joint & external

Shared dependencies

  • Integration testing and end-to-end acceptance
  • Incident coordination and evidence exchange
  • Partner, network, authority and cloud dependencies
  • Business continuity, cut-over and recovery exercises
Security review

Ask for evidence that matches your deployment.

Enterprise due diligence should test the legal entity, control scope, current evidence and contractual commitment—not rely on marketing adjectives.

Request a security review ↗
ArchitectureSystem boundaries, data flows, environments, trust zones, external dependencies and production activation gates.
Control matrixIdentity, access, encryption, logging, monitoring, vulnerability, change, backup, incident and continuity controls.
CertificationsCurrent certificate, certified entity, locations, systems, exclusions, validity and applicable scope.
Data & privacyDPA terms, roles, locations, subprocessors, retention, transfers, rights handling, return and deletion.
Service operationsSupport model, severity, escalation, notification, maintenance, reporting and responsibility matrix.
Testing & changeRelevant vulnerability or test evidence, remediation governance, secure release process and change records.
Continuity & exitBackup and recovery design, continuity summary, agreed objectives, exercise evidence and transition obligations.

Evidence availability depends on relevance, currency, confidentiality, customer scope and applicable third-party restrictions. Sensitive artefacts may require an NDA or controlled review.

Incidents & continuity

Plan for detection, response and recovery.

Public pages should not invent universal response or recovery guarantees. Deployment-specific notification, escalation, recovery objectives and remedies are confirmed in the applicable service schedules.

Incident lifecycle

Identify, contain, investigate, recover

Security events are assessed, contained and remediated through defined ownership and escalation, with customer communication and post-incident review according to the applicable process and obligations.

Service continuity

Backup, recovery and controlled restoration

Recovery design, backup configuration, restoration procedures, continuity responsibilities and exercises are aligned to the contracted deployment and agreed service objectives.

Corporate assurance

Assurance evidence with its boundaries intact.

Confirm the current evidence, named legal entity, scope, validity and applicability during due diligence. Management-system evidence does not by itself establish product or regulatory approval.

Information security

Governance and controls

Review current policies, risk governance and supporting evidence for the contracted entity and service scope.

Business continuity

Resilience evidence

Review continuity design, recovery objectives, dependencies and current exercise evidence for the proposed service.

Quality management

Delivery governance

Review delivery controls, change governance, corrective action and applicable quality evidence.

Network membership

OpenPeppol

Abzer DMCC is an OpenPeppol member. Membership is distinct from certified-service-provider status and UAE accreditation.

Regulatory boundary: Invocor remains in UAE accreditation and pre-production preparation. Accreditation, production onboarding, certificates, authority access, customer acceptance and controlled cut-over remain external activation gates. Security controls and product capability do not create regulatory permission.
Security questions

Security FAQ

Who owns the data processed through Invocor?

The customer retains ownership of its data. Abzer’s rights to process it are limited by the contracted service, security and support needs, and applicable legal obligations.

Where is Invocor data hosted?

Hosting location and data-residency commitments depend on the selected deployment and market requirements. The final architecture and data schedule should identify the applicable cloud, region, backup locations and subprocessors.

How is production access controlled?

Production access is restricted through approved roles, MFA, least privilege, environment separation, access lifecycle controls and audit history. The detailed operating model is supplied during due diligence.

Can customers review security evidence?

Relevant and current evidence can be made available according to scope, confidentiality and third-party restrictions. Sensitive material may require an NDA or controlled review session.

Does management-system evidence mean the Invocor service is UAE-accredited?

No. Management-system evidence, OpenPeppol membership, technical testing, product readiness and UAE regulatory accreditation are distinct. Invocor is not live as an accredited UAE service provider.

Put the control model under review.

Bring your security questionnaire, deployment requirements and data-residency constraints to a structured assurance discussion.

Start a security review ↗