Compliance & Trust Hub
We are committed to providing the highest level of security, compliance, and traceability, ensuring our customer can operate with complete confidence in our infrastructure.

Security & Privacy You Can Trust
Arratech is committed to safeguarding your data through strong security practices, responsible privacy controls, resilient operations, and fully transparent governance. Using an automated compliance monitoring platform, we maintain real-time visibility into our ISO 27001 and ISO 22301 readiness, ensuring that any deviation is identified and addressed quickly. Our approach blends rigorous internal processes with trusted partners and privacy-by-design principles to ensure your information remains protected at all times.
Arratech embeds security and privacy throughout our platform and internal operations.
Our practices follow the requirements of ISO 27001 and ISO 22301, ensuring strong protection, resilience, and reliable service continuity.
Working toward certification reinforces our commitment to providing verifiable, independently assessed assurance for our customers.
Arratech employs automated monitoring to continuously validate the effectiveness of our security and resilience controls.
This real-time oversight ensures that any deviation from ISO 27001 and ISO 22301 requirements is identified promptly, allowing our teams to act quickly and maintain a high level of assurance and operational integrity.
We apply strict data protection principles to ensure personal information is collected, processed, and stored transparently and lawfully.
Our privacy-by-design approach helps customers meet their compliance obligations.
We pair this with security-by-design practices to ensure that data protection is built in from the foundation up.
Operational resilience is central to how we deliver our services.
Our business continuity and incident response capabilities are structured to minimize disruption and safeguard availability at all times.
Through regular preparedness activities such as tabletop exercises, we refine our response procedures and reinforce our ability to manage unexpected incidents with confidence.
Peppol Governance
At Arratech, we operate at the core of the Peppol network as an Peppol certified Access Point and SMP provider, recognized for our compliance with the highest standards of interoperability, reliability, and security. Our services are fully aligned with the governance models defined by OpenPeppol and the respective Peppol Authorities (PAs) requirements across Europe and beyond.
We actively adhere to each jurisdiction’s Peppol Authority Specific Requirements (PASRs), ensuring that our infrastructure and operational practices meet or exceed local and international compliance expectations.
Whether a PASR involves operational requirements or a formal accreditation process, Arratech maintains conformity through rigorous testing, continuous monitoring, and transparent reporting.
For our customers, this means instant access to a compliant Peppol environment without the complexity of managing separate national accreditations.
Our shared-label Access Point and SMP solutions enable service providers to enter new markets confidently, knowing that every transaction flows through an infrastructure already validated by the relevant Peppol Authorities.
Arratech operates a Peppol certified Access Point, ensuring every transaction meets the strict interoperability, security, and governance standards defined by OpenPeppol and national Peppol Authorities.
Our certified infrastructure allows service providers and software vendors to connect to the Peppol network immediately.

FAQs
Connect once, exchange documents with the entire network
Peppol Access Points are essential communication hubs within the Peppol network. By connecting your business through a single certified Access Point, you can immediately begin securely exchanging electronic business documents with all participants across the network. Although initial setup and certification require some effort, once established, your organization can instantly reap the benefits of streamlined operations and substantial cost savings.
Your business can either establish its own Peppol Access Point or collaborate with a certified provider like Arratech. Setting up your own Access Point involves multiple steps, including:
- Becoming an OpenPeppol member.
- Understanding Peppol’s technical framework and compliance requirements.
- Demonstrating a secure, reliable technical infrastructure.
- Completing mandatory accreditation testing.
- Hosting and managing your own software and infrastructure.
Want to avoid the complexity? Arratech simplifies accreditation and onboarding, helping you become fully operational within days—so you can focus on what matters to your business.
With Arratech's streamlined Access Point API, your business can be operational and exchanging compliant documents on the Peppol network within days. Our simplified onboarding and clear documentation ensure fast integration, significantly reducing your time to go live.
Yes, Arratech’s API is continuously updated and fully compliant with the latest Peppol specifications and regulatory requirements. We ensure your business maintains compliance effortlessly, allowing you to focus on what matters to your business without worrying about technical complexities.
Read our latest blog posts

Already chosen a Plateforme Agréée in France? Use these ten checks to assess production readiness, identify structural gaps and determine whether to improve your current setup or consider changing PA.

OpenPeppol is making ISO/IEC 27001 certification mandatory for all Peppol Service Providers. Learn why the requirement has been introduced, who it affects, what ISO 27001 readiness really means, and the practical steps providers should take to prepare before the implementation deadline.

France’s e-invoicing deadline remains 1 September 2026, but DGFiP’s latest practical guidance makes clear that business continuity should come first. Companies are expected to prepare seriously, document issues and return to compliant processes quickly, while temporary fallback methods may be used when technical problems arise.





