Message IconCustomer SupportUser IconContact SalesLock IconLogin

Compliance & Trust Hub

We are committed to providing the highest level of security, compliance, and traceability, ensuring our customer can operate with complete confidence in our infrastructure.

Compliance Trust Hub Hero

Certifications & Peppol Authority Accreditations

Peppol Access Point Logo
Certified Provider
ISO 27001 Logo
Jan 2026
ISO 22301 Logo
Q4 2025
GDPR Logo
Compliant

Security & Privacy You Can Trust

Arratech is committed to safeguarding your data through strong security practices, responsible privacy controls, resilient operations, and fully transparent governance. Using an automated compliance monitoring platform, we maintain real-time visibility into our ISO 27001 and ISO 22301 readiness, ensuring that any deviation is identified and addressed quickly. Our approach blends rigorous internal processes with trusted partners and privacy-by-design principles to ensure your information remains protected at all times.

Shield Locked Icon
Protecting your data, powering your business

Arratech embeds security and privacy throughout our platform and internal operations.

Our practices follow the requirements of ISO 27001 and ISO 22301, ensuring strong protection, resilience, and reliable service continuity.

Working toward certification reinforces our commitment to providing verifiable, independently assessed assurance for our customers.

Autorenew Icon
Continuous compliance through automation

Arratech employs automated monitoring to continuously validate the effectiveness of our security and resilience controls.

This real-time oversight ensures that any deviation from ISO 27001 and ISO 22301 requirements is identified promptly, allowing our teams to act quickly and maintain a high level of assurance and operational integrity.

Lock Person Icon
Data handled responsibly

We apply strict data protection principles to ensure personal information is collected, processed, and stored tra

Our privacy-by-design approach helps customers meet their compliance obligations.

We pair this with security-by-design practices to ensure that data protection is built in from the foundation up.

Read our Privacy Policy

crisis alert icon
Prepared for the unexpected

Operational resilience is central to how we deliver our services.

Our business continuity and incident response capabilities are structured to minimize disruption and safeguard availability at all times.

Through regular preparedness activities such as tabletop exercises, we refine our response procedures and reinforce our ability to manage unexpected incidents with confidence.

Peppol Governance

At Arratech, we operate at the core of the Peppol network as an Peppol certified Access Point and SMP provider, recognized for our compliance with the highest standards of interoperability, reliability, and security. Our services are fully aligned with the governance models defined by OpenPeppol and the respective Peppol Authorities (PAs) requirements across Europe and beyond.

Briefcase icon
Peppol Authorities

We actively adhere to each jurisdiction’s Peppol Authority Specific Requirements (PASRs), ensuring that our infrastructure and operational practices meet or exceed local and international compliance expectations.

Whether a PASR involves operational requirements or a formal accreditation process, Arratech maintains conformity through rigorous testing, continuous monitoring, and transparent reporting.

Processor Icon
Compliant Environment

For our customers, this means instant access to a compliant Peppol environment without the complexity of managing separate national accreditations.

Our shared-label Access Point and SMP solutions enable service providers to enter new markets confidently, knowing that every transaction flows through an infrastructure already validated by the relevant Peppol Authorities.

Refresh CW Icon
Fully Certified

Arratech operates a Peppol certified Access Point, ensuring every transaction meets the strict interoperability, security, and governance standards defined by OpenPeppol and national Peppol Authorities.

Our certified infrastructure allows service providers and software vendors to connect to the Peppol network immediately.

FAQs Hero Image

FAQs

What is an Access Point?

Connect once, exchange documents with the entire network

Peppol Access Points are essential communication hubs within the Peppol network. By connecting your business through a single certified Access Point, you can immediately begin securely exchanging electronic business documents with all participants across the network. Although initial setup and certification require some effort, once established, your organization can instantly reap the benefits of streamlined operations and substantial cost savings.

How can my business get its own Peppol Access Point?

Your business can either establish its own Peppol Access Point or collaborate with a certified provider like Arratech. Setting up your own Access Point involves multiple steps, including:

  • Becoming an OpenPeppol member.
  • Understanding Peppol’s technical framework and compliance requirements.
  • Demonstrating a secure, reliable technical infrastructure.
  • Completing mandatory accreditation testing.
  • Hosting and managing your own software and infrastructure.

Want to avoid the complexity? Arratech simplifies accreditation and onboarding, helping you become fully operational within days—so you can focus on what matters to your business.

How quickly can my business integrate with the Peppol network using Arratech's API?

With Arratech's streamlined Access Point API, your business can be operational and exchanging compliant documents on the Peppol network within days. Our simplified onboarding and clear documentation ensure fast integration, significantly reducing your time to go live.

Is Arratech’s Access Point API compliant with the latest Peppol standards and regulations?

Yes, Arratech’s API is continuously updated and fully compliant with the latest Peppol specifications and regulatory requirements. We ensure your business maintains compliance effortlessly, allowing you to focus on what matters to your business without worrying about technical complexities.

Read our latest blog posts
What is the identity of the person submitting a tax report illustration
Identity: A forgotten theme in Digital Tax Reporting

As tax reporting moves into real time, identity can no longer be assumed. In a world of continuous transaction controls and outsourced compliance, tax authorities must instantly know who is submitting a report, on whose behalf, and under what authorization. Without verifiable identity, automation breaks and trust with it.

Difference between VAN networks and Peppol networks illustration
The difference between the Peppol network and traditional e-invoicing networks

The Peppol network is a decentralized, international e-invoicing infrastructure using a 4-corner model. This allows organizations to exchange e-invoices through certified service providers without needing bilateral agreements between senders, receivers, or providers. It ensures interoperability and avoids vendor lock-in. Traditional e-invoice (VAN) networks rely on bilateral agreements, creating a fragmented ecosystem.

Surreal paintaing of PDF inspired by Magritte with person looking at painting
Get ready for the Belgium e-Invoicing mandate

Belgium’s B2B e-invoicing mandate is now law. From 1 January 2026, nearly all Belgian VAT-registered businesses must send and receive structured electronic invoices using Peppol BIS Billing 3.0, aligned with EN 16931. PDFs and paper invoices will no longer suffice. The framework also prepares Belgium for near real-time VAT e-reporting by 2028, with penalties for non-compliance already defined.