Security Schedule
Version 1.1 · Published 3 September 2026
This Security Schedule (the “Schedule”) describes the information-security measures InvoiceNow Biz F.Z.C. (“InvoiceNow Biz” or “ASP”) applies to the electronic invoicing and related services (the “Services”). It forms part of, and is incorporated by reference into, the applicable end user licence agreement or service terms (the “Agreement”) and complements the Data Processing Addendum. Capitalised terms not defined here have the meaning given in the Agreement.
1. Security programme and governance
ASP maintains, directly or through its group affiliates, a documented information-security management system certified to ISO/IEC 27001, and business-continuity management certified to ISO 22301. Certification currently held at group level applies to the infrastructure and platform operated for the Services. Policies are reviewed at least annually, and risk assessments are performed regularly.
2. Access control
Access follows role-based, least-privilege principles with unique user IDs and multi-factor authentication for administrative and user access. Access rights are reviewed periodically and revoked promptly on change of role or termination.
3. Encryption
Data is encrypted in transit using TLS and at rest using strong, industry-standard algorithms. Cryptographic keys are managed under documented key-management procedures.
4. Infrastructure and data segregation
The Services are hosted with a reputable cloud provider in the region required by the applicable data-residency requirement. Customer Data is logically segregated, and infrastructure is hardened and protected by network controls.
5. Monitoring and logging
ASP performs security monitoring and maintains audit logs of relevant events, with alerting and defined retention periods.
6. Vulnerability and patch management
ASP performs regular vulnerability scanning, applies security patches on a risk-prioritised basis, and conducts penetration testing at least annually.
7. Secure development and change management
ASP follows a secure development lifecycle with code review and controlled change-management processes.
8. Personnel security
Personnel are bound by confidentiality obligations, receive security-awareness training, and are subject to background checks where lawful.
9. Business continuity and disaster recovery
ASP maintains backups and a documented business-continuity and disaster-recovery plan aligned to ISO 22301 (held by ASP or its group affiliates), with defined recovery objectives.
10. Incident response
ASP maintains a documented incident-response process, notifies the Customer of personal-data breaches in accordance with the DPA, and provides the information the Customer needs to meet its notification obligations to a Competent Authority (see the Maintenance and Support Policy).
11. Sub-processor and vendor management
ASP performs security due diligence on sub-processors and imposes flow-down security obligations, as further described in the DPA and the Sub-processor List at https://www.invoicenow.biz/legal/subprocessors.
12. Compliance and audit
ASP complies with Applicable Law and the security requirements of the Competent Authorities relevant to its accreditations for the Services. Certifications and summary audit reports are available on reasonable request, subject to confidentiality.
13. Changes
ASP may update this Schedule from time to time and will not materially reduce the security measures during the current term without prior notice.