1. Home
  2. Security
  • About Us
  • Your Gateway to Effortless E-Invoicing & Supply Chain Document Digitalization

Sign up for our Newsletter

Legal

  • Privacy Policy
  • Terms of Service
  • Imprint
  • Security

Follow Us

ISO 9001 Certified - ICG Quality Management System Certification
EFRE ESF - EU and Free State of Saxony funding
Skip to content
OverviewMeasuresOn-PremGlossaryFAQRequest a call

Data protection & information security

Security for PEDIF processes

For prospects assessing PEDIF as a PDF-to-EDI, e-invoicing or document automation service in the context of NIS2, ISO 27001-oriented controls and supplier assessments.

Supedio documents organizational, technical and data-protection measures for structured document digitization services.

Validation, trust and orchestration

PEDIF is a validation, trust and orchestration layer for document-based business processes. The focus moves from “document in, data out” to “document in, trustworthy process decision out” – supported by data protection, information security and traceable validation.

Note: Terms from security, privacy, EDI and on-prem operations are explained in plain language in the glossary below — without footnotes or numbered references.

Request a security callView measuresView glossary
ISO 9001 Certificate
Certified according to DIN EN ISO 9001:2015
DIN EN ISO 9001:2015
Certified for 5 years
Hosting
ISO 27001-certified cloud providers
Data location
Stored within the EU
Data protection
External DPO

For due diligence

An overview for NIS2 and ISO 27001-oriented assessments

PEDIF processes business documents within a defined scope. For technical, legal and procurement assessments, key aspects include governance, data location, access controls, deletion concepts, incident processes and the handling of external service providers.

Responsibility

ISMS governance

Executive management bears overall responsibility for the ISMS. Roles and responsibilities are documented; access follows the need-to-know principle.

Risk control

Risk management & SoA

Supedio conducts structured risk analyses, treats risks with documented measures and documents the selection of ISO 27001 Annex A-oriented controls in a Statement of Applicability.

Evidence

Monitoring, audit & improvement

The ISMS is audited internally at least annually and after material changes. Findings are classified by severity and tracked to closure through CAPA.

Data protection

External Data Protection Officer

Supedio has appointed Andrea Prinz, Datenschutz Prinz GmbH, as external Data Protection Officer with effect from 2025-11-01. The role acts independently and reports directly to management.

Data categories

Which data is in scope

Supedio processes only business-related documents between legally independent organizations, such as orders, delivery notes and invoices. Personal data generally concerns employee contact information from those organizations.

  • Customers must ensure that only business documents are processed.
  • Private or impermissible content must not be transmitted.
  • Onboarding defaults to dummy or sanitized data; real business documents are not required.

Technical & organizational measures

Controls across PEDIF operations

The following points are written as a compact, auditable overview for data protection, IT security, ERP/EDI and procurement teams.

Hosting & data location

Hosting is performed exclusively with ISO 27001-certified cloud providers. Data is stored within the European Union throughout the entire lifecycle.

  • ISO 27001-certified cloud providers
  • Data storage within the EU
  • Cloud and on-premises scenarios described in the ISMS scope

Access management

Access is controlled through IAM, role-based permissions, least-privilege principles and limited administrative access. Production access is restricted to authorized Supedio personnel and logged.

  • RBAC and need-to-know
  • SSO with 2FA active for PEDIF Portal, EPIC Prod and Mailious
  • Production access logged with identity, IP details and activity

Network protection

Customer-facing services are protected against DDoS and common web and bot attacks through Cloudflare and AWS WAF.

  • Edge protection through Cloudflare and AWS WAF
  • Email domains protected with SPF, DKIM and DMARC
  • Least-privilege and hardened privileged access

Encryption

All data transfers use SSL/TLS. For data at rest, AWS platform encryption in the EU region is active; cryptographic target standards are documented in the ISMS.

  • TLS 1.2 or 1.3 for data in transit
  • AWS EC2/EBS platform encryption active
  • AES-256 and KMS-managed keys as documented target standard

Backups & disaster recovery

Backups are encrypted daily, retained for 14 days and support recovery from data-loss or ransomware events.

  • RPO: 24 hours
  • RTO: 6 hours
  • Restore tests recurring, after major releases and at least every 12 months

Secure development & patch management

The secure development lifecycle includes peer or senior code reviews, dependency and secret scanning, SAST, release approvals and an emergency-change process.

  • Mandatory review before merge
  • Testing and quality assurance before release
  • Security fixes by severity SLAs: critical 24h, high 7 days, medium 30 days, low 90 days

Operational use

Operators normally work with system logs rather than customer documents. Download, export and local storage of customer data are allowed only for specific operational tasks, restricted and logged.

  • No-touch processing as standard
  • Manual review only for genuine error cases
  • Content access only named, authorized, logged and monitored

Validation & output integrity

Extracted data is checked before handoff against defined refinement, target-format, validation and sanity rules.

  • Versioned validation scripts
  • Traceability through validator version and responsible approver
  • Unclear or failing cases go to review

AI use

AI is used for document recognition, extraction and to assist anonymization. Customer data is not used to train AI models.

  • Real customer documents only where required to deliver or debug the contracted service
  • Customer approval before real-document processing
  • AI governance through register, vendor review and DPIA screening

External service providers

External service providers support Supedio in software development, bug fixing and maintenance within clearly defined technical responsibilities and controlled systems.

  • Development and maintenance with dummy, anonymized or pseudonymized data
  • No standing production access for external service providers
  • Real customer-data exceptions only documented, purpose-bound, time-limited and customer-approved

Incident management & awareness

Supedio operates a documented incident process. Reports via the defined incident channel are monitored on business days and triaged within 24 hours.

  • Analysis, containment, resolution and lessons learned
  • Potential personal data breaches assessed without undue delay
  • Information security training at onboarding and at least annually

Export, deletion & exit

Customers can request export and early deletion of their data. On termination, a structured export is available; customer data is deleted within 30 days unless otherwise agreed.

  • Defined, logged request process
  • Deletion date confirmed back to the customer
  • Support for termination or migration

Deployment option

Supedio On-Prem Solution for stronger data control

For organizations with strict data protection, compliance or infrastructure requirements, PEDIF-oriented processing can also be operated as an on-prem model. The operational runtime runs inside the customer's infrastructure, while Supedio continues to support the product, updates, fingerprint creation, workflow configuration and service onboarding.

Runtime in the customer environment

The core processing stack is brought into the customer's private environment. Documents can be received, processed, converted and routed without requiring operational data to leave the customer-controlled system.

EPIC Live & DTC

EPIC Live provides the extraction runtime; DTC provides the workflow and orchestration layer. Input can be processed via API, email, SFTP or AS2.

Target formats & use cases

Typical outputs include EDI, CSV, Excel, XML or customer-specific formats. The model is suitable for PDF-to-EDI, invoice processing, purchase order automation, dispatch advice processing, order response handling and supply-chain workflows.

Shared operating model

Customers can apply their own standards for network access, TLS termination, user permissions, logging, monitoring, backups and disaster recovery; Supedio provides the application, updates, workflow and fingerprint expertise.

Glossary

Technical terms in plain language

This glossary explains the key terms used on this page in everyday language. It is intentionally centralized: no footnotes, numbered references or separate markers in the body copy.

Security, privacy & compliance

Data protection / privacy
Protection of personal data — information that can relate to individual people.
Information security
Protection of information against unauthorized access, change, loss or outage.
Compliance
Following laws, contracts, internal rules and customer requirements.
NIS2
EU directive for cybersecurity requirements. It also matters when many companies assess their suppliers.
ISO 27001 / ISO/IEC 27001
International standard for information security management systems. Referencing ISO 27001 does not automatically mean that a company itself is certified.
DIN EN ISO 9001:2015
Quality management standard. It describes how organizations plan, document and improve quality.
ISMS
Information Security Management System: organized rules, roles, controls and improvement processes for information security.
Governance
Defined responsibilities, decision paths and rules so that security is managed deliberately.
Due diligence
Structured assessment before or during a business relationship, often by procurement, privacy or security teams.
Supplier assessment
Customer review of a service provider before or during engagement.
Controls
Measures intended to reduce risks, such as access restrictions, logging or backups.
SoA / Statement of Applicability
Documented selection of relevant security controls and reasons why they are or are not applied.
ISO 27001 Annex A controls
Set of typical security controls listed in Annex A of ISO 27001.
Audit
Review of whether rules, processes and evidence exist and work as intended.
CAPA
Corrective and Preventive Action: process for fixing identified issues and preventing recurrence.
Data Protection Officer
Independent person or organization that advises on data protection duties and monitors compliance.
DPA / Data Processing Agreement
Contract that governs how a service provider processes personal data for a customer.
Assessment
Structured evaluation, for example of security, privacy, technology or supplier risk.

Data, access & operations

Scope
The defined boundary of a statement, assessment or measure.
Business documents
Documents from business processes, such as orders, delivery notes, invoices or order responses.
Personal data
Information relating to individual people, such as names, email addresses or business contact details.
Data location
The place or region where data is stored or processed.
EU data storage
Storage or processing of data within the European Union.
Onboarding
Setup phase in which a service is prepared, tested and made ready for use.
Dummy data
Artificial test data that does not contain real customer or personal data.
Sanitized data
Data from which sensitive or unnecessary content has been removed or replaced.
Anonymization
Changing data so individual people can no longer be identified.
Pseudonymization
Replacing identifying data with placeholders. Re-identification may still be possible under certain conditions.
No-touch processing
Normal processing without manual viewing of customer documents.
Customer documents
Documents provided by a customer or created in the customer process.
System logs / logs
Technical records of system events, such as access events or error messages.
Logged request process
A process that records who requested or handled what and when.
Need-to-know principle
People only receive access to information they actually need for their task.
Least privilege
Users receive only the minimum permissions required, not more.
RBAC
Role-Based Access Control: permissions are assigned through roles such as support, administrator or customer.
IAM
Identity and Access Management: management of user identities, roles and access rights.
SSO
Single Sign-on: log in once and use multiple connected applications.
2FA
Two-factor authentication: login with two proofs, such as password plus app code.
IP details
Technical address and connection information of a device or network.
Production access
Access to the live system where real customer processes run.
Administrative access
Extended technical permissions for managing systems or applications.

Technology, development & resilience

Hosting
Running applications or storing data on servers in a data center or with a cloud provider.
Cloud provider
Provider of data-center and server services over the internet, for example for hosting or storage.
On-premises / on-prem
Operation inside the customer’s own infrastructure instead of only in an externally hosted cloud.
Network protection
Measures that protect systems against attacks or unwanted traffic.
DDoS
Attack in which a very large number of requests tries to overload a system.
Bot attacks
Automated attacks by software programs, for example to test logins or exploit weaknesses.
WAF
Web Application Firewall: protection layer that filters web requests and can block suspicious attacks.
Cloudflare
Provider of network and web protection services such as DDoS protection and traffic filtering.
AWS
Amazon Web Services: cloud platform for servers, storage, databases and other technical services.
AWS EC2/EBS
AWS services for virtual servers and their associated storage volumes.
SPF, DKIM and DMARC
Email security methods that help verify senders and make spoofed emails harder.
Encryption
Transforming data into a form that cannot be read without the right key.
SSL/TLS
Encryption protocols that secure data transfer over networks.
Data in transit
Data that is currently being transferred between systems.
Data at rest
Data that is stored and not currently being transferred.
AES-256
Widely used strong encryption standard for stored data.
KMS-managed keys
Encryption keys managed through a Key Management Service.
Backup
Copy of data that can be used to recover after loss or errors.
Backup retention
Period for which backup copies are kept.
Disaster recovery
Plan and technical capability to recover after major disruption or data loss.
RPO
Recovery Point Objective: maximum acceptable data loss measured in time.
RTO
Recovery Time Objective: target time to restore a system after an outage.
Restore test
Test to confirm that a backup can actually be restored.
Major release
Larger software update with relevant changes.
Ransomware
Malicious software that encrypts data or blocks systems and demands payment.
SDLC / Secure Development Lifecycle
Secure development process from planning through coding, testing and release.
Code review
Review of software code by another developer.
Dependency scanning
Automated check of used software components for known vulnerabilities.
Secret scanning
Search for accidentally stored passwords, access keys or tokens in code.
SAST
Static Application Security Testing: automated security analysis of source code.
Patch management
Planned handling of software updates and security fixes.
Security fix
Software change that resolves a security vulnerability.
Severity SLA
Response or resolution deadline based on the severity of an issue.
Emergency change
Urgent change implemented faster than usual because of an acute issue.

PEDIF, EDI, AI & on-prem terms

PEDIF
Supedio service for document-based automation, such as PDF-to-EDI, e-invoicing and structured handoff of business data.
PDF-to-EDI
Conversion of PDF business documents into structured electronic data formats for business systems.
EDI
Electronic Data Interchange: standardized electronic exchange of business data between organizations.
E-invoicing
Electronic invoicing in structured formats instead of only as an image or PDF.
Document automation
Automatic capture, checking, conversion and routing of documents.
Validation
Checking whether recognized data is plausible and follows defined rules.
Output integrity
Confidence that the generated result is correct, traceable and not unnoticedly changed.
Orchestration
Coordination of several processing steps, systems and decisions in one workflow.
Workflow
Defined sequence of work steps.
API
Interface that allows systems to communicate automatically.
SFTP
Secure method for transferring files.
AS2
Protocol for secure electronic data exchange, often used in EDI contexts.
CSV
Table-like text format in which values are separated by delimiters.
XML
Structured data format that organizes information with descriptive tags.
Target format
Format in which data is handed over to a target system after processing.
Use case
Concrete application scenario, such as invoice processing or purchase order automation.
Dispatch advice
Message about an upcoming delivery, often including shipment and item details.
Runtime
Execution environment where the actual processing runs.
EPIC Live
Component for live extraction and recognition of document content.
DTC
Component for workflow and orchestration — controlling processing and handoff.
Extraction
Automatic reading of relevant information from a document.
Fingerprint
Recognition pattern or configuration used to identify and process a document type.
AI
Artificial intelligence: software methods that can recognize patterns or support decisions.
AI model
Trained technical model that processes input and produces results.
AI governance
Rules and evidence for how AI is used, reviewed and controlled.
Vendor review
Review of a provider, for example for security, privacy and reliability.
DPIA screening
Initial check whether a Data Protection Impact Assessment may be needed.
Incident management
Organized process for detecting, assessing, handling and reviewing security incidents.
Triage
Initial classification of an incident by urgency and severity.
Awareness
Understanding and training for everyday security risks.
Exit
Orderly end of a service, including export, deletion or migration.
Migration
Moving data, processes or systems to another environment.

FAQ

Answers for data protection, security and procurement teams

Is Supedio itself ISO 27001 certified?+
No. No ISO 27001 certification claim is made for Supedio itself. The substantiated facts are an internal ISMS based on established best practices and ISO/IEC 27001 requirements, plus hosting exclusively with ISO 27001-certified cloud providers. Supedio is certified according to DIN EN ISO 9001:2015.
How should this page be read in the NIS2 context?+
The page is structured as a due-diligence overview for NIS2-oriented questions. It describes governance, risk, access protection, incident management, business continuity, data minimization and evidence handling without claiming blanket NIS2 conformity.
Who is appointed as external Data Protection Officer?+
Supedio has appointed Andrea Prinz, Datenschutz Prinz GmbH, as external Data Protection Officer with effect from 2025-11-01. The role acts independently and reports directly to management.
Where is data stored?+
Data is stored within the European Union throughout the entire lifecycle. Hosting is performed exclusively with ISO 27001-certified cloud providers.
Who can see customer documents?+
No-touch processing is the standard. Support usually works from system logs. Access to customer document content is only intended for genuine error cases where the issue cannot be resolved from logs alone; access is restricted to named, authorized operations personnel and is logged and monitored.
How long is operational data stored?+
Operational data is deleted no later than 30 days after processing unless otherwise agreed. Backups containing the data are overwritten within the 14-day backup retention cycle.
Is customer data used to train AI models?+
No. Customer data is not used to train AI models. Real customer documents are processed only where required to deliver or debug the contracted service and only after customer approval.
When does the On-Prem Solution make sense?+
The On-Prem Solution is useful for companies that want to use PEDIF-oriented document automation and EDI capabilities while keeping runtime processing, runtime documents, logs and security controls inside their own infrastructure.
Can customers request export or early deletion?+
Yes. Customers can request export and early deletion. This is handled through a defined, logged request process with confirmation.

Note: This page is a public, curated overview and does not replace a contractual agreement, DPA or full audit package. Detailed evidence should be provided through a controlled process.

Contact Us

Questions, need help choosing the right setup?

Company Information

Supedio GmbH
Dresden, Germany
CEO: Marcus Ehrenburg