Security and trust on the Peppol network
Peppol security rests on three layers — a closed PKI (only certified Access Points hold network certificates), AS4 messaging with signing and encryption in transit, and contractual obligations on every Service Provider. Documents are never publicly accessible and every delivery is acknowledged.
The three layers
- Peppol PKI. OpenPeppol operates a certificate authority issuing certificates only to certified Access Points and SMPs. A message signed by a non-member simply cannot enter the network.
- AS4 transport. Messages travel over TLS, are signed and encrypted per the eDelivery AS4 profile, and every transmission returns a signed receipt (non-repudiation both ways).
- Provider obligations. Service Providers sign the OpenPeppol agreements: security policies, incident duties, statistical reporting (EUSR/TSR) and — where a national Peppol Authority exists — its additional requirements.
What the network does not standardise is what providers do with your data at rest — retention, encryption at rest, hosting location. That differs per provider and belongs on your Access Point selection checklist.
Updated: August 29, 2026