Security and trust on the Peppol network

Peppol security rests on three layers — a closed PKI (only certified Access Points hold network certificates), AS4 messaging with signing and encryption in transit, and contractual obligations on every Service Provider. Documents are never publicly accessible and every delivery is acknowledged.

The three layers

  1. Peppol PKI. OpenPeppol operates a certificate authority issuing certificates only to certified Access Points and SMPs. A message signed by a non-member simply cannot enter the network.
  2. AS4 transport. Messages travel over TLS, are signed and encrypted per the eDelivery AS4 profile, and every transmission returns a signed receipt (non-repudiation both ways).
  3. Provider obligations. Service Providers sign the OpenPeppol agreements: security policies, incident duties, statistical reporting (EUSR/TSR) and — where a national Peppol Authority exists — its additional requirements.

What the network does not standardise is what providers do with your data at rest — retention, encryption at rest, hosting location. That differs per provider and belongs on your Access Point selection checklist.

Updated: August 29, 2026

Frequently asked questions

Can anyone join the network and read documents?

No. Only providers that pass OpenPeppol certification receive PKI certificates, and transmissions are encrypted and signed between exactly two certified endpoints.

Do I get proof my invoice arrived?

Yes — AS4 acknowledgements are cryptographically signed receipts; your provider stores them as delivery evidence.