forumNew topic

Are we vulnerable to cyberattacks when sending e-invoices? Is the system secure, is there encryption?

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#1

I send customer info to my accountant via e-invoice. Is the system centralized, can anyone else interfere? E-invoice XML files contain confidential customer info (tax ID, address). Can someone intercept and alter this traffic?

I told a developer to 'set up the e-invoice connection', I found the address but idk how they manage the username/password. If the system doesn't lock me out, could all invoices leak? Is authentication sufficient?

When changing accounting firms, does the old accountant lose access to the e-invoice system? Or is it a separate system? How do I inform my clients, what is the data transfer process?

DDeniz K***MemberCommunity member
Joined
Nov 2025
Message
21
Most Helpful#2

The e-invoice system (like GiBE/UBLe) is managed by the Ministry of Treasury and Finance. Security: 1) Transmission: TLS 1.2+ encrypted, certificate pinning, 2) Authentication: digital certificate (qualified e-signature), two-factor auth, 3) Data integrity: XML signature (non-repudiation), HMAC validation, 4) Access control: role-based (accountant, business admin), token expiry (session timeout), 5) Audit logs: all transactions logged in GiBE, recovery possible, 6) Credential management: digital certificate password (never store), hardware token storage (optional). Accountant change: access revoke (GiBE settings), API token revoke (if custom integration), forwarding setup (optional). Data migration: export (XML, PDF), direct file transfer (encrypted channel), or API integration (new provider). Integration security: API key rotation, IP whitelist (if available), VPN tunnel (critical transfers). Risk: custom integration (if XSD validation missing), phishing (credential theft), certificate expiry (TLS communication fail).

HHakan G***Member
Job title
Purchasing manager
Sector
Seafood
Organization type
300-person organization
Joined
Oct 2024
Message
185
#3

the e-invoice system is managed by the state very secure. the password is linked to the e-signature certificate others can't easily log in. if the accountant changes, close access from the system that's it. revoke the gibe user...

TTolga K***ExpertCommunity member
Joined
Apr 2025
Message
24
#4

E-invoice tech: XML → digital sign (qualified certificate) → TLS transport → GiBE server. GiBE security: HSM (Hardware Security Module), certificate management, audit logging (tamper-proof), redundancy (high availability). Integration: SOAP API (legacy), REST API (new), mutual TLS (mTLS) certificate pinning. Custom integration risk: input validation (XSD schema), credential storage (HSM, not plaintext), rate limiting (DDoS), error handling (info disclosure).

TTolga G***Veteran
Job title
Secretary
Sector
Plastic
Organization type
regional distributor
Joined
Jan 2024
Message
138
#5

the e-invoice state system is super secure, bro. make sure the certificate password is strong and manage access in the GiBE account one by one and if the accountant changes revoke the old persons access and give it to the new one. if theres a smell with the integration software switch to another payment processor...

JJale Ş***Member
Job title
Content Editor
Sector
Healthcare services
Organization type
chain store
Joined
Aug 2024
Message
168
#6

E-Invoice security: 1) Digital certificate (qualified e-signature), 2) TLS 1.2+ transmission, 3) GiBE audit logs (non-repudiation), 4) Role-based access (accountant role restricted), 5) Token expiry (session management). Integration: API authentication (certificate + key), input validation (XSD), output encoding. Incident: certificate revocation (CRL check), breach notification (GiBE handle), audit trail investigation.

VVeli Ö***Expert
Job title
Accounting clerk
Sector
Logistics
Organization type
boutique agency
Joined
Jun 2025
Message
32
#7

Quick summary for newcomers: If 2FA is on a stolen password alone is useless.

If you post the result here, it will help others too.

EEfe K***Member
Job title
Intern
Sector
Consulting
Organization type
early-stage startup
Joined
Nov 2023
Message
107
#8

Good call starting this thread.

MMeryem S***Member
Job title
Graphic Designer
Sector
Consulting
Organization type
family business
Joined
May 2024
Message
208
#9

We need to take it step by step. Most incidents start with a leaked password, not a vulnerability.

Correct me if I'm wrong.

RRıdvan Y***Expert
Job title
Software team lead
Joined
Sep 2023
Message
196

Doki · Interface design · 2023

#10

If you're going this route, sort this out first. If you get three different answers on a topic, the question was asked wrong.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. Just leaving this note, it might be useful.

ÖÖzge E***Member
Job title
Sales Manager
Sector
Paper
Organization type
workshop
Joined
Jun 2023
Message
50

Doki · Brand identity · 2023

#11

My perspective changed after experiencing that. Just because everyone does it doesn't mean it's right.

If 2FA is on, a stolen password alone is useless. Good luck with that.

MMerve Ö***Expert
Job title
Technical service technician
Sector
Retail
Organization type
workshop
Joined
Oct 2022
Message
142
#12

Exactly like that. Your time to detect an issue directly determines its cost.

Correct me if I'm wrong.

OOnur A***Veteran
Job title
Quality Assurance Manager
Sector
Paper
Organization type
chain store
Joined
Feb 2026
Message
36
#13

Thanks, this was very helpful.

GGizem U***MemberCommunity member
Joined
Oct 2023
Message
55
#14

let me speak from the other side; I'm on the supplier side. i mean security isn't absolute; it's about making attacks not worth the effort.

the answer varies greaty by industry; there is no one-size-fits-all rule then if you have questions write them; I'll answer as best I can.

ZZeynep Ş***VeteranCommunity member
Joined
Aug 2024
Message
26
#15

The cheap-looking path usually ends up costing more later. tbh having backups accessible on the same network and with the same identity makes them part of the target.

If I were you, Id go this route.

KKübra A***Member
Job title
Technical service technician
Sector
Automotive aftermarket
Organization type
120-person company
Joined
Aug 2025
Message
71

Doki · Phishing awareness training · 2026

#16

This thread is archived.

VVeli N***Expert
Job title
System administrator
Sector
Packaging
Organization type
a company within a holding
Joined
May 2022
Message
359
#17

There's a common mistake people make when doing this. Hasty decisions become decisions you have to fix six months later.

Good luck with that.

HHasan E***MemberCommunity member
Joined
Aug 2022
Message
333
#18

I can't fully agree with this. Don't hesitate to ask; those who don't ask always pay more.

Just because everyone does it doesn't mean it's right. Correct me if I'm wrong.

PPolat M***MemberCommunity member
Joined
Nov 2025
Message
69
#19

I went through the same thing. Hasty decisions become decisions you have to fix six months later.

Of course, it varies if your situation is different.

MMetin K***Member
Job title
Export manager
Sector
Paper
Organization type
300-person organization
Joined
Nov 2023
Message
19
#20

Exactly like that. If permission and scope aren't in writing, don't start that test.

Taking notes for two weeks yields better results than a six-month estimate. This is my opinion, I'm not claiming it's absolute truth.

Reply