What had to be solved
Before a national e-invoicing system carries the country's business-to-business invoices, the revenue authority needs independent evidence that it is secure, protects taxpayer data, performs under load and can be recovered.
- Every VAT-registered business will depend on the system.
- It holds commercial and personal data.
- Its records must stand up to audit.
Scope of the engagement
Penetration testing and vulnerability assessment
Privacy impact assessment
Performance and stress testing
Functional and integration testing
Audit-trail and disaster-recovery assurance
How we approached it
We acted as an independent consultant: our job was to find what was wrong, evidence it and report it so it could be fixed before go-live.
- Planning
- Agree the systems in scope, exclusions, rules of engagement and testing windows.
- Testing
- Reconnaissance, vulnerability scanning and exploitation attempts, the way an attacker would work.
- Validation
- Confirm each finding and remove false positives before it is reported.
- Reporting
- An executive summary, technical findings and a remediation checklist, reviewed by a senior consultant.
Security and compliance
- Rules of engagement
- Testing ran only against agreed systems, within agreed windows.
- Confidential findings
- Vulnerabilities were reported to NRS only and are not published.
- Privacy impact
- Personal-data processing in the system was assessed as part of the scope.
How it was delivered
Scope and acceptance
Scope agreed in writing and commercial terms accepted before work began.
Assurance testing
Delivered against the agreed scope, with weekly status reports.
Internal QA
Every deliverable reviewed internally before it reached the client.
Client review and acceptance
Deliverables reviewed with the client and accepted in writing before close-out.
Results and status
Assurance testing completed.
Evidence · Completion confirmed by Byteflow, 9 October 2026