SECURITY · OPERATIONAL SECURITY

A well-designed architecture is only as secure as its operational rigor.

Encryption of data at rest and in transit, rigorous access and identity management, regular external audits, structured incident protocols. Day-to-day security against real technical threats.

WHY OPERATIONS MATTER AS MUCH AS STRUCTURE

A well-designed architecture can be compromised by insufficient operational practices.

The three previous pages of this Security section documented our structural guarantees: infrastructure sovereignty, the product's isolation and confidentiality properties, ethical governance principles and bodies. These structural guarantees are a necessary precondition, but they are not enough. A well-designed architecture can be compromised by insufficient operational practices: absent or misconfigured encryption, overly permissive access management, no logging, nonexistent incident protocols.

This page documents the operational dimension of our security. How we concretely protect data day to day against real technical threats. How we detect and contain incidents. How we quickly restore service after a failure. How we position ourselves against the reference sector standards.

This operational dimension is probably the one a chief information officer, a chief information security officer or a cyber risk director will scrutinize most closely. We commit Imagine All The People to operational standards aligned with the requirements of the large accounts we serve. Without claiming sector certifications we have not yet formally undertaken: this honesty is a deliberate choice of maturity, not an evasion.

THE TECHNICAL PROTECTIONS

Four structuring pillars, systematically mobilized.

Encryption of data at rest and in transit.

All the data we process is encrypted both at rest (on storage servers) and in transit (during transfers between system components, between our infrastructure and our clients' systems, between our users and our platform). We use encryption algorithms compliant with European and international standards: AES-256 for symmetric encryption at rest, TLS 1.3 for encryption in transit. Encryption keys are managed under strict rotation and isolation protocols, on sovereign French infrastructure.

Rigorous access and identity management.

Access to our production systems is under strict controls: mandatory multi-factor authentication for all our technical teams, identity and privilege management under the least-privilege principle, immediate revocation of access when an employee leaves, strict separation between development, pre-production and production environments. Administrator access to critical systems is systematically logged and reviewed a posteriori. No permanent access to client data is granted to technical teams outside precise, logged operational needs.

Regular external audits and penetration testing.

Our infrastructure and platform undergo regular independent external audits: application penetration tests, infrastructure audits, code reviews on critical components. These audits are conducted by specialized firms qualified on the French and European cybersecurity frameworks. Audit reports and the associated corrective measures are documented and can be shared under a non-disclosure agreement with the risk and security teams of our large-account clients who request them as part of their due diligence.

Logging and anomaly detection.

All critical operations on our systems are systematically logged: data access, processing operations, configuration changes, administrator connections. These logs are kept for the applicable legal durations and run through automated anomaly detection: unusual access, suspicious authentication attempts, operations outside normal parameters. Every generated alert is systematically handled by a human on our technical teams.

HOW WE HANDLE INCIDENTS

Detection, containment, communication, restoration, lessons learned.

1. Detection.

Our logging and anomaly detection systems generate continuous alerts on suspicious behavior or operational anomalies. Alerts are automatically classified by criticality and routed to the competent technical teams. Critical incidents trigger an on-call procedure enabling a response within fifteen minutes during business hours and within one hour outside them.

2. Containment.

When an incident is confirmed, our technical teams mobilize structured containment protocols: isolating the affected components, cutting potentially compromised access, preserving technical traces for later analysis. Our product's isolation architecture (detailed on the Confidentiality & isolation page) structurally limits the propagation of an incident across clients: an incident in one client's environment cannot spread to other clients' environments.

3. Communication to the affected clients.

Clients whose data could be affected by an incident are notified within a maximum of 24 hours after confirmation, in line with GDPR obligations and our contractual commitments. The notification comes with a factual description of the incident, its assessed impact on their data, the immediate measures taken and the expected resolution timeline. We commit to full transparency: including when it is commercially unfavorable to us.

4. Restoration.

Our backup protocols enable rapid service restoration after an operational failure or major incident. Production data is backed up continuously, with multiple restore points and regular restoration tests. Our restoration objective after a major incident is under 4 hours for critical services and under 24 hours for all functionality.

5. Lessons learned.

Every significant incident undergoes a structured post-mortem by our technical teams: chronological reconstruction of the incident, identification of root causes, identification of failures in our detection or containment mechanisms, definition of corrective measures to prevent recurrence. These post-mortems are documented and can be shared with the affected clients who request them.

OPERATIONAL ROBUSTNESS AS A STRUCTURAL PRECONDITION

CRISIS MANAGEMENT

Responding within 48 hours to the media disclosure of a contested internal practice.

This case illustrates how the operational robustness of our infrastructure is a structural precondition of the most demanding missions. A listed European industrial group faced the imminent publication of an investigation into a morally contested internal practice. Our team was mobilized at half past midnight, with delivery expected before four in the morning. In under thirty minutes of computation, our agents conducted in-depth interviews with 5,400 synthetic stakeholders across 800 parallel threads. No room was left for technical incident: infrastructure failure, compute saturation, logging breakdown. The operational robustness documented on this page makes possible these extreme missions where deadlines and reliability structurally condition the product's commercial value.

Read the full case →

OUR POSITION ON SECTOR STANDARDS

Alignment with the reference standards, formal certification undertaken at the request of large accounts.

Imagine All The People does not currently hold formally obtained sector certifications: ISO 27001, SecNumCloud, HDS for healthcare, or sector equivalents. This reality is owned. We do not claim credentials we have not formally undertaken: this honesty seems more reassuring to us than an approximate claim that would not survive a serious audit.

Our operational protections are aligned with the reference standards. The protections described in the previous blocks, encryption, access management, external audits, logging, incident protocols, are designed in line with the requirements of the main sector cybersecurity standards. An external audit conducted against the ISO 27001 or SecNumCloud frameworks could observe this alignment without our being formally engaged in the certification processes.

Certification processes can be undertaken at the request of the large accounts that choose us. A public or private large account requiring a specific sector certification as part of a structuring partnership can ask Imagine All The People to undertake the corresponding formal process. This flexibility, no upfront over-commitment to certifications costly in time and resources, but adaptation to the real requirements of the large accounts that choose us, seems to us a more honest position for a company at our stage of development.

Our methodological traceability complements operational security. Beyond classic cybersecurity standards, our discipline mobilizes a specific methodological traceability: complete auditability of reasoning, restitution of decision paths, contestability by independent third parties. These mechanisms, detailed on the Regulatory traceability page, complement operational security on the specific stakes of our activities.

Une décision à prendre, une population de synthèse qui y répond, un éclairage

Want to audit our operational security?

Chief information officers, chief information security officers, cyber risk teams, large-account procurement teams: our technical team can provide you with the detailed documentation of our operational protections, recent external audit reports under a non-disclosure agreement, and the conditions under which we undertake sector certification processes at the request of the large accounts that choose us.

See our regulatory traceability →