Security & Trust · Operations
Security is determined by day-to-day controls.
Identities, access, encryption, secrets, logs, vulnerabilities, backups and incidents: the register below presents the key operational controls and their actual status, scope by scope.
Identity & access
Who connects, with what permissions.
Data & encryption
Flows and storage.
Secrets & privileges
Keys, credentials, technical access.
Logging & detection
What is recorded and monitored.
Vulnerabilities & incidents
Remediation and handling.
Backup & recovery
Restoration.
Who has access, with what permissions.
Named accounts and MFA (technical teams)
Access by our teams to production environments is subject to multi-factor authentication and named, logged accounts.
Scope — Environments we operate.
Statut : EN PLACE
Client-side authentication
The authentication method for client users depends on the configuration selected during scoping; it is not imposed by default for every profile.
Statut : CONFIGURABLE
Permissions
Rights tied to role and to the scope of the relevant engagement.
Statut : CONFIGURABLE
Privileged access
Reserved for staff whose technical role requires it, for operations, diagnostics or incident handling.
Statut : EN PLACE
Account lifecycle
Access is revoked when a staff member leaves or an engagement ends; development, pre-production and production environments are separated.
Statut : EN PLACE
What protects data in transit, at rest and outside the codebase.
Encryption in transit
TLS 1.3 for user traffic and flows between internal components.
Scope — Environments we operate.
Statut : EN PLACE
Encryption at rest
AES-256 for production data and backups.
Scope — Environments we operate.
Statut : EN PLACE
Secrets
API keys and credentials stored in a dedicated secrets store, separate from code, with restricted access and the ability to revoke them without redeployment.
Statut : EN PLACE
What is recorded, and what is monitored.
- Access
- Connections to environments we operate.
- Administration
- Privileged operations and configuration changes.
- Technical
- Execution errors and operational events.
- Engagement
- Executions associated with an engagement, for diagnostic purposes and not for content analysis.
Monitoring
Operational logs are monitored for diagnostic purposes.
Statut : EN PLACE
Alerts
Technical alerts trigger review of an event; no 24/7 on-call coverage is in place by default.
Statut : EN PLACE
From reporting to verification.
- Detection
- Assessment
- Prioritization
- Remediation
- Verification
What happens when a control fails.
No response, notification or resolution timeframe is stated here: applicable timeframes are those set out in the engagement contract, where specified.
- 01Detection
Technical alert, client report or internal observation.
- 02Assessment
Technical incident, security incident or data breach.
- 03Containment
Isolation of affected components.
- 04Investigation
Reconstruction from available logs.
- 05Recovery
Service restoration and data recovery where necessary.
- 06Information
Notification of the affected client according to the contract.
- 07Post-incident review
Root-cause analysis and follow-up actions.
A security incident is not necessarily a data breach that triggers a notification obligation. View compliance →
What is backed up, and how it is restored.
- What is backed up
- Production data from the environments we operate.
- Encryption
- Backups are encrypted.
- Recovery
- Documented procedure, reviewable during scoping.
- Frequency / retention
- Defined with the client according to the selected configuration.
What a security team can ask to examine.
Access architecture
Backup and recovery arrangements
Incident management
Applicable security clauses
Auditable ≠ audited. Certifiable ≠ certified. Certification statuses are addressed on the Compliance →
Operational security reduces risk. It does not eliminate it.
Strong authentication ≠ absence of compromise
A second factor reduces certain credential-based attacks; it does not cover configuration errors or misuse of legitimate access.
Encryption ≠ absence of access
Encryption protects storage and transport, not use: it does not replace permissions or logging.
Logging ≠ perfect detection
A log can help reconstruct an event after the fact; it does not guarantee detection when the event occurs.
Backup ≠ automatic continuity
An encrypted backup is useful only if restoration has been verified for the relevant scope.
Your next decision
Which decision do you want to explore?
Describe your need. We can point you to the right level of support.