Security & Trust · Operations

Security is determined by day-to-day controls.

Identities, access, encryption, secrets, logs, vulnerabilities, backups and incidents: the register below presents the key operational controls and their actual status, scope by scope.

Identity & access

Who connects, with what permissions.

Data & encryption

Flows and storage.

Secrets & privileges

Keys, credentials, technical access.

Logging & detection

What is recorded and monitored.

Vulnerabilities & incidents

Remediation and handling.

Backup & recovery

Restoration.

Six operational control domains, from identity through recovery.

Control surface. Summary view of the domains examined; it does not represent a security score.
01Identity & access

Who has access, with what permissions.

  • Named accounts and MFA (technical teams)

    Access by our teams to production environments is subject to multi-factor authentication and named, logged accounts.

    Scope — Environments we operate.

    Statut : EN PLACE

  • Client-side authentication

    The authentication method for client users depends on the configuration selected during scoping; it is not imposed by default for every profile.

    Statut : CONFIGURABLE

  • Permissions

    Rights tied to role and to the scope of the relevant engagement.

    Statut : CONFIGURABLE

  • Privileged access

    Reserved for staff whose technical role requires it, for operations, diagnostics or incident handling.

    Statut : EN PLACE

  • Account lifecycle

    Access is revoked when a staff member leaves or an engagement ends; development, pre-production and production environments are separated.

    Statut : EN PLACE

02Data, encryption, secrets

What protects data in transit, at rest and outside the codebase.

  • Encryption in transit

    TLS 1.3 for user traffic and flows between internal components.

    Scope — Environments we operate.

    Statut : EN PLACE

  • Encryption at rest

    AES-256 for production data and backups.

    Scope — Environments we operate.

    Statut : EN PLACE

  • Secrets

    API keys and credentials stored in a dedicated secrets store, separate from code, with restricted access and the ability to revoke them without redeployment.

    Statut : EN PLACE

03Logs & detection

What is recorded, and what is monitored.

Access
Connections to environments we operate.
Administration
Privileged operations and configuration changes.
Technical
Execution errors and operational events.
Engagement
Executions associated with an engagement, for diagnostic purposes and not for content analysis.
  • Monitoring

    Operational logs are monitored for diagnostic purposes.

    Statut : EN PLACE

  • Alerts

    Technical alerts trigger review of an event; no 24/7 on-call coverage is in place by default.

    Statut : EN PLACE

04Vulnerabilities

From reporting to verification.

  1. Detection
  2. Assessment
  3. Prioritization
  4. Remediation
  5. Verification
No contractual remediation deadline is defined for the standard service. External assessment measures are stated according to their actual status: no penetration test or independent external audit has been performed on the service to date.
05Incidents

What happens when a control fails.

No response, notification or resolution timeframe is stated here: applicable timeframes are those set out in the engagement contract, where specified.

  1. 01Detection

    Technical alert, client report or internal observation.

  2. 02Assessment

    Technical incident, security incident or data breach.

  3. 03Containment

    Isolation of affected components.

  4. 04Investigation

    Reconstruction from available logs.

  5. 05Recovery

    Service restoration and data recovery where necessary.

  6. 06Information

    Notification of the affected client according to the contract.

  7. 07Post-incident review

    Root-cause analysis and follow-up actions.

Incident handling sequence. The duration of each stage depends on the nature of the incident.

A security incident is not necessarily a data breach that triggers a notification obligation. View compliance →

06Backup & recovery

What is backed up, and how it is restored.

What is backed up
Production data from the environments we operate.
Encryption
Backups are encrypted.
Recovery
Documented procedure, reviewable during scoping.
Frequency / retention
Defined with the client according to the selected configuration.
07Evidence

What a security team can ask to examine.

  • Access architecture

  • Backup and recovery arrangements

  • Incident management

  • Applicable security clauses

Auditable ≠ audited. Certifiable ≠ certified. Certification statuses are addressed on the Compliance →

Talk to our team →

08Limitations

Operational security reduces risk. It does not eliminate it.

  • Strong authentication ≠ absence of compromise

    A second factor reduces certain credential-based attacks; it does not cover configuration errors or misuse of legitimate access.

  • Encryption ≠ absence of access

    Encryption protects storage and transport, not use: it does not replace permissions or logging.

  • Logging ≠ perfect detection

    A log can help reconstruct an event after the fact; it does not guarantee detection when the event occurs.

  • Backup ≠ automatic continuity

    An encrypted backup is useful only if restoration has been verified for the relevant scope.

Your next decision

Which decision do you want to explore?

Describe your need. We can point you to the right level of support.

What if you tested
your next decision?

State your decision. See the future it produces.

Explore the product