Security
Your continuity plans hold your most strategic information. Here's how we protect them.
Encryption everywhere
TLS 1.2 minimum (TLS 1.3 supported) in transit, AES-256 at rest. Keys managed by our cloud infrastructure.
Strong authentication
TOTP 2FA with recovery codes, OAuth and magic link, sessions in secure cookies (__Host-, HttpOnly) with rotation and remote revocation.
RBAC access control
Separate platform and organization roles, full action auditing, SHA-256 tamper-evident chain.
European hosting
Data hosted in the European Union (OVH France / Convex EU). No transfer outside the EU by default.
Audit & logging
Every sensitive action is logged with IP, User-Agent, country and cryptographic hash. Apache cross-check for forensic spoofing detection.
Anomaly detection
Brute-force, credential stuffing and unusual-country logins auto-detected and notified to administrators.
Frameworks & standards
Our current alignment with the leading security and continuity frameworks.
- RGPD / GDPRCompliant
- ISO 27001 (alignment)In progress
- ISO 22301 (alignment)In progress
- DORA-ready (EU 2022/2554)Compliant
- NIS2-ready (EU 2022/2555)Compliant
- SecNumCloud (mapping)In progress
Report a vulnerability
We welcome responsible disclosure. No legal action will be taken against good-faith security researchers.
Or see security.txt for technical details (RFC 9116).