Skip to main content

Information Security Policy

Bunker builds its platform and hosts it in datacenters it owns and operates, in France. This page describes our information security management system (ISMS), what it covers, who is accountable for it, and the measures we apply.

Status regarding the ISO/IEC 27001 standard

Our ISMS is aligned with the ISO/IEC 27001 standard. Our controls are self-assessed. They are not certified by a third party to date. ISO 27001 certification is a stated objective.

Scope

The ISMS covers Bunker's entire activity:

  • the development of the platform (console, API, nuage CLI) and of the managed services we operate;
  • hosting in our three datacenters located in France, in Essarts-en-Bocage (Vendée), Saint-Gilles-Croix-de-Vie (Vendée) and Nantes (Loire-Atlantique), with no dependency on a hyperscaler;
  • the data entrusted to us by our customers, access credentials, operational logs and internal company information.

We own our datacenters and our own team operates them. Physical security is part of the scope, not delegated to a third-party provider. The technical foundations of this hosting are described in our infrastructure documentation.

Governance and responsibilities

RoleHolderContact
Chief Information Security Officer (CISO)François-Guillaume Ribreau[email protected]
Data Protection Officer (DPO)Robin Straub[email protected]

Everyone with access to sensitive information (employees, contractors, suppliers) is responsible for protecting it under this policy. That means restricting access to authorised individuals only, protecting one's credentials, and reporting any incident or suspected incident to the security contact without delay.

Guiding principles

  • Accountability for information security is held by a named person, the CISO.
  • Policies and procedures are kept up to date and made available to the relevant stakeholders.
  • The team receives continuous training on data security.
  • Technical and organisational measures protect information assets.
  • Procedures are in place to correct and prevent deviations and incidents.
  • We comply with applicable laws and regulations, starting with the GDPR, under French law.
  • We publish our security posture rather than reserving it for those who ask: our components are open source and our infrastructure can be re-internalised by the customer.
  • We review our security objectives to progress towards ISO 27001 compliance.

Technical measures

AreaMeasure
EncryptionTLS 1.2 minimum for data in transit; encryption of backups
NetworkStrict segmentation, WireGuard VPN (Headscale) for operational access
Perimeter protectionCrowdSec WAF, denial-of-service protection, intrusion detection
Access controlCentralised and strong authentication through Keycloak, access logging
BackupsReplicas in a geographically separate datacenter, encrypted
ObservabilityCentralised logs, metrics and traces (Grafana, Loki, Tempo, Mimir)
Security maintenanceMonitoring of published vulnerabilities and patching of the components we manage

How platform authentication works is detailed on the Authentication page. The backup and restore mechanisms available to customers are covered in the backup guide.

Organisational measures

  • 100 % in-house support: no subcontractor handles customer support.
  • Technical team based in France, under French law.
  • Formalised incident management procedure.
  • Professional liability and cyber-risk insurance.
  • Critical components are open source and self-hosted in our datacenters, which makes the infrastructure auditable and re-internalisable.

Detailed policies

This page gives the overview; the detail lives in our topic-specific policies. Each maps to the matching ISO/IEC 27001:2022 controls in the Statement of Applicability and states its status without over-stating it.

For a procurement file, it all fits on one page: download the security dossier (PDF), which covers the scope, the governance, the status of all 93 controls and the policy index.

Governance and access

Data and cryptography

Infrastructure and development

Operations and resilience

Regulatory compliance

Bunker processes personal data under the General Data Protection Regulation and French law, and publishes the status of each GDPR obligation, control by control, in its Statement of Applicability and its Personal Data Protection Policy. The corresponding contractual commitments (data processing agreement, list of subprocessors, information notices) are published on the website:

The record of processing activities required by Article 30 of the GDPR is provided on request to the DPO.

Target certifications

  • ISO/IEC 27001: the international standard for information security management. Priority milestone, targeted in the medium term. Our controls are self-assessed today, with no certification audit: their status, control by control, is published in our Statement of Applicability.
  • SecNumCloud: the French ANSSI qualification for cloud service providers. Long-term objective, subject to how our resources and our market evolve.

We claim no certification we do not hold. Any change to this status will be published on this page.

Reporting a vulnerability

If you find a security flaw in our services, write to [email protected]. We acknowledge receipt within 48 hours. The rules of engagement (scope, mutual commitments, legal protection for the researcher) are set out in our responsible disclosure policy.

Non-compliance and review

Failure to comply with this policy may lead to disciplinary action, up to and including termination of the employment or service contract.

This policy is reviewed at least once a year, and whenever our technology, our practices or the regulatory framework change significantly.

Last reviewed: 26 August 2026.

See also