Human Resources Security Policy
This policy sets out the security requirements that apply to people, before, during and after their collaboration with Bunker. On the people dimension, it implements the principles of our information security policy and covers controls A.6.1 to A.6.6 of the Statement of Applicability.
Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.
Purpose and scope
This policy applies to anyone with access to systems or data within the ISMS scope, employees and contractors alike, whatever the length of the engagement. Customer support is handled 100 % in-house. No subcontractor works on our customers' requests.
Principles
- Verify before granting access: references and qualifications are checked on hiring, not after the fact.
- Personnel under French or European control: French or European citizenship is verified on hiring, consistent with the SecNumCloud requirement.
- Confidentiality with no exception: the confidentiality clause is in every contract, for employees and contractors alike.
- Least privilege from day one: joining opens the rights strictly needed for the role rather than a generic baseline.
- Leaving matters as much as joining: access revocation and secret rotation are handled with the same rigour as the original grant.
Measures
| Area | Measure |
|---|---|
| Screening | Reference and qualification checks on hiring, and verification of French or European citizenship (A.6.1). |
| Terms of employment | Security and confidentiality clauses in contracts; onboarding to the least-privilege principle (A.6.2). |
| Confidentiality | Confidentiality clause in all contracts, employees and contractors alike (A.6.6). |
| Awareness | Continuous team awareness of security; a formalised training programme to be documented (A.6.3, partial). |
| Discipline | Non-compliance with this policy may lead to disciplinary action, up to termination of the employment or service contract (A.6.4). |
| Termination | Access revocation and secret rotation on departure done in practice; the offboarding procedure is being formalised and made traceable (A.6.5, partial). |
| Reporting | Internal reporting channel and public security contact, completed by our responsible disclosure policy (A.6.8). |
Responsibilities
- The CISO (François-Guillaume Ribreau) owns this policy, the checks performed on hiring and the revocation of access on departure.
- The DPO (Robin Straub) ensures those checks and the personnel data they produce stay proportionate under the GDPR.
- Everyone, employee and contractor alike, protects their credentials and reports any incident or suspected incident without delay to [email protected].
Status and roadmap
Screening, terms of employment, confidentiality undertakings and the disciplinary process are in place and operational (A.6.1, A.6.2, A.6.4, A.6.6). Two items remain in formalisation, and we declare them as such. The awareness and training programme (A.6.3, partial) is continuous today but undocumented, and the traceable offboarding procedure (A.6.5, partial) is applied in practice but not yet formalised. Return of assets (A.5.11) is planned and tied to that same procedure.
Review
This policy is reviewed at least once a year and whenever our organisation or our hiring practices change significantly.
Last reviewed: 31 August 2026.
See also
- Statement of Applicability (the status of controls A.6.1 to A.6.8)
- Access Control Policy (the granting and revocation of rights that accompany joining and leaving)
- Acceptable Use Policy (what everyone may do with the assets made available to them)
- Information Security Policy (the ISMS framework this policy derives from)