Skip to main content

Physical and Environmental Security Policy

This policy describes how Bunker protects the premises, server rooms and equipment that carry its platform. On the physical dimension, it implements the principles of our information security policy and covers controls A.7.1 to A.7.14 of the Statement of Applicability.

Status regarding the ISO/IEC 27001 standard

Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.

Purpose and scope

Bunker owns and operates its three datacenters in France: Essarts-en-Bocage (Vendée), Saint-Gilles-Croix-de-Vie (Vendée) and Nantes (Loire-Atlantique). Physical security is therefore not delegated to a third-party host; it is part of the ISMS scope.

This policy covers the server rooms and the premises housing them, the equipment installed there, the supporting utilities (power, cooling, cabling) and storage media through to disposal. It applies to employees and to contractors working on site.

Principles

  • Owned perimeter, not outsourced: the premises are under our exclusive control, which makes us accountable for their level of protection and for their gaps alike.
  • Horizontal resilience rather than single-site infallibility: the loss of an entire datacenter is an event anticipated by design. Partial hardening at a given site is treated as a compensated measure through the multi-datacenter architecture described in our security model.
  • Access restricted to authorised personnel: entry to a server room is limited to a restricted list, the physical extension of the least privilege we apply to our systems.
  • Site-by-site hardening: the main site leads, the others follow. We declare the gap rather than smooth it over.
  • Removed media must be unusable: encryption at rest on the storage layer is the last line of defence when a disk leaves the room.

Measures

AreaMeasure
PerimeterServer rooms located in premises owned by Bunker, perimeter fully under our control (A.7.1).
Physical entryAccess control and restricted list in place; badge and electronic logging being deployed, at the main site by June 2027 at the latest (A.7.2).
Offices and facilitiesPremises under exclusive control; written formalisation of access procedures in progress (A.7.3).
Physical monitoringVideo surveillance and intrusion detection active at the main site, being deployed at the other sites (A.7.4).
Environmental threatsFire detection and cooling in place; full coverage being specified (A.7.5).
Secure areasAccess restricted to authorised personnel; formal procedures for working in secure areas to be documented (A.7.6).
Clear desk and clear screenPractice applied by the team; a formal policy to be established (A.7.7).
Equipment sitingEquipment installed in our own rooms, under our direct physical control (A.7.8).
Assets off-premisesProduction assets concentrated in our datacenters; framing of the rare off-site assets to be formalised (A.7.9).
Storage mediaEncryption at rest on the storage layer (removed media is unusable data), plus secure erasure or destruction (A.7.10).
Supporting utilitiesUPS in place. In the event of a prolonged mains outage, the absence of a generator at some sites is compensated by multi-datacenter resilience, site loss being tolerated (A.7.11).
CablingCabling under control in our premises; formalisation in progress (A.7.12).
MaintenanceEquipment maintenance performed by our team; a formal procedure to be documented (A.7.13).
DisposalSecure erasure through key destruction (crypto-erase) and physical destruction of decommissioned equipment (A.7.14).

Responsibilities

  • The CISO (François-Guillaume Ribreau) owns this policy and authorises access to the server rooms.
  • The operations team maintains the list of authorised individuals and escorts any third-party intervention on site (maintenance, delivery, connection work).
  • Anyone working on site reports abnormal access, a break-in or an environmental incident without delay to [email protected].

Status and roadmap

Four controls are in place and operational, namely the physical perimeter (A.7.1), equipment siting (A.7.8), storage media protection (A.7.10) and secure disposal (A.7.14).

The others are partial or planned, and our roadmap covers three workstreams, which are deploying badge access and electronic logging (A.7.2) at the main site by June 2027 at the latest; extending video surveillance and intrusion detection to the secondary sites (A.7.4); and writing down the procedures already applied in practice, from premises access to working in secure areas, cabling, maintenance and the clear desk rule (A.7.3, A.7.6, A.7.7, A.7.12, A.7.13).

The absence of a generator at some sites (A.7.11) is not on that list. It is a deliberate engineering choice. Availability comes from failover between datacenters, not from local redundancy at an isolated site.

Review

This policy is reviewed at least once a year and whenever our premises, our equipment or the way we operate them change significantly.

Last reviewed: 31 August 2026.

See also