Physical and Environmental Security Policy
This policy describes how Bunker protects the premises, server rooms and equipment that carry its platform. On the physical dimension, it implements the principles of our information security policy and covers controls A.7.1 to A.7.14 of the Statement of Applicability.
Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.
Purpose and scope
Bunker owns and operates its three datacenters in France: Essarts-en-Bocage (Vendée), Saint-Gilles-Croix-de-Vie (Vendée) and Nantes (Loire-Atlantique). Physical security is therefore not delegated to a third-party host; it is part of the ISMS scope.
This policy covers the server rooms and the premises housing them, the equipment installed there, the supporting utilities (power, cooling, cabling) and storage media through to disposal. It applies to employees and to contractors working on site.
Principles
- Owned perimeter, not outsourced: the premises are under our exclusive control, which makes us accountable for their level of protection and for their gaps alike.
- Horizontal resilience rather than single-site infallibility: the loss of an entire datacenter is an event anticipated by design. Partial hardening at a given site is treated as a compensated measure through the multi-datacenter architecture described in our security model.
- Access restricted to authorised personnel: entry to a server room is limited to a restricted list, the physical extension of the least privilege we apply to our systems.
- Site-by-site hardening: the main site leads, the others follow. We declare the gap rather than smooth it over.
- Removed media must be unusable: encryption at rest on the storage layer is the last line of defence when a disk leaves the room.
Measures
| Area | Measure |
|---|---|
| Perimeter | Server rooms located in premises owned by Bunker, perimeter fully under our control (A.7.1). |
| Physical entry | Access control and restricted list in place; badge and electronic logging being deployed, at the main site by June 2027 at the latest (A.7.2). |
| Offices and facilities | Premises under exclusive control; written formalisation of access procedures in progress (A.7.3). |
| Physical monitoring | Video surveillance and intrusion detection active at the main site, being deployed at the other sites (A.7.4). |
| Environmental threats | Fire detection and cooling in place; full coverage being specified (A.7.5). |
| Secure areas | Access restricted to authorised personnel; formal procedures for working in secure areas to be documented (A.7.6). |
| Clear desk and clear screen | Practice applied by the team; a formal policy to be established (A.7.7). |
| Equipment siting | Equipment installed in our own rooms, under our direct physical control (A.7.8). |
| Assets off-premises | Production assets concentrated in our datacenters; framing of the rare off-site assets to be formalised (A.7.9). |
| Storage media | Encryption at rest on the storage layer (removed media is unusable data), plus secure erasure or destruction (A.7.10). |
| Supporting utilities | UPS in place. In the event of a prolonged mains outage, the absence of a generator at some sites is compensated by multi-datacenter resilience, site loss being tolerated (A.7.11). |
| Cabling | Cabling under control in our premises; formalisation in progress (A.7.12). |
| Maintenance | Equipment maintenance performed by our team; a formal procedure to be documented (A.7.13). |
| Disposal | Secure erasure through key destruction (crypto-erase) and physical destruction of decommissioned equipment (A.7.14). |
Responsibilities
- The CISO (François-Guillaume Ribreau) owns this policy and authorises access to the server rooms.
- The operations team maintains the list of authorised individuals and escorts any third-party intervention on site (maintenance, delivery, connection work).
- Anyone working on site reports abnormal access, a break-in or an environmental incident without delay to [email protected].
Status and roadmap
Four controls are in place and operational, namely the physical perimeter (A.7.1), equipment siting (A.7.8), storage media protection (A.7.10) and secure disposal (A.7.14).
The others are partial or planned, and our roadmap covers three workstreams, which are deploying badge access and electronic logging (A.7.2) at the main site by June 2027 at the latest; extending video surveillance and intrusion detection to the secondary sites (A.7.4); and writing down the procedures already applied in practice, from premises access to working in secure areas, cabling, maintenance and the clear desk rule (A.7.3, A.7.6, A.7.7, A.7.12, A.7.13).
The absence of a generator at some sites (A.7.11) is not on that list. It is a deliberate engineering choice. Availability comes from failover between datacenters, not from local redundancy at an isolated site.
Review
This policy is reviewed at least once a year and whenever our premises, our equipment or the way we operate them change significantly.
Last reviewed: 31 August 2026.
See also
- Statement of Applicability (the status of controls A.7.1 to A.7.14)
- Security Model (the horizontal resilience principle that compensates for a single site's gaps)
- Infrastructure (the datacenters, storage and network that carry our services)
- Access Control Policy (the logical counterpart to physical access control)
- Information Security Policy (the ISMS framework this policy derives from)