Risk Management Policy
This policy describes how Bunker identifies, assesses and treats the risks bearing on information security. On the risk dimension, it implements the principles of our information security policy and covers controls A.5.4, A.5.35 and A.5.36 of the Statement of Applicability.
Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.
Purpose and scope
This policy applies to the ISMS scope, namely building the platform and hosting it in our three datacenters located in France. It covers technical risks (vulnerabilities, unavailability, data leakage), organisational risks (governance, formalisation) and contractual risks (subprocessors, regulatory obligations).
Principles
- Status is evidenced, not declared: every control is assessed against concrete evidence (infrastructure configuration, code, procedures, contracts).
- Under-declare rather than over-declare: a control with an outstanding element is declared partial, never "implemented".
- Publish the assessment: our risk assessment is visible in the Statement of Applicability, without anyone having to ask for it.
- Compensate explicitly: an accepted gap on one site is treated as a compensated measure through the multi-datacenter architecture, and that compensation is written down rather than implied.
- Independence of review: an external audit is only worth something if it is independent from the customer requesting it.
Measures
| Area | Measure |
|---|---|
| Assessment | Self-assessment of the 93 Annex A controls of ISO/IEC 27001:2022, control by control, each status backed by evidence and published in our Statement of Applicability (A.5.36). |
| Treatment | Every partial or planned control carries its remaining gap and the measure that closes it; physical gaps on a given site are treated as measures compensated by multi-datacenter resilience (A.5.36). |
| Governance | Engineering governance documented (mandatory merge-request review, recorded architecture decisions); a formal ISMS management-responsibility directive to be finalised (A.5.4, partial). |
| Internal review | CVE and security-advisory monitoring across the stack, backed by continuous vulnerability supervision; compliance with engineering standards machine-enforced in continuous integration (A.5.35, A.5.36). |
| Independent review | External penetration test planned for the ISO 27001 certification path; no third-party audit to date (A.5.35, planned). |
| Cadence | A periodic ISMS-level compliance review to be set to a cadence; the Statement of Applicability carries its last-reviewed date (A.5.36, partial). |
The external penetration test is tied to the certification path rather than triggered case by case at a customer's request, which is what guarantees it covers the whole scope, and not only the subset a given buyer cares about.
Responsibilities
- The CISO (François-Guillaume Ribreau) owns this policy, the risk assessment and the statuses published in the Statement of Applicability.
- The DPO (Robin Straub) owns the assessment of risks bearing on personal data.
- Anyone identifying an uncovered risk reports it to [email protected].
Status and roadmap
Risk assessment is operational and published. The Statement of Applicability covers all 93 controls and serves as our register of gap treatment. Three items remain open, consistent with their declared status, namely the formal ISMS management-responsibility directive (A.5.4, partial), the compliance-review cadence at ISMS level (A.5.36, partial) and the independent review. The external penetration test and third-party audit belong to the ISO 27001 certification path (A.5.35, planned).
Review
This policy is reviewed at least once a year and whenever our scope, our infrastructure or the applicable regulatory framework changes significantly.
Last reviewed: 31 August 2026.
See also
- Statement of Applicability (the status of all 93 controls, one by one)
- Security Model (the horizontal resilience our compensated measures rest on)
- Supplier Security Policy (the risk carried by our subprocessors)
- Information Security Policy (the ISMS framework this policy derives from)