Skip to main content

Risk Management Policy

This policy describes how Bunker identifies, assesses and treats the risks bearing on information security. On the risk dimension, it implements the principles of our information security policy and covers controls A.5.4, A.5.35 and A.5.36 of the Statement of Applicability.

Status regarding the ISO/IEC 27001 standard

Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.

Purpose and scope

This policy applies to the ISMS scope, namely building the platform and hosting it in our three datacenters located in France. It covers technical risks (vulnerabilities, unavailability, data leakage), organisational risks (governance, formalisation) and contractual risks (subprocessors, regulatory obligations).

Principles

  • Status is evidenced, not declared: every control is assessed against concrete evidence (infrastructure configuration, code, procedures, contracts).
  • Under-declare rather than over-declare: a control with an outstanding element is declared partial, never "implemented".
  • Publish the assessment: our risk assessment is visible in the Statement of Applicability, without anyone having to ask for it.
  • Compensate explicitly: an accepted gap on one site is treated as a compensated measure through the multi-datacenter architecture, and that compensation is written down rather than implied.
  • Independence of review: an external audit is only worth something if it is independent from the customer requesting it.

Measures

AreaMeasure
AssessmentSelf-assessment of the 93 Annex A controls of ISO/IEC 27001:2022, control by control, each status backed by evidence and published in our Statement of Applicability (A.5.36).
TreatmentEvery partial or planned control carries its remaining gap and the measure that closes it; physical gaps on a given site are treated as measures compensated by multi-datacenter resilience (A.5.36).
GovernanceEngineering governance documented (mandatory merge-request review, recorded architecture decisions); a formal ISMS management-responsibility directive to be finalised (A.5.4, partial).
Internal reviewCVE and security-advisory monitoring across the stack, backed by continuous vulnerability supervision; compliance with engineering standards machine-enforced in continuous integration (A.5.35, A.5.36).
Independent reviewExternal penetration test planned for the ISO 27001 certification path; no third-party audit to date (A.5.35, planned).
CadenceA periodic ISMS-level compliance review to be set to a cadence; the Statement of Applicability carries its last-reviewed date (A.5.36, partial).

The external penetration test is tied to the certification path rather than triggered case by case at a customer's request, which is what guarantees it covers the whole scope, and not only the subset a given buyer cares about.

Responsibilities

  • The CISO (François-Guillaume Ribreau) owns this policy, the risk assessment and the statuses published in the Statement of Applicability.
  • The DPO (Robin Straub) owns the assessment of risks bearing on personal data.
  • Anyone identifying an uncovered risk reports it to [email protected].

Status and roadmap

Risk assessment is operational and published. The Statement of Applicability covers all 93 controls and serves as our register of gap treatment. Three items remain open, consistent with their declared status, namely the formal ISMS management-responsibility directive (A.5.4, partial), the compliance-review cadence at ISMS level (A.5.36, partial) and the independent review. The external penetration test and third-party audit belong to the ISO 27001 certification path (A.5.35, planned).

Review

This policy is reviewed at least once a year and whenever our scope, our infrastructure or the applicable regulatory framework changes significantly.

Last reviewed: 31 August 2026.

See also