Compliance notice

Security &
Compliance

Bunker's legal commitments on data protection. The technical and organisational security posture is published in the trust center.

The full security posture is public

Sovereign infrastructure, encryption, an ISO 27001 aligned information security management system and vulnerability disclosure are all detailed in the trust center.

Open the trust center

Regulatory compliance

GDPR Compliant with the General Data Protection Regulation.
DPO Robin Straub ([email protected]).
DPA Data processing agreement available on the dedicated page, together with the list of sub-processors.
CNIL Analytics in CNIL exemption mode (Matomo), with no tracking cookie.

Certifications

Self-assessed security measures, not certified by a third party to date.

Bunker claims no ISO 27001, SecNumCloud or HDS certification. ISO 27001 certification is targeted in the medium term and the SecNumCloud qualification remains a long-term objective; progress is published in the trust center.

Report a vulnerability

If you discover a security vulnerability, report it to us responsibly.

Security contact email

[email protected]

We acknowledge your report within 48 hours and keep you informed of the measures taken. The full terms, including our commitment not to take legal action, are set out in our responsible disclosure policy.

Responsible disclosure policy

Questions about our security?

Contact us at [email protected]

Contact us