Sovereign Cloud

Security &
Compliance

Bunker operates its own datacenters in France and implements rigorous security measures to protect its clients' data.

Sovereign infrastructure

Bunker operates 3 datacenters in France, with no dependency on hyperscalers (AWS, Azure, GCP). Your data is 100% hosted in France.

Datacenter Location
DC01 Essarts-en-Bocage (Vendee)
DC02 Saint-Gilles-Croix-de-Vie (Vendee)
DC03 Nantes (Loire-Atlantique)

Technical security measures

Encryption

TLS 1.2+ in transit, end-to-end backup encryption.

Network

WireGuard VPN (Headscale), strict network segmentation.

Protection

CrowdSec WAF, DDoS protection, intrusion detection.

Access

Centralized access control, access logging, strong authentication (Keycloak).

Backups

Replicated to a geographically separate datacenter, end-to-end encryption.

Organizational measures

100% in-house support, no outsourced support.
Technical team based in France.
Formalized incident management procedure.
Professional liability and cyber risk insurance.
Continuous team training on data security.

Sovereign technology stack

All critical components are open source and self-hosted in our datacenters:

Keycloak

Authentication

Open Source

PostgreSQL

Databases

Open Source

Matomo

Analytics (CNIL exemption)

Open Source

GitLab

CI/CD

Open Source

Grafana / Loki / Tempo / Mimir

Observability

Open Source

Ceph S3

Object storage

Open Source

DocuSeal

Electronic signatures

Open Source

Regulatory compliance

GDPR Compliant with the General Data Protection Regulation.
DPO Robin Straub ([email protected]).
DPA Available for download on our dedicated page.
CNIL Analytics in CNIL exemption mode (Matomo).

Target certifications

Bunker is pursuing the following certifications:

SecNumCloud

ANSSI qualification for cloud service providers.

ISO 27001

International standard for information security management.

Report a vulnerability

If you discover a security vulnerability, we invite you to report it responsibly.

Security contact email

[email protected]

We commit to analyzing your report within 48 hours and keeping you informed of the measures taken.

Questions about our security?

Contact us at [email protected]

Contact us