Trust center

Our security,
readable before you ask for it

Bunker runs its own datacenters in France on a 100% open-source stack. Our information security management system is published: your team can read it without going through a salesperson.

3 datacentersin FranceEncryptionTLS 1.2+ in transitAccess controlKeycloak, MFALoggingGrafana, Loki, MimirBackup & DRmulti-site replication

Sovereignty

Three datacenters in France, no hyperscaler in the chain.

We own and operate our own rooms. No customer data transits through AWS, Azure or Google Cloud, which keeps the infrastructure out of reach of the US CLOUD Act and extraterritorial orders.

DC01
Essarts-en-Bocage (Vendee)
DC02
Saint-Gilles-Croix-de-Vie (Vendee)
DC03
Nantes (Loire-Atlantique)
  • French company, French-law contract, French jurisdiction.
  • Operations and on-call handled by the in-house team, with no outsourced support.

Reversibility

Every building block is open source, so you can take it back.

Keycloak, PostgreSQL, GitLab, Grafana, Ceph, Matomo: nothing proprietary, nothing Bunker-specific. If you leave, you leave with a system your own engineers can redeploy elsewhere, with no rewrite and no exit fee.

  • No closed critical component and no captive data format.
  • Bringing the stack back in-house on your own hardware is written into the contract.

Encryption and isolation

TLS 1.2 minimum in transit, encrypted backups, isolated environments.

Traffic is encrypted in transit, stored data is encrypted at rest on the storage layer, and backups are replicated encrypted to a geographically separate datacenter. The network is segmented per customer environment, behind a CrowdSec WAF and DDoS mitigation.

  • WireGuard VPN (Headscale) for administrative access.
  • Algorithms and retention periods are documented in our ISMS and shared on request.

ISMS and ISO 27001 programme

An information security management system aligned with ISO 27001: policy, security model and statement of applicability published in our documentation.

Certification status

ISO 27001 aligned, self-assessed, not certified to date

Our security measures are self-assessed and are not certified by a third party to date. We publish our information security management system, our security model, our ISO 27001:2022 statement of applicability (the status of all 93 controls) and our disclosure policy; the detailed control policies and per-control evidence are shared on request, as our internal review progresses, so your security team can judge on evidence rather than on a logo.

What we are working towards

ISO 27001

Certification targeted in the medium term, covering the platform and the datacenters.

SecNumCloud

French ANSSI qualification as a long-term objective, depending on our resources and market.

Report a vulnerability

Coordinated disclosure, no monetary reward, with a commitment not to sue.

If you find a flaw on our domains, our console or our API, write to us. As long as your research follows our disclosure policy, we consider it authorised and we will not take legal action against you.

Security contact

[email protected]

Acknowledgement
within 48 hours
Coordinated publication
after the fix, within 90 days
Reward
public credit, no bounty

For your due diligence file

Public buyer, CISO or DPO: the public documentation covers most of the usual questionnaire. For anything contractual or named, write directly to the right person.

Security questions
[email protected]
Data Protection Officer
[email protected]

Detailed records of processing, insurance certificates and tender documents are available from the DPO on request.

A question the documentation does not answer?

We answer with facts, not with a brochure.