Sovereignty
Three datacenters in France, no hyperscaler in the chain.
We own and operate our own rooms. No customer data transits through AWS, Azure or Google Cloud, which keeps the infrastructure out of reach of the US CLOUD Act and extraterritorial orders.
- DC01
- Essarts-en-Bocage (Vendee)
- DC02
- Saint-Gilles-Croix-de-Vie (Vendee)
- DC03
- Nantes (Loire-Atlantique)
- French company, French-law contract, French jurisdiction.
- Operations and on-call handled by the in-house team, with no outsourced support.
Reversibility
Every building block is open source, so you can take it back.
Keycloak, PostgreSQL, GitLab, Grafana, Ceph, Matomo: nothing proprietary, nothing Bunker-specific. If you leave, you leave with a system your own engineers can redeploy elsewhere, with no rewrite and no exit fee.
- No closed critical component and no captive data format.
- Bringing the stack back in-house on your own hardware is written into the contract.
Encryption and isolation
TLS 1.2 minimum in transit, encrypted backups, isolated environments.
Traffic is encrypted in transit, stored data is encrypted at rest on the storage layer, and backups are replicated encrypted to a geographically separate datacenter. The network is segmented per customer environment, behind a CrowdSec WAF and DDoS mitigation.
- WireGuard VPN (Headscale) for administrative access.
- Algorithms and retention periods are documented in our ISMS and shared on request.
ISMS and ISO 27001 programme
An information security management system aligned with ISO 27001: policy, security model and statement of applicability published in our documentation.
ISO 27001 aligned, self-assessed, not certified to date
Our security measures are self-assessed and are not certified by a third party to date. We publish our information security management system, our security model, our ISO 27001:2022 statement of applicability (the status of all 93 controls) and our disclosure policy; the detailed control policies and per-control evidence are shared on request, as our internal review progresses, so your security team can judge on evidence rather than on a logo.
What we are working towards
Certification targeted in the medium term, covering the platform and the datacenters.
French ANSSI qualification as a long-term objective, depending on our resources and market.
Report a vulnerability
Coordinated disclosure, no monetary reward, with a commitment not to sue.
If you find a flaw on our domains, our console or our API, write to us. As long as your research follows our disclosure policy, we consider it authorised and we will not take legal action against you.
- Acknowledgement
- within 48 hours
- Coordinated publication
- after the fix, within 90 days
- Reward
- public credit, no bounty
For your due diligence file
Public buyer, CISO or DPO: the public documentation covers most of the usual questionnaire. For anything contractual or named, write directly to the right person.
- Security questions
- [email protected]
- Data Protection Officer
- [email protected]
Detailed records of processing, insurance certificates and tender documents are available from the DPO on request.