MAP
Page under internal review, not published. It depends on elements that must be verified in the entity’s documents before going live. It appears neither in the site map nor on public pages.
Trust Under review

You get verifiable security elements, dated, and their limits.

Your IT department and your procurement team do not need a discourse on security, but dated elements, with their limits and a point of contact. You will find here how the security of the service is organised, what can be shown and what remains restricted. No certification, audit or availability rate appears here without evidence.

Under review Editorial status: this page is neither published, indexed nor listed in the site map.

Organisation

Who answers for the security of the service

Security falls under an identified responsibility within the entity, with periodic reviews and a risk assessment specific to the activity. The corresponding elements are presented in the documentation file, with their limits and their date.

Access management

Access to systems and data is granted according to role, reviewed and logged. The rights table for a programme is settled at the first discussion. Nobody holds access that does not correspond to their role.

Protection of exchanges

Exchanges between your organisation, the service and the parties in the flow are encrypted in transit. Authentication arrangements, authorised channels and exchange formats are settled at the first discussion and described in the integration documentation.

Monitoring

Operations and access are monitored in proportion to the risks identified. The detail of these monitoring measures is not public: publishing it would reduce their effectiveness. We present it, to the extent useful, to organisations conducting a supplier assessment.

Incidents

An incident follows a procedure. We establish its nature and severity, we handle it, we inform the parties concerned, and we draw the lessons learned. The applicable notification time limits are those provided for by the regulations and by the contract, and not a general commercial commitment.

Available audits

The security documents, and their mode of access

A document appears here once it exists and can be provided in the mode indicated. Restricted documents are not hosted on this site.

Information systems security policy Governance, measures, what is covered
Restricted
Incident management procedure Nature, handling, information of the parties
On request
Attestations and audit reports Nature, what is covered, auditor, validity date
On request
Hosting and location of processing Providers concerned and operating regions
On request

Limits and point of contact

This page describes an organisation, not a result. A specific question from your IT department, a security questionnaire to complete or a clause to negotiate are dealt with through a point of contact. We do so with the documents to hand, while the programme is being prepared.

Reporting
A vulnerability reporting channel is only announced once its receipt and handling are operational. In its absence, a vulnerability can be reported through the institutional contact channel.
Continuity
Recovery, external dependencies and the recovery of your data are dealt with on a dedicated page.