Security

Security & Compliance

Security by design, compliance, data confidentiality and complete traceability for software products that must be trusted in production.

Why this is an absolute priority

Security is not a layer added at the end of a project. It is a design constraint, on a par with performance and availability — and it is the first thing we look at when we take over an existing system.

Recent events are a reminder that no one is out of reach, not even the best-resourced public administrations.

French tax administration — August 2026

The Direction générale des Finances publiques confirmed a data theft following illegitimate access to its information system, spread over three consecutive months: June, July and August 2026. Days later, a vulnerability was found on a second tax administration portal, followed by a data extraction.

Official statement — impots.gouv.fr →
France Travail — January 2026 fine

The CNIL fined France Travail 5 million euros for failing to adequately protect jobseekers data. The 2024 breach affected up to 43 million people, and the agency must now document its corrective measures under a daily penalty.

CNIL decision →

Both cases say the same thing. The question is not whether a system will be targeted, but whether it was built to hold — and whether the organisation running it can show it took the expected measures. The cost of negligence is no longer measured in incidents alone: it now comes with a fine.

Protection
  • Hardening, patching and dependency control
  • Encryption in transit and at rest
  • Secret management and rotation
Access
  • IAM, RBAC and least privilege
  • SSO with OAuth or SAML
  • Audit of sensitive actions
Resilience
  • Backups and restore tests
  • Logging, traces and audit trails
  • Incident response and security reviews

Our approach

We treat security as an absolute priority, for our own products as much as for our clients. That translates into concrete choices at every level of the stack: the dependencies we accept, how secrets are stored and rotated, the permissions each service is granted, what is logged and for how long.

We follow the state of the art rather than habit. The tools, protocols and libraries we use are today reference choices, and we question them as they age: a system considered safe five years ago is not necessarily safe now — which is precisely what the incidents above show.

We support our clients on their own security

Many companies have no dedicated team and discover the subject at the worst possible moment: an audit, a tender, or an incident already under way. We step in at all three.

  • Assessment of an existing system: what actually exposes you, what is urgent, what can wait.
  • GDPR compliance: data mapping, records of processing, processor agreements, retention periods.
  • Hardening: access control, secret management, encryption, backups and real restore tests.
  • Incident readiness: logging, alerting, response procedure and notification obligations.

We sell neither certification nor a label. We make a system defensible — and we tell you plainly what is not yet.

Compliance & GDPR

Data mapping, records of processing, DPAs, retention policies and workflows for data-subject requests.

Talk to us