Skip to main content
ResiPlan
ResiPlan

Security

Your continuity plans hold your most strategic information. Here's how we protect them.

Encryption everywhere

TLS 1.2 minimum (TLS 1.3 supported) in transit, AES-256 at rest. Keys managed by our cloud infrastructure.

Strong authentication

TOTP 2FA with recovery codes, OAuth and magic link, sessions in secure cookies (__Host-, HttpOnly) with rotation and remote revocation.

RBAC access control

Separate platform and organization roles, full action auditing, SHA-256 tamper-evident chain.

European hosting

Data hosted in the European Union (OVH France / Convex EU). No transfer outside the EU by default.

Audit & logging

Every sensitive action is logged with IP, User-Agent, country and cryptographic hash. Apache cross-check for forensic spoofing detection.

Anomaly detection

Brute-force, credential stuffing and unusual-country logins auto-detected and notified to administrators.

Frameworks & standards

Our current alignment with the leading security and continuity frameworks.

  • RGPD / GDPR
    Compliant
  • ISO 27001 (alignment)
    In progress
  • ISO 22301 (alignment)
    In progress
  • DORA-ready (EU 2022/2554)
    Compliant
  • NIS2-ready (EU 2022/2555)
    Compliant
  • SecNumCloud (mapping)
    In progress

Report a vulnerability

We welcome responsible disclosure. No legal action will be taken against good-faith security researchers.

Vulnerability report form

Or see security.txt for technical details (RFC 9116).

Security — ResiPlan