The data you entrust to us is extremely valuable.
We guarantee the security, confidentiality, availability, and integrity of your data.
Security is at the heart of our platform.
01 - SAFETY
Hardware, network, database, source code, and ongoing team training.
02 - CONFIDENTIALITY
Access limited to what is strictly necessary, AES-256 encryption, and anonymization.
03 - AVAILABILITY
Hosting in France, multi-data-center replication, and tested backups.
04 - INTEGRITY
Controlled authentication, audit logs, and traceability for every change.
A locked-down technical environment, from the workstation to production
Every layer of our infrastructure is protected and isolated, and every team member is trained on the risks that apply to them.
Computer Equipment
- Automatic Session Lockout
- Full-disk encryption
- Antivirus protection and firewalls deployed across the entire network
Network & Database
- VPN-Encrypted Network Connection
- Complex passwords that are changed periodically
- Strict separation of development, testing, and production environments
Source code
- Strictly controlled access to the code
- Systematic peer review prior to each merger
- Centralized rights management across all of our SaaS tools
Teams
- Regular training and awareness-raising on data security
- Safety and Privacy Policy signed by all members
Your data can only be accessed by those who need to see it
End-to-end encryption, isolated environments, and access permissions defined by your administrators: everyone sees only what they need to see.
Empowering Teams
- Routine background checks on applicants
- Confidentiality Agreement signed by all of our members
- Access to customer data is limited solely to those projects that warrant it
Data Encryption
- AES-256 encryption for both transmission and storage
- Encrypted backups at the same level as production data
- Anonymization of Sensitive Data
Granular Access Rights
- Management of Permissions and Roles Assigned by Administrators
- Read-only or publishing rights, depending on the scope
- Access can be revoked at any time without the need for our team to intervene
Protection of Recipients' Data
- Each beneficiary can access only their own information
- Administrators precisely define access scopes
- Sensitive documents are accessible only to authorized individuals
Access Logging
- Every access to sensitive data is logged
- Access logs are retained and audited
- Abnormal activity is detected quickly
Environment Isolation
- Strictly Separate Development, Testing, and Production Environments
- Production data is never used for development purposes
Hosted in France, continuously replicated
No data leaves French territory, and no incident at a data center can prevent you from accessing it.
Data Hosting
- 100% of data and backups are hosted in France
- Data replication across multiple data centers to ensure data durability and accessibility in the event of a disaster
Backing Up the Database
- The database is backed up and tested daily, and a backup restoration process is in place.
- Continuous replication of all data across 2 nodes for databases and 3 nodes for storage on AWS S3. Each node is hosted in a specific data center, geographically separate from the others
- In the event of an incident at a data center, the data stored there is automatically replicated
Every access and every change leaves a trace
Equify's audit logs make it easy to track the history of changes
Access Security
- Mandatory user authentication via email and password (governed by a strict policy)
- Logging of connections and connection attempts to detect potential fraudulent use of accounts
- Internal data access is restricted to duly authorized employees via a VPN
Traceability of System Access and Data Modifications
- Implementation of audit logs to identify and archive all access to systems, as well as all access to and modifications of data on those systems
- Identification and separate logging of all system-related technical events, such as errors
- Automatic replication of logs three times across three remote data centers in France (AWS servers, ISO 27001-certified), with automatic failover from one to another in the event of an incident
Frequently asked questions
Where is the data entrusted to Equify stored?
All data, including backups, is hosted in France at ISO 27001-certified data centers. It is continuously replicated across multiple geographically separate centers to ensure its durability and accessibility.
Who at Equify can access my data?
Only members whose duties require it, following a background check and the signing of a confidentiality agreement.
How is the data encrypted?
Yes. Equify supports eIDAS-compliant electronic signatures for governance documents: powers of attorney, attendance sheets, resolutions, and other documents. Each signature is time-stamped and stored in the relevant body’s file.
What happens if there's an incident at a data center?
The data stored in the relevant data center is automatically replicated and served from the other centers. The database is backed up and tested daily, with a documented recovery process.
Do Equify's electronic signatures have legal validity?
Yes. The electronic signatures built into Equify comply with the European eIDAS Regulation. Each signature is time-stamped and archived along with the relevant document and instance.