Security and Data Protection

The data you entrust to us is extremely valuable.

We guarantee the security, confidentiality, availability, and integrity of your data.

COMPANIES WITH THE HIGHEST SECURITY REQUIREMENTS ENTRUST US WITH THEIR SHAREHOLDERS
Aug 9, 2006-2026-01-24-11-9087-PM
Copy of Copy of Investment Fund (1)
Copy of Copy of Investment Fund (2)
Payfit-2
Copy of Investment Fund (3)
Swan-1
Copy of Copy of Investment Funds (4)
Brevo-2
Copy of Copy of Investment Fund (5)

Security is at the heart of our platform.

01 - SAFETY

Hardware, network, database, source code, and ongoing team training.

02 - CONFIDENTIALITY

Access limited to what is strictly necessary, AES-256 encryption, and anonymization.

03 - AVAILABILITY

Hosting in France, multi-data-center replication, and tested backups.

04 - INTEGRITY

Controlled authentication, audit logs, and traceability for every change.

01 - SAFETY

A locked-down technical environment, from the workstation to production

Every layer of our infrastructure is protected and isolated, and every team member is trained on the risks that apply to them.

Computer Equipment

  • Automatic Session Lockout
  • Full-disk encryption
  • Antivirus protection and firewalls deployed across the entire network

Network & Database

  • VPN-Encrypted Network Connection
  • Complex passwords that are changed periodically
  • Strict separation of development, testing, and production environments

Source code

  • Strictly controlled access to the code
  • Systematic peer review prior to each merger
  • Centralized rights management across all of our SaaS tools

Teams

  • Regular training and awareness-raising on data security
  • Safety and Privacy Policy signed by all members
02 - CONFIDENTIALITY

Your data can only be accessed by those who need to see it

End-to-end encryption, isolated environments, and access permissions defined by your administrators: everyone sees only what they need to see.

Empowering Teams

  • Routine background checks on applicants
  • Confidentiality Agreement signed by all of our members
  • Access to customer data is limited solely to those projects that warrant it

Data Encryption

  • AES-256 encryption for both transmission and storage
  • Encrypted backups at the same level as production data
  • Anonymization of Sensitive Data

Granular Access Rights

  • Management of Permissions and Roles Assigned by Administrators
  • Read-only or publishing rights, depending on the scope
  • Access can be revoked at any time without the need for our team to intervene

Protection of Recipients' Data

  • Each beneficiary can access only their own information
  • Administrators precisely define access scopes
  • Sensitive documents are accessible only to authorized individuals

Access Logging

  • Every access to sensitive data is logged
  • Access logs are retained and audited
  • Abnormal activity is detected quickly

Environment Isolation

  • Strictly Separate Development, Testing, and Production Environments
  • Production data is never used for development purposes
03 - AVAILABILITY

Hosted in France, continuously replicated

No data leaves French territory, and no incident at a data center can prevent you from accessing it.

Data Hosting

  • 100% of data and backups are hosted in France
  • Data replication across multiple data centers to ensure data durability and accessibility in the event of a disaster

Backing Up the Database

  • The database is backed up and tested daily, and a backup restoration process is in place.
  • Continuous replication of all data across 2 nodes for databases and 3 nodes for storage on AWS S3. Each node is hosted in a specific data center, geographically separate from the others
  • In the event of an incident at a data center, the data stored there is automatically replicated
04 - INTEGRITY

Every access and every change leaves a trace

Equify's audit logs make it easy to track the history of changes

Access Security

  • Mandatory user authentication via email and password (governed by a strict policy)
  • Logging of connections and connection attempts to detect potential fraudulent use of accounts
  • Internal data access is restricted to duly authorized employees via a VPN

Traceability of System Access and Data Modifications

  • Implementation of audit logs to identify and archive all access to systems, as well as all access to and modifications of data on those systems
  • Identification and separate logging of all system-related technical events, such as errors
  • Automatic replication of logs three times across three remote data centers in France (AWS servers, ISO 27001-certified), with automatic failover from one to another in the event of an incident

Frequently asked questions

Where is the data entrusted to Equify stored?

All data, including backups, is hosted in France at ISO 27001-certified data centers. It is continuously replicated across multiple geographically separate centers to ensure its durability and accessibility.

Who at Equify can access my data?

Only members whose duties require it, following a background check and the signing of a confidentiality agreement.

How is the data encrypted?

Yes. Equify supports eIDAS-compliant electronic signatures for governance documents: powers of attorney, attendance sheets, resolutions, and other documents. Each signature is time-stamped and stored in the relevant body’s file.

What happens if there's an incident at a data center?

The data stored in the relevant data center is automatically replicated and served from the other centers. The database is backed up and tested daily, with a documented recovery process.

Do Equify's electronic signatures have legal validity?

Yes. The electronic signatures built into Equify comply with the European eIDAS Regulation. Each signature is time-stamped and archived along with the relevant document and instance.