1. What we claim, and what we do not
Our security practices are aligned with the ISO/IEC 27001 framework. We are not ISO 27001 certified: no accredited body has audited or certified our information security management system to date.
We would rather state this plainly than maintain an ambiguity your IT department would discover during vendor due diligence.
2. Encryption
- All traffic between your browser and our services is encrypted in transit using TLS, with systematic redirection to HTTPS.
- Stored data is encrypted at rest by our hosting infrastructure.
- Passwords and session tokens are never stored in clear text.
3. Hosting and infrastructure
Socium's infrastructure relies on three main hosting providers: Amazon Web Services (AWS) and Google Cloud Platform (GCP) for application services and production data, and Cloudflare for the public website delivery, denial-of-service protection and application filtering at the edge.
Production platform data is hosted in data centres located in Europe (AWS eu-west / GCP europe-west). Per-country data residency is not offered at this stage.
4. Access control
- Access to the administration area is protected by a one-time code sent by email, then by a cryptographically signed session of limited duration.
- The session cookie is inaccessible to page JavaScript, transmitted only over an encrypted channel, and restricted to the relevant domain.
- Internal access is granted on a least-privilege basis and reviewed whenever the team changes.
- Each customer company's data is logically segregated: no customer can reach another's data.
5. Development and operations
- Public forms are protected against automated submissions and inputs are validated server-side.
- Software dependencies are monitored and updated when a known vulnerability appears.
- Operational secrets are kept out of the source code, in the hosting platform's configuration vault.
- Technical and security logs are retained to support incident investigation.
6. Backups and continuity
Socium commits to strict resilience targets to ensure the continuity of your HR operations:
| Indicator | Target | Description |
|---|---|---|
| Availability (Uptime) | 99.9% | Monthly service availability rate |
| RTO (Recovery Time) | < 4 hours | Maximum time to restore critical services |
| RPO (Recovery Point) | < 1 hour | Maximum acceptable data loss in case of restoration |
Backup strategy:
- Backup cycle: automated daily backups, encrypted with AES-256.
- Data isolation: backups are logically isolated from production environments to prevent any risk of cross-contamination.
- Restore testing: dry-run restoration exercises are carried out quarterly to ensure data integrity and recovery speed.
7. Incident management
In the event of a security incident affecting personal data, we inform the customers concerned without undue delay, with the information they need for their own assessment and any obligations of their own.
Law No. 2008-12 does not impose a notification deadline comparable to the European regulation; we nonetheless undertake to alert our customers as promptly as possible and, where the European regulation applies to the processing concerned, to meet the deadlines it sets.
8. Reporting a vulnerability
If you discover a security flaw in our services, write to [email protected] describing the issue precisely and the steps to reproduce it.
We undertake to acknowledge receipt, keep you informed of progress, and not to pursue legal action against a researcher acting in good faith, without degrading the service or accessing data that is not theirs.
9. Compliance
Processing of personal data is governed by Law No. 2008-12 of 25 January 2008 and declared to the Commission de Protection des Données Personnelles. Details are set out in our privacy policy.
