Built for the most demanding organizations
Encryption by design, full isolation and complete traceability — for your most sensitive crisis data.
Per-tenant encryption
Each organization has its own AES-256 encryption key. Only the tenant administrator can decrypt its data: the key stays in your hands.
Mandatory MFA
Multi-factor authentication (TOTP) is mandatory per organization. The second factor is required for everyone, administrators included.
Granular RBAC
Seven application roles — administrator, facilitator, observer, participant, crisis manager, internal and external stakeholder — plus the per-exercise roles. Platform administration forms a perimeter distinct from an organization's.
Complete audit trail
All sensitive actions (POST, PUT, PATCH, DELETE) are logged with identity, timestamp and source IP. SIEM-compatible export.
Sovereign hosting
Infrastructure hosted in France, with a French operator, end to end. Self-hosted database and object storage, objects encrypted at rest.
Your regulatory regime, taken into account
Your regime — NIS2, DORA, LPM, HDS, PCI-DSS, ISO 27001 — is declared in the organization profile, then taken into account when generating scenarios, units and deliverables. CrisisLab applies the corresponding technical measures; official certification remains to be obtained.
OIDC SSO
Authentication delegated to your identity provider over OpenID Connect, configured per organisation. Your password, session and revocation rules keep applying.
Admin console behind mTLS
The platform console opens on a valid client certificate: it alone grants access, password included.
Scoped service accounts
Integrations use dedicated API keys, limited to explicit scopes and revocable independently of user accounts.
AI under governance
Lena acts through a catalogue of tools bounded by module and by right; every call is logged, usage is capped by quotas, and the sovereign option confines models to a French operator. When she answers from her own knowledge, she says so.
One memory per organisation
One agent per tenant: every memory stays inside its organisation. What Lena learns at your place — documents, exercises, decisions — belongs to you, and the platform sets the generic only.
Compliance frameworks
Declare your regime: it steers the scenarios proposed, the crisis units assembled and the deliverables produced.
Documented, traceable regulatory exercises
Operational resilience testing for financial entities
LPM
Suited to operators of vital importance under French military programming law
For healthcare organisations and health data hosting providers
ISO 27001
Exercises filed as evidence for your management system
Data hosted in France, bounded retention, data subject rights respected
Questions about security?
Our team can provide detailed compliance documentation.

