Security

Built for the most demanding organizations

Encryption by design, full isolation and complete traceability — for your most sensitive crisis data.

  • Per-tenant encryption

    Each organization has its own AES-256 encryption key. Only the tenant administrator can decrypt its data: the key stays in your hands.

  • Mandatory MFA

    Multi-factor authentication (TOTP) is mandatory per organization. The second factor is required for everyone, administrators included.

  • Granular RBAC

    Seven application roles — administrator, facilitator, observer, participant, crisis manager, internal and external stakeholder — plus the per-exercise roles. Platform administration forms a perimeter distinct from an organization's.

  • Complete audit trail

    All sensitive actions (POST, PUT, PATCH, DELETE) are logged with identity, timestamp and source IP. SIEM-compatible export.

  • Sovereign hosting

    Infrastructure hosted in France, with a French operator, end to end. Self-hosted database and object storage, objects encrypted at rest.

  • Your regulatory regime, taken into account

    Your regime — NIS2, DORA, LPM, HDS, PCI-DSS, ISO 27001 — is declared in the organization profile, then taken into account when generating scenarios, units and deliverables. CrisisLab applies the corresponding technical measures; official certification remains to be obtained.

  • OIDC SSO

    Authentication delegated to your identity provider over OpenID Connect, configured per organisation. Your password, session and revocation rules keep applying.

  • Admin console behind mTLS

    The platform console opens on a valid client certificate: it alone grants access, password included.

  • Scoped service accounts

    Integrations use dedicated API keys, limited to explicit scopes and revocable independently of user accounts.

  • AI under governance

    Lena acts through a catalogue of tools bounded by module and by right; every call is logged, usage is capped by quotas, and the sovereign option confines models to a French operator. When she answers from her own knowledge, she says so.

  • One memory per organisation

    One agent per tenant: every memory stays inside its organisation. What Lena learns at your place — documents, exercises, decisions — belongs to you, and the platform sets the generic only.

Compliance frameworks

Declare your regime: it steers the scenarios proposed, the crisis units assembled and the deliverables produced.

  • NIS2

    Documented, traceable regulatory exercises

  • DORA

    Operational resilience testing for financial entities

  • LPM

    Suited to operators of vital importance under French military programming law

  • HDS

    For healthcare organisations and health data hosting providers

  • ISO 27001

    Exercises filed as evidence for your management system

  • GDPR

    Data hosted in France, bounded retention, data subject rights respected

Questions about security?

Our team can provide detailed compliance documentation.