Skip to content
KOLOSALTech
Security & compliance

How we secure ourselves.

Transparency on the technical and organizational measures KOLOSALTech applies internally. You cannot entrust us with your cyber if we are not exemplary ourselves.

Technical measures

Technical measures

Encryption in transit

TLS 1.3 on all exposed services. HSTS preload on kolosaltech.com. Let's Encrypt certificates renewed automatically.

Encryption at rest

Client data encrypted with AES-256 at rest (Airtable, Vercel KV, sourced cloud storage). Keys managed by certified providers.

Mandatory MFA

TOTP/FIDO2 MFA on all our admin accounts (Vercel, GitHub, Airtable, Resend, Cloudflare, Stripe). No admin account without MFA.

Password management

Centralized vault (Bitwarden Teams). No passwords shared in clear text (email, doc, Slack). Preventive 90-day rotation on critical secrets.

EDR on internal endpoints

Bitdefender GravityZone Premium on all team endpoints. Centralized console + real-time alerts.

Immutable backup

3-2-1-1-0 architecture: local NAS with BTRFS snapshots + immutable object cloud (Wasabi Object Lock). Automatic monthly test.

Patch management

OS + application patches applied within 7 days for critical ones, 30 days otherwise. Up-to-date inventory, no unsupported OS.

Centralized logs

Application logs (Vercel) + security (Sentry) + access (Cloudflare) correlated. Retention 30 days min, 1 year for audit.

Organizational measures

Organizational measures

Documented security policy

Written ISSP, reviewed annually, approved by management. Available on request under NDA.

Access management

Tier model: Tier 0 admin · Tier 1 production · Tier 2 tools. Principle of least privilege. Quarterly access review.

Onboarding / offboarding

Formalized procedure: account provisioning on day 1, immediate revocation on departure (< 1h). Up-to-date hardware inventory.

Continuous training

Quarterly phishing awareness for the whole team. Daily CVE monitoring. NIS2/DORA training for management.

Supply chain security

Annual audit of critical suppliers (hosting providers, software vendors, forwarders). Security clauses in contracts. SBOM on delivered products.

Business continuity plan

BCP / DRP documented. RTO 4h / RPO 1h on critical services. Annual full-scale test.

Incident management

Incident management

Detection

Sentry monitoring 24/7 + priority email alerts to management. Weekly security KPI dashboard.

Notification

In the event of an incident impacting a client: notification within 24h with technical detail. Compliant with NIS2 deadlines (24h pre-notification, 72h detailed).

Response

Written incident procedure. Dedicated emergency number for clients under managed-services contract. Post-mortem shared within 30 days.

CNIL notification

Documented procedure for notifying the CNIL (French data protection authority) within 72h in the event of a personal data breach (GDPR art. 33).

Regulatory compliance

Regulatory compliance

GDPR

Records of processing activities maintained. DPA available. Privacy by design in our client deployments. EU hosting prioritized.

NIS2 (in preparation)

NIS2 self-assessment in progress. Compliance target within 6 months. See our NIS2 SME guide for the client framework.

Sovereign hosting

EU datacenters favored (OVHcloud Roubaix, Scaleway Paris, Vercel cdg1, Wasabi Paris, Cloudflare EU). No US hosting for sensitive client data.

ANSSI-qualified solutions

Systematic recommendation of ANSSI security visa solutions (Stormshield, Tehtris, Wallix Bastion) for sensitive sectors.

Need a DPA or supplier audit?

Standard DPA, supplier questionnaire, EU hosting attestation, continuity plan — available on request under NDA for prospects under evaluation.