Skip to main content

Trust Center

How Make IT Safe protects your data

This page brings together the security measures that apply to the Make IT Safe platform, from hosting to incident management, and the documents we share with our customers on request.

Governance

A security policy backed by senior management

Security at Make IT Safe relies on an information security management system (ISMS) built along the ISO/IEC 27001 standard. Its scope covers the development, delivery and operation of the platform.

The CISO sits on the management team and reports every month to the chief executive, who sets the budgets for the security policy. This policy is reviewed every year, or whenever a major change occurs.

Security requirements are passed on to our suppliers. Their contracts carry security clauses, and we assess them in our own solution.

Three levels of documents

The information security policy sets the principles. Directives apply them topic by topic, then procedures describe their technical and organisational implementation.

Named roles

A CISO, a data protection officer, administrators and a product owner, who is accountable for secure development practices.

Trained staff

Every employee signs an information system charter and a confidentiality undertaking, then follows a security awareness and training programme.

In France

All platform data is hosted in datacentres located in France.

6 months

The interval between two security tests of the platform.

1 year

The frequency of the ISMS audit and of the continuity plan test.

Data protection

What happens to your data, from hosting to the end of the contract

Hosted in France

The platform is hosted in France on OVHcloud and 3DS OUTSCALE, in ISO 27001 and ISO 27701 certified datacentres. A dedicated SecNumCloud offer is available.

Encryption

Databases are encrypted, with a key managed by Make IT Safe. All exchanges with the platform go through encrypted connections, and passwords are never stored in clear text.

Backups

Data and systems are backed up every day, with one month of history, a monthly copy and a yearly copy. Copies are encrypted and stored on a remote site.

Reversibility

At the end of the contract, your data is returned to you in an open format, through an encrypted channel. It is then deleted from servers and backups, and a destruction certificate is issued within 30 days.

Access control

Access limited to what is strictly needed

  • Access rights follow two rules: need to know and least privilege. In the solution, permission profiles apply them to your own users.
  • Accounts are personal, including administration accounts. Generic accounts are forbidden.
  • Access to production environments is reviewed every six months, and an employee’s rights are revoked when they leave.
  • Administration actions are logged. Logs are centralised and time-stamped, and an administrator cannot alter an event once it has been collected.
  • The network is split into zones separated by firewalls, where every flow is denied by default. The hosting provider supplies protection against denial-of-service attacks.

Development

Security built into the development cycle

  • Every development is assessed against the OWASP Top 10, and developers are trained on this framework.
  • Development, test and production environments are segregated. Acceptance environments only use fictitious data.
  • A release is qualified in pre-production, then approved by the product owner before going live.
  • Vulnerability monitoring triggers the fixes. Security updates are deployed automatically, with a rollback available.
  • Security tests take place every six months: penetration tests, configuration audit or code audit.

Incidents and continuity

From the report to the return to normal

Any employee and any customer can report an incident or a security flaw. The report then follows the same process, whatever its origin.

Handled incidents are reviewed in committee, to track their status and check that the service levels set in the contract are met.

Qualification and severity

Every report is qualified by a single point of contact, then ranked on four severity levels, assessed on availability, integrity, confidentiality and proof.

Crisis unit

Critical incidents are escalated to a crisis unit. Any personal data breach is notified to the customers concerned.

Post-incident review

Every incident is reviewed with the people involved, and a report records the changes made to security measures.

Business continuity

A continuity plan covers major failures and disasters. It is tested at least once a year through realistic exercises.

Personal data

Our commitments as a processor under the GDPR

For the data you enter in the platform, you are the controller and Make IT Safe is the processor. A data protection officer oversees compliance with the regulation.

Processing on www.makeitsafe.fr is described in the privacy policy, and the conditions of use of the platform in the terms of use.

Make IT Safe undertakes to:

  • Process data only for the purposes set out in the contract.
  • Keep a record of the processing carried out on behalf of its customers.
  • Help its customers respond to data subject requests.
  • Only use sub-processors that provide sufficient guarantees.
  • Keep no copy of the data after the end of the contract, and provide proof of it.

Documents and audits

What our customers can request and verify

Detailed security documents are shared with our customers, on request.

On request

Security Assurance Plan

The reference document: organisation, technical and organisational measures, set out chapter by chapter along the ISO/IEC 27001 standard. It is shared with our customers. The document is in French.

On request

ISMS audit summary

The information security management system is audited every year. A summary of the results can be presented to customers.

One month’s notice

Customer audit

A customer can audit the platform at its own expense, directly or through a third party. Make IT Safe gives access to the documents and people required, and proposes a remediation plan if a shortcoming is found.

One month’s notice

Customer penetration test

A customer can commission a penetration test at its own expense, under an audit agreement signed before each test, which sets out its duration, type and scope.

In practice

Frequently asked questions

Where is the platform data hosted?

In France, on OVHcloud and 3DS OUTSCALE, in ISO 27001 and ISO 27701 certified datacentres. A dedicated SecNumCloud offer is available for organisations that need it.

What happens to our data at the end of the contract?

It is returned to you in an open format, through an encrypted channel. It is then deleted from servers and backups, irreversibly. A destruction certificate is issued within 30 days.

Can Make IT Safe be audited?

Yes. A customer can carry out an audit or a penetration test, directly or through a third party, by giving Make IT Safe one month’s written notice. The third party must not be a competitor, and a penetration test requires an audit agreement signed beforehand.

What is Make IT Safe’s role under the GDPR?

For the data you enter in the platform, you are the controller and Make IT Safe is the processor. For the data collected on this website, Make IT Safe is the controller: the privacy policy describes that processing.

How do I report an incident or a security flaw?

By email to support@makeitsafe.fr, or by phone during business hours. No technical information should travel in clear text: details are exchanged in an encrypted archive.

A security question about the platform?

Our CISO is the point of contact for our customers on all security matters.