Skip to main content

GDPR Article 32 Documentation Pack

Security of Processing Statement

In accordance with Article 32 of the GDPR, Noxys Security SAS maintains a comprehensive security program designed to ensure the confidentiality, integrity, and availability of processed data.

1. Pseudonymization and Encryption

  • Hashing: Raw AI prompts are hashed using SHA-256 locally in the user's browser.
  • TLS 1.3: Mandatory for all data in transit.
  • AES-256: Standard for all persistent storage volumes.

2. Confidentiality and Integrity

  • RBAC: Granular permissions (Admin, Viewer, Security Officer).
  • Audit Logging: Every policy decision and administrative action is logged and immutable.
  • Tenant Isolation: Database-level isolation prevents cross-tenant data leakage.

3. Availability and Resilience

  • Kubernetes Cluster: Deployed on Scaleway (EU) with multi-zone redundancy.
  • Backups: Daily encrypted backups with 30-day retention.
  • SLA: 99.9% availability commitment for Business and Enterprise tiers.

4. Regular Testing and Evaluation

  • SAST/DAST: Automated security scanning in CI/CD pipelines.
  • Pentesting: Annual third-party penetration testing (starting 2026-Q3).
  • Vulnerability Management: Remediation SLAs for high and critical vulnerabilities.

5. Sovereignty Safeguards

  • 100% EU Infrastructure: No reliance on US-owned cloud providers for core processing.
  • No CLOUD Act Exposure: Sovereign legal framework ensures data immunity from foreign warrants.