GDPR Article 32 Documentation Pack
Security of Processing Statement
In accordance with Article 32 of the GDPR, Noxys Security SAS maintains a comprehensive security program designed to ensure the confidentiality, integrity, and availability of processed data.
1. Pseudonymization and Encryption
- Hashing: Raw AI prompts are hashed using SHA-256 locally in the user's browser.
- TLS 1.3: Mandatory for all data in transit.
- AES-256: Standard for all persistent storage volumes.
2. Confidentiality and Integrity
- RBAC: Granular permissions (Admin, Viewer, Security Officer).
- Audit Logging: Every policy decision and administrative action is logged and immutable.
- Tenant Isolation: Database-level isolation prevents cross-tenant data leakage.
3. Availability and Resilience
- Kubernetes Cluster: Deployed on Scaleway (EU) with multi-zone redundancy.
- Backups: Daily encrypted backups with 30-day retention.
- SLA: 99.9% availability commitment for Business and Enterprise tiers.
4. Regular Testing and Evaluation
- SAST/DAST: Automated security scanning in CI/CD pipelines.
- Pentesting: Annual third-party penetration testing (starting 2026-Q3).
- Vulnerability Management: Remediation SLAs for high and critical vulnerabilities.
5. Sovereignty Safeguards
- 100% EU Infrastructure: No reliance on US-owned cloud providers for core processing.
- No CLOUD Act Exposure: Sovereign legal framework ensures data immunity from foreign warrants.