Security
Defense in depth, least privilege and a secure development lifecycle. Program aligned with ISO/IEC 27001 Annex A controls, audited internally.
Trust center
Your core data is hosted in France and the EEA. We follow GDPR principles, encrypt communications and comply with the applicable requirements of the AI Act.
Trust baseline
Operational safeguards
Core services hosted with OVHcloud in France and the European Economic Area.
All communications are encrypted over HTTPS / TLS.
Each organisation's data is isolated from every other.
For a client data breach, notification where reasonably possible within 48 hours.
Our approach
Defense in depth, least privilege and a secure development lifecycle. Program aligned with ISO/IEC 27001 Annex A controls, audited internally.
GDPR legal bases, bounded retention periods, data-subject rights and an Article 28 data processing agreement (DPA).
Honax follows the applicable AI Act requirements through transparency, human oversight and risk management principles.
Providers selected for their role and held to our security and privacy requirements.
Documentation
Available to our clients once signed in. Prospects: ask us for the package.
Notre accord de sous-traitance au titre de l'article 28 du RGPD, intégré aux Conditions Générales d'Utilisation.
Les réponses aux questions les plus fréquentes des questionnaires de sécurité.
Notre processus de réponse aux incidents et de notification des violations de données sous 72 heures.
Les mesures de sécurité mises en oeuvre pour protéger les données traitées (annexe au contrat de sous-traitance).
Nos durées de conservation par catégorie de données et nos engagements d'effacement.
Architecture défensive, authentification, isolation des données, chiffrement et cycle de développement sécurisé.
La liste nominative de nos sous-traitants, leur rôle et les services auxquels ils contribuent.
Ce que fait l'assistant vocal, ses garde-fous, sa transparence IA et le traitement des données d'appel.
FAQ
The essential answers for assessing our security and privacy approach.
With OVHcloud, with core data in France and the European Union.
Yes, all communications are encrypted in transit over HTTPS / TLS.
Yes. Our Article 28 GDPR data processing agreement is incorporated into the Terms and is available in the client Trust Center.
Yes, data reversibility and export are provided. Details are in our documents.
We follow an incident response process and notify affected clients, where reasonably possible, within 48 hours after becoming aware of a breach.
Our program is aligned with ISO/IEC 27001 Annex A controls and audited internally. No certification is claimed at this stage.
Security team
Our team answers security requests and vulnerability reports.