Sovereignty & compliance
Sovereignty, proven in the architecture
Our commitments are not commercial clauses: they are technical constraints, verifiable in every delivery.
On-premises. No data abroad. Zero dependency.
Everything we deliver installs inside your infrastructure: applications, trust foundation, cryptographic keys, proof logs. No outbound call to any third-party service is required to operate — no CDN, no foreign cloud, no telemetry.
This posture is verifiable: our deliverables run on an isolated network, and we demonstrate it at every acceptance. Service continuity depends on no actor outside your control.
Reversibility is contractual: source code, documentation, operating procedures and training are delivered. You can operate, audit and evolve the system without us.
Our compliance frameworks
Five frameworks structure our deliverables — from code to contracts.
DGSSI directive
The national information systems security directive drives our architecture, hardening and logging.
OWASP ASVS
Every application is built and verified against the ASVS requirements applicable to its risk class.
Law 05-20 — cybersecurity
Security obligations for vital infrastructure: turned into concrete, auditable technical measures.
Law 43-20 — trust services
Electronic signature, timestamping and seals: our foundations fit Morocco's legal framework for trust services.
Law 09-08 — data protection
Data minimisation and a tooled processing register: protecting citizens' personal data is a design constraint.
Measurable commitments
- 100%
- of deliverables operable on an isolated network
- 0
- outbound call required to any third-party service
- 100%
- of source code and documentation delivered
- 6
- frameworks applied: DGSSI, ASVS, 05-20, 43-20, 09-08, ISO 27001
Frequently asked questions
Do your solutions work without Internet access?
Yes. All our deliverables run on an isolated network. Updates ship as signed packages, transferred through your operating procedures.
Where are cryptographic keys hosted?
In your infrastructure, under your exclusive control — ideally in an HSM or key vault you administer. We never access your private keys.
How do you prove ASVS compliance?
Every applicable requirement is traced in a compliance matrix delivered with the project, linking to the code and tests that cover it.
What happens at the end of the contract?
Reversibility is planned from day one: source code, diagrams, operating documentation and team training. The system remains fully operable without us.
Do you process personal data?
Our foundations minimise the data processed and align with law 09-08 and its evolutions. The processing register and impact assessments remain the institution's responsibility — we provide the tooling.
Demand proof, not promises.
Request a pilot and verify our commitments on your own network.