Morocco Next
Technologies

Trust Center

Trust is proven, not declared

Security commitments, compliance, data protection and the status of our services: everything the institutions' trust in us is built on, presented transparently.

Our security commitments

Architectural commitments, verifiable in every delivery — not commercial promises.

On-premises hosting, under national control

Everything we deliver installs inside your infrastructure: applications, trust foundation, keys, proof logs. No outbound call is required to operate.

Proof and non-repudiation by default

Every sensitive act is signed, time-stamped and recorded in a verifiable register: proof is a feature, not an option.

Contractual reversibility

Source code, documentation, operating procedures and training delivered: your teams can operate, audit and evolve the system without us.

Demonstrated on an isolated network

Our deliverables run on an isolated network and we demonstrate it at every acceptance — sovereignty is verified, not promised.

Compliance & accreditations

The frameworks that structure our deliverables, and the accreditations we pursue — status displayed in full transparency.

Compliant

DGSSI national directive

The national information systems security directive drives our architecture, hardening and logging — a compliance matrix ships with every project.

Compliant

OWASP ASVS

Every application is built and verified against the ASVS requirements applicable to its risk class, requirement by requirement.

Targeted

PASSI qualification

We are preparing the information systems security audit provider qualification: our audit methods already align with its requirements.

Targeted

PSCo accreditation (law 43-20)

Trust service provider status governs signature, timestamping and electronic seals: our accreditation roadmap is under way.

In progress

ISO/IEC 27001

Our information security management system is structured on ISO 27001; the certification process is under way.

Data protection

Protecting citizens' personal data (law 09-08, CNDP) is a design constraint, not a checkbox.

Compliant

Law 09-08 & CNDP

Our foundations minimise processed data and align with law 09-08; we equip the institution's processing register and CNDP procedures.

Minimisation and segregation

Only the data required by the service is processed, segregated by use, with retention periods defined at design time.

Data-subject rights, tooled

Access, rectification, objection: the processing we deliver embeds the mechanisms citizens need to exercise their rights.

Our approach to sovereignty

On-premises, under national control: what that concretely means in our architectures.

No data abroad

Data, keys and proofs stay on national territory, within the institution's perimeter — no CDN, no foreign cloud, no telemetry.

Keys under exclusive control

Cryptographic keys live in your infrastructure, ideally in an HSM you administer. We never access your private keys.

Zero operational dependency

Service continuity depends on no actor outside your control: updates ship as signed packages, through your operating procedures.

Service status

The state of our services, kept up to date by our teams.

  • Institutional portal

    Operational

    Public website and content space.

  • MNT Trust services

    Operational

    Strong authorisation and signature of sensitive actions (on-premises client deployments).

  • Support & assistance

    Operational

    Requests answered within 48 working hours.

The sovereign digital future, built on trust.

Request a pilot