On-premises hosting, under national control
Everything we deliver installs inside your infrastructure: applications, trust foundation, keys, proof logs. No outbound call is required to operate.
Trust Center
Security commitments, compliance, data protection and the status of our services: everything the institutions' trust in us is built on, presented transparently.
Architectural commitments, verifiable in every delivery — not commercial promises.
Everything we deliver installs inside your infrastructure: applications, trust foundation, keys, proof logs. No outbound call is required to operate.
Every sensitive act is signed, time-stamped and recorded in a verifiable register: proof is a feature, not an option.
Source code, documentation, operating procedures and training delivered: your teams can operate, audit and evolve the system without us.
Our deliverables run on an isolated network and we demonstrate it at every acceptance — sovereignty is verified, not promised.
The frameworks that structure our deliverables, and the accreditations we pursue — status displayed in full transparency.
The national information systems security directive drives our architecture, hardening and logging — a compliance matrix ships with every project.
Every application is built and verified against the ASVS requirements applicable to its risk class, requirement by requirement.
We are preparing the information systems security audit provider qualification: our audit methods already align with its requirements.
Trust service provider status governs signature, timestamping and electronic seals: our accreditation roadmap is under way.
Our information security management system is structured on ISO 27001; the certification process is under way.
Protecting citizens' personal data (law 09-08, CNDP) is a design constraint, not a checkbox.
Our foundations minimise processed data and align with law 09-08; we equip the institution's processing register and CNDP procedures.
Only the data required by the service is processed, segregated by use, with retention periods defined at design time.
Access, rectification, objection: the processing we deliver embeds the mechanisms citizens need to exercise their rights.
On-premises, under national control: what that concretely means in our architectures.
Data, keys and proofs stay on national territory, within the institution's perimeter — no CDN, no foreign cloud, no telemetry.
Cryptographic keys live in your infrastructure, ideally in an HSM you administer. We never access your private keys.
Service continuity depends on no actor outside your control: updates ship as signed packages, through your operating procedures.
The state of our services, kept up to date by our teams.
Public website and content space.
Strong authorisation and signature of sensitive actions (on-premises client deployments).
Requests answered within 48 working hours.
Your privacy matters
This portal only uses strictly technical cookies (session, security) — no advertising cookies, no third-party trackers. Your choice is stored on your device. Cookie policy