Security and Compliance, Our Commitments

Aprovall is committed to protecting your data with the highest standards of security and confidentiality. Discover our certifications, security practices and our transparent approach to compliance.

ISO 27001
ISO 27701
Galink
Ecovadis
Documents

Download our compliance artifacts

Public documents are available instantly. Gated ones require a short NDA.

NDA
Questionnaire

Vendor Security Questionnaire (CAIQ)

Updated May 2026
Request
NDA
Audit report

Galink Assessment

Updated May 2026
Request
Public
Policy

Responsible Disclosure Policy

Responsibly report security vulnerabilities

Updated May 2026
View
Public
Legal

Terms of Use

Rules for accessing and using the platform

Updated May 2026
View
Public
Legal

Cookie Policy

This cookie policy explains what cookies are, which cookies are used on this website, for what purposes, for how long, by whom the data may be processed, and how you can manage your consent.

Updated May 2026
View
Public
Legal

Legal Notices

General terms of access and use of the website

Updated May 2026
View
NDA
Legal

General Subscription Terms

Updated May 2026
Request
NDA
Policy

Information Security Policy

Updated May 2026
Request
Public
Certification

ISO/IEC 27001:2022 Certificate

ISO/IEC 27001:2022·Updated May 2026
Download
NDA
Policy

Supplier Code of Conduct

Principles and commitments expected from our suppliers regarding ethics, human rights, cybersecurity and the environment.

Updated May 2026
Request
NDA
Policy

Social & Human Rights Policy

Aprovall's commitments regarding non-discrimination, anti-harassment, freedom of association, privacy, fair compensation and new technologies.

Updated May 2026
Request
NDA
Policy

Responsible Purchasing Policy

Aprovall's and its suppliers' commitments to responsible purchasing: environment, human rights, ethics and data protection.

Updated May 2026
Request
NDA
Legal

Privacy Policy

How we collect, use, and protect your personal data

Updated May 2026
Request
Public
Certification

ISO/IEC 27701:2019 Certificate

ISO/IEC 27701:2019·Updated May 2026
Download
Theme

Finance

This theme covers material related to financial soundness, internal controls and governance. Financial statements and audit reports are available on request as part of a due-diligence process.

Theme

Cybersecurity

This theme covers our information security policy and our responsible vulnerability disclosure process. It is complemented by the technical and organizational controls in place and the list of our sub-processors.

Our approach

Container of Markdown cards (Security, Privacy, Availability, Compliance). Reorder cards via their handle.

Security

AES-256 encryption at rest, TLS 1.3 in transit, enforced MFA, 24/7 monitoring, annual penetration tests.

Privacy

GDPR-compliant, DPA available, EU hosting (Ireland/France), data minimisation by design.

Availability

99.9% SLA. Annually-tested business continuity plan. RPO 1h, RTO 4h.

Compliance

ISO 27001 · ISO 27701 · GDPR · DORA-ready · SOC 2 Type II 2026.

Security controls

Defense in depth, across the stack

A summary of the controls continuously monitored in our compliance program.

Access Control

  • Unique user identification
  • Multi-factor authentication enforced

Cryptography

  • Data at rest encrypted (AES-256)
  • Data in transit encrypted (TLS 1.3)

Human Resources

  • Security awareness training

Incident Response

  • Documented incident response plan

Vulnerability Mgmt

  • Monthly vulnerability scans
Sub-processors

Sub-processors

Full list of our sub-processors. Subscribe to be notified of additions or changes.

NamePurposeLocationCertificationsDPASince
OVHcloud
FR
Primary hosting — application data, databases, and uploaded filesFrance
ISO 27001ISO 27701
Signed2025-07
Scaleway
FR
Encrypted backups of databases and filesFrance
ISO 27001
Signed2025-07
YouSign
FR
Electronic signature — signatory names, email addresses, signed documentsFrance
eIDAS
Signed2025-07
Mistral AI
FR
AI document analysis — document contents submitted for analysisFrance
Signed2025-07
Amazon SES
FR
Transactional email — email addresses and message metadataFrance (eu-west-3)
SOC 2ISO 27001EU-US DPF
Signed2025-07
Google (Vertex AI)
BE
AI document analysis — document contents submitted for analysisBelgique (europe-west1)
SOC 2ISO 27001EU-US DPF
Signed2025-12

Commitments and policies

Commitments

  • ISO certifications — Aprovall is certified to ISO/IEC 27001:2022 and ISO/IEC 27701:2019, audited by Bureau Veritas.
  • Responsible AI governance — Internal governance of AI use, with the aim of aligning with ISO/IEC 42001:2023.

Published policies

Theme

Ethics & Compliance

This theme sets out the commitments that apply to business relationships, particularly with suppliers: integrity, anti-corruption and conflict-of-interest prevention.

Commitments and policies

Commitments

  • UN Global Compact — Signatory since September 2019, applying its ten principles (human rights, labour, environment, anti-corruption).
  • Responsible Purchasing Charter — Signed in April 2025; its 10 commitments structure supplier relationships.
  • Zero-tolerance anti-corruption — Refusal of any active or passive corruption and of conflicts of interest. Explicit Code of Conduct and confidential whistleblowing channel.

Published policies

Theme

Environment

This theme outlines the responsible purchasing policy and the environmental criteria used when selecting partners.

Commitments and policies

Commitments

  • Low-carbon procurement — Low-carbon procurement policy covering non-production and general-services spend: rail business travel, electric vehicles and extended IT equipment lifecycles.

Published policies

Theme

Human Rights

This theme covers the social policy and human rights commitments that apply both to our employees and to our value chain, with reference to international standards (ILO, UN Global Compact).

Commitments and policies

Commitments

  • Diversity Charter — Signatory since 2014. Equal opportunity, non-discrimination and inclusion structure the HR policy.
  • ILO fundamental conventions — Adherence to the eight ILO conventions: freedom of association, collective bargaining, elimination of forced labour, abolition of child labour, non-discrimination.

Published policies

Service status

Uptime over the last 90 days, powered by our external monitoring.

All services operational
90 days agotoday

Frequently asked questions

Everything you need to know before requesting access.

Need something specific?

Can't find the document you need? Get in touch with our security team.