Security and Compliance, Our Commitments

Aprovall is committed to protecting your data with the highest standards of security and confidentiality. Discover our certifications, security practices and our transparent approach to compliance.

ISO 27001
ISO 27701
Galink
Ecovadis
Documenti

Download our compliance artifacts

Public documents are available instantly. Gated ones require a short NDA.

Public
Other

Carbon Footprint 2025

Carbone footprint 2025 Aproval included scope 1, scope 2 and scope 3

Aggiornato May 2026
Scarica
NDA
Questionnaire

Vendor Security Questionnaire (CAIQ)

Aggiornato May 2026
Richiedi
NDA
Audit report

Galink Assessment

Aggiornato May 2026
Richiedi
Public
Policy

Responsible Disclosure Policy

Responsibly report security vulnerabilities

Aggiornato May 2026
Consulta
Public
Legal

Terms of Use

Rules for accessing and using the platform

Aggiornato May 2026
Consulta
Public
Legal

Cookie Policy

This cookie policy explains what cookies are, which cookies are used on this website, for what purposes, for how long, by whom the data may be processed, and how you can manage your consent.

Aggiornato May 2026
Consulta
Public
Legal

Legal Notices

General terms of access and use of the website

Aggiornato May 2026
Consulta
NDA
Legal

General Subscription Terms

Aggiornato May 2026
Richiedi
NDA
Policy

Information Security Policy

Aggiornato May 2026
Richiedi
Public
Certification

ISO/IEC 27001:2022 Certificate

ISO/IEC 27001:2022·Aggiornato May 2026
Scarica
NDA
Policy

Responsible Purchasing Policy

Aprovall's and its suppliers' commitments to responsible purchasing: environment, human rights, ethics and data protection.

Aggiornato May 2026
Richiedi
NDA
Policy

Social & Human Rights Policy

Aprovall's commitments regarding non-discrimination, anti-harassment, freedom of association, privacy, fair compensation and new technologies.

Aggiornato May 2026
Richiedi
NDA
Policy

Supplier Code of Conduct

Principles and commitments expected from our suppliers regarding ethics, human rights, cybersecurity and the environment.

Aggiornato May 2026
Richiedi
NDA
Legal

Privacy Policy

How we collect, use, and protect your personal data

Aggiornato May 2026
Richiedi
Public
Certification

ISO/IEC 27701:2019 Certificate

ISO/IEC 27701:2019·Aggiornato May 2026
Scarica
Tematica

Finance

This theme covers material related to financial soundness, internal controls and governance. Financial statements and audit reports are available on request as part of a due-diligence process.

Tematica

Cybersecurity

This theme covers our information security policy and our responsible vulnerability disclosure process. It is complemented by the technical and organizational controls in place and the list of our sub-processors.

Our approach

Container of Markdown cards (Security, Privacy, Availability, Compliance). Reorder cards via their handle.

Security

AES-256 encryption at rest, TLS 1.3 in transit, enforced MFA, 24/7 monitoring, annual penetration tests.

Privacy

GDPR-compliant, DPA available, EU hosting (Ireland/France), data minimisation by design.

Availability

99.9% SLA. Annually-tested business continuity plan. RPO 1h, RTO 4h.

Compliance

ISO 27001 · ISO 27701 · GDPR · DORA-ready · SOC 2 Type II 2026.

Controlli di sicurezza

Defense in depth, across the stack

A summary of the controls continuously monitored in our compliance program.

Access Control

  • Unique user identification
  • Multi-factor authentication enforced

Cryptography

  • Data at rest encrypted (AES-256)
  • Data in transit encrypted (TLS 1.3)

Human Resources

  • Security awareness training

Incident Response

  • Documented incident response plan

Vulnerability Mgmt

  • Monthly vulnerability scans
Sub-responsabili

Sub-processors

Full list of our sub-processors. Subscribe to be notified of additions or changes.

NomeFinalitàSedeCertificazioniDPADal
OVHcloud
FR
Primary hosting — application data, databases, and uploaded filesFrance
ISO 27001ISO 27701
Firmato2025-07
Scaleway
FR
Encrypted backups of databases and filesFrance
ISO 27001
Firmato2025-07
YouSign
FR
Electronic signature — signatory names, email addresses, signed documentsFrance
eIDAS
Firmato2025-07
Mistral AI
FR
AI document analysis — document contents submitted for analysisFrance
Firmato2025-07
Amazon SES
FR
Transactional email — email addresses and message metadataFrance (eu-west-3)
SOC 2ISO 27001EU-US DPF
Firmato2025-07
Google (Vertex AI)
BE
AI document analysis — document contents submitted for analysisBelgique (europe-west1)
SOC 2ISO 27001EU-US DPF
Firmato2025-12

Commitments and policies

Commitments

  • ISO certifications — Aprovall is certified to ISO/IEC 27001:2022 and ISO/IEC 27701:2019, audited by Bureau Veritas.
  • Responsible AI governance — Internal governance of AI use, with the aim of aligning with ISO/IEC 42001:2023.

Published policies

Tematica

Ethics & Compliance

This theme sets out the commitments that apply to business relationships, particularly with suppliers: integrity, anti-corruption and conflict-of-interest prevention.

Commitments and policies

Commitments

  • UN Global Compact — Signatory since September 2019, applying its ten principles (human rights, labour, environment, anti-corruption).
  • Responsible Purchasing Charter — Signed in April 2025; its 10 commitments structure supplier relationships.
  • Zero-tolerance anti-corruption — Refusal of any active or passive corruption and of conflicts of interest. Explicit Code of Conduct and confidential whistleblowing channel.

Published policies

Tematica

Environment

This theme outlines the responsible purchasing policy and the environmental criteria used when selecting partners.

Commitments and policies

Commitments

  • Low-carbon procurement — Low-carbon procurement policy covering non-production and general-services spend: rail business travel, electric vehicles and extended IT equipment lifecycles.

Published policies

Tematica

Human Rights

This theme covers the social policy and human rights commitments that apply both to our employees and to our value chain, with reference to international standards (ILO, UN Global Compact).

Commitments and policies

Commitments

  • Diversity Charter — Signatory since 2014. Equal opportunity, non-discrimination and inclusion structure the HR policy.
  • ILO fundamental conventions — Adherence to the eight ILO conventions: freedom of association, collective bargaining, elimination of forced labour, abolition of child labour, non-discrimination.

Published policies

Service status

Uptime over the last 90 days, powered by our external monitoring.

Tutti i servizi operativi
90 giorni faoggi

Frequently asked questions

Everything you need to know before requesting access.

Need something specific?

Can't find the document you need? Get in touch with our security team.