User Authentication with Auth0
We utilize Auth0, a leading authentication platform, to manage user identities securely. Auth0 is certified under several internationally recognized standards:
ISO/IEC 27001/27018: These certifications affirm Auth0's commitment to information security management and the protection of personal data in the cloud.
CSA STAR: Auth0 is registered with the Cloud Security Alliance's Security, Trust & Assurance Registry, demonstrating transparency and rigorous cloud security practices.
SOC 2 Type 2: Auth0 undergoes regular audits to ensure compliance with stringent security and privacy controls.
Data Storage: Scaleway
Our data is hosted on Scaleway's servers, ensuring that all information remains within Europe. Scaleway's data centers are strategically located to provide optimal performance and compliance. All ten of Scaleway's data centers are in Europe, including four in France.
Scaleway is ISO/IEC 27001:2022 certified, ensuring a robust information security management system that guarantees the confidentiality and integrity of your data.
Payments: Stripe
We use Stripe to securely process payments and subscriptions. Stripe is a PCI Level 1 Service Provider, the highest certification in the industry, ensuring compliance with strict security standards. It encrypts and tokenizes payment data to prevent fraud, and its infrastructure undergoes continuous security testing to protect transactions.
Encryption
All data, both at rest and in transit, is encrypted using industry-standard protocols. This ensures that user information remains protected against unauthorized access. Our encryption practices follow the latest security standards to maintain the highest levels of confidentiality and data protection.
GDPR Compliance
We are committed to upholding the principles of the General Data Protection Regulation (GDPR). As a data processor, we implement all necessary technical and organizational measures to guarantee the security and confidentiality of personal data, in line with GDPR requirements. For more details, please refer to our Data Processing Agreement (DPA).
EU AI Act Compliance
In anticipation of the forthcoming EU Artificial Intelligence Act, we are proactively aligning our practices to meet its standards. We are committed to ensuring that our AI systems are transparent, fair, and respect user rights, adhering to the highest ethical standards.