Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

TRUST CENTER

The standard we sell is the standard we live.

The trust we ask our clients to demand from their third parties, we apply to ourselves: published here, kept current, verifiable on request.

EU-only hosting · MFA everywhere · Audited yearly

Trust center · commitments board

  • Critical patches < 24 h
  • Breach notification (CNIL) < 72 h
  • Security logs retained 90 days min.
  • Access reviews Every 6 months
  • Encryption TLS 1.2+ · AES-256
  • Data residency EU only

Every line below is detailed on this page; documentation and audit reports under NDA.

SECURITY POSTURE

How we protect the platform, and your data.

A condensed view of our operating security commitments. Detailed documentation and audit reports are available under NDA.

01

Detection & resilience

  • Formalized incident management and notification processes
  • Documented business continuity and disaster recovery plans
  • Continuous security event monitoring with critical escalation
02

Exposure & remediation

  • Continuous CVE and ANSSI alert monitoring
  • Critical patches applied within 24 hours
  • Annual independent audits and penetration tests (latest report on request)
03

Identity & access

  • Mandatory MFA on critical systems, least-privilege by default
  • Individual accounts, no sharing; centralized IAM in production
  • Access reviews every six months
04

Network & infrastructure

  • Active segmentation and filtering; DDoS mitigation in place
  • TLS 1.2+ everywhere; VPN for remote administration
  • Security logs retained 90 days minimum
05

Code & data

  • Encryption in transit (TLS) and at rest (AES-256)
  • Systematic code review in a secure development lifecycle
  • Automated vulnerability analysis on every deployment; strict dev/staging/prod isolation
06

Continuity & governance

  • Multi-region backups with regular restoration testing
  • Traceable change management through CI/CD
  • Active security policy (PSSI), onboarding security training, annual risk mapping reviews

DATA HOSTING & SOVEREIGNTY

Exclusively European infrastructure.

Customer data is hosted and processed in the European Union, on European regions of certified providers. Zero data transfers outside the EU.

Data, AI models and backups inside the EU perimeter; nothing crosses it.

  • EU regions only (France-based primary infrastructure)

  • AI models hosted in Europe; customer data never used for training

  • Every AI call internally traced and controlled

  • Complete tenant data isolation

CERTIFICATIONS & LABELS

Where we stand, honestly.

Reached, underway, planned: the roadmap as it is, not as a badge wall.

  1. Bpifrance DeepTech

    Qualified
  2. Jeune Entreprise Innovante (JEI)

    Active
  3. ISO 27001:2022

    In progress - target Q1 2027
  4. SOC 2 Type II

    Planned - 2027

GDPR

Data protection commitments.

  • Breach notification to CNIL within 72 hours

  • Data subject rights honored: access, rectification, erasure, portability

  • Recorded, revocable consent mechanisms

  • Processing register maintained; GDPR obligations flowed down to all subprocessors

RESPONSIBLE DISCLOSURE

Found a vulnerability?

We welcome responsible disclosure. Write to security@mindlapse.ai: we acknowledge within 48 hours.

EVALUATE US

Ask for the evaluation pack.

Security questionnaire pre-answered, DPA, hosting attestations, latest audit report: provided on request, under NDA where you need it.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.