Third Party Index

Snapshot 20751

Document
Trust center
URL
https://olyteck.com/trust/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
28598 bytes
SHA-256 (raw)
f9d2ad4e6fcfe926d201975aacaa0a21ef60422a708316818d0f7d343395e9f3
SHA-256 (normalized text)
eaeecda6d8b991d87acb33d7b9bb29183f4df2e1cde96399aa2aff4a84a38537

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Security & privacy at Olyteck
How we protect your Microsoft 365 data, where it lives, who can touch it, and the documents you need for procurement. Filter by product below. Updated continuously.
All products Cyber Ask Studio Guard
EU
Hosting region
France · European Union (Scaleway PAR1)
🔒
Encryption
TLS 1.2+ · AES-256 at rest
M
Authentication
Microsoft Entra ID · MFA inherited
📄
Data minimisation
Counts findings, never files
Our security posture in one paragraph
Olyteck is a French company building practical AI and cybersecurity for SMBs and mid-market organisations on Microsoft 365. Everything we ship follows the same principles: read-only first (diagnose before changing), EU-hosted and GDPR-aligned (French jurisdiction, EU servers, no third-country processors), and "counts findings, never files" — we store counts, severities and flags, not file contents, message bodies or document names. Every transit uses TLS 1.2 or higher, every byte at rest is encrypted with AES-256, and staff access is restricted to a small set of named operators and logged.
Sales & security questionnaires
Need a vendor security questionnaire filled in, or a custom NDA-protected document pack? E-mail [email protected] — typical turnaround is one to two business days.
Documents
Showing documents for all products. Items marked NDA or ON REQUEST are released to qualified prospects and customers via e-mail.
Public
ISP
Information Security Policy — exec summary
PDF · 2 pages · signed
GDPR
GDPR Compliance One-Pager
PDF · article-by-article mapping
DPA
Data Processing Agreement (DPA)
PDF · with EU SCCs annex · v1.0
SP
Sub-processor list
PDF · also listed below · last reviewed May 2026
SEC
Security & Architecture Documentation — Cyber
Full Word document · v1.0 · May 2026
SRB
Security review brief — Cyber START HERE
Two-minute read · what the scanner can and cannot do, and how to verify it in your own tenant
MS
Microsoft Graph permissions statement — Cyber
v2.0 · 18 Aug 2026 · every permission, why it is needed, and what we deliberately do not request · offered for counter-signature
DAST
Latest production DAST scan — Cyber CLEAN
PDF · 1 June 2026 · 0 High · 0 Medium · 0 Low · OWASP ZAP
CAIQ
CAIQ v4.0.3 — Cyber VERIFY ↗
CSA STAR self-assessment · verify on the official CSA registry
Available on request
MS
Microsoft Graph permissions — Guard ON REQUEST
Mail.Read/ReadWrite, Directory.Read.All · justified per scope
DAST
Latest production DAST scan — Guard ON REQUEST
OWASP ZAP · request the most recent summary
Available under NDA
ISP
Information Security Policy — full NDA
Signed PDF · request via e-mail
SDL
Secure Software Development Lifecycle NDA
Full document · request via e-mail
PEN
External penetration test summary NDA
Redacted summary · most recent
BCP
Business Continuity exercise report NDA
Dated · with RTO/RPO achieved
ARC
Detailed architecture & network diagrams NDA
PDF · data flow, network topology
RR
Risk register — exec summary NDA
Sanitized · reviewed quarterly
Certifications & assurance
Where we are today and what we are working toward.
CSA STAR Level 1 — listed GDPR — compliant EU-only data residency Hosting provider: ISO 27001 + SOC 2 audited OWASP ZAP DAST — production scan clean (June 2026) External penetration test — annual SOC 2 Type II — on roadmap ISO 27001 — on roadmap
Frameworks our controls align to
ISO/IEC 27001 & 27002 · SOC 2 Trust Services Criteria · OWASP ASVS · CIS Critical Security Controls · GDPR · CSA Cloud Controls Matrix v4. Mapping documents available under NDA.
Sub-processors
Carefully selected, contractually bound. Last reviewed 2026-08-18.
Sub-processor	Service	Region
Microsoft Corporation	Entra ID authentication + Microsoft Graph (customer-controlled tenant)	Customer-controlled
Scaleway (EU cloud hosting)	Infrastructure-as-a-service hosting of application, database, backups	European Union (France, PAR1)
Microsoft 365 (Exchange Online)	Transactional & notification e-mail delivery	European Union
Cloudflare, Inc.	DNS and edge protection for the public marketing site olyteck.com. Product traffic resolves directly to Scaleway (PAR1).	Global (EU PoPs) - marketing surface only
Stripe Payments Europe, Ltd.	Card payment processing & subscription billing	European Union / Ireland
Google Safe Browsing	URL reputation lookups (opt-in)	Global
This page is the authoritative, current list of our sub-processors. We post any addition or replacement here at least 30 days before it takes effect, so customers can review and object as set out in our DPA. To be added to our change-notification list, e-mail us.
Status & incident response
Live system status is published at status.olyteck.com. Customers are notified of personal-data incidents without undue delay and within 72 hours, in line with GDPR Article 33.
Report a security issue
Customers and third parties can report a suspected security issue to [email protected]. We acknowledge receipt within one business day and engage a responder.
Talk to us
Need a vendor security questionnaire filled in?
We pre-write most answers. Send us your template and we usually return it inside two business days.
[email protected]
Sign an NDA & get the full pack
Detailed S-SDLC, pentest summary, BCP exercise report, full architecture diagrams.
Request the pack