Snapshot 20751
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust Center Security & privacy at Olyteck How we protect your Microsoft 365 data, where it lives, who can touch it, and the documents you need for procurement. Filter by product below. Updated continuously. All products Cyber Ask Studio Guard EU Hosting region France · European Union (Scaleway PAR1) 🔒 Encryption TLS 1.2+ · AES-256 at rest M Authentication Microsoft Entra ID · MFA inherited 📄 Data minimisation Counts findings, never files Our security posture in one paragraph Olyteck is a French company building practical AI and cybersecurity for SMBs and mid-market organisations on Microsoft 365. Everything we ship follows the same principles: read-only first (diagnose before changing), EU-hosted and GDPR-aligned (French jurisdiction, EU servers, no third-country processors), and "counts findings, never files" — we store counts, severities and flags, not file contents, message bodies or document names. Every transit uses TLS 1.2 or higher, every byte at rest is encrypted with AES-256, and staff access is restricted to a small set of named operators and logged. Sales & security questionnaires Need a vendor security questionnaire filled in, or a custom NDA-protected document pack? E-mail [email protected] — typical turnaround is one to two business days. Documents Showing documents for all products. Items marked NDA or ON REQUEST are released to qualified prospects and customers via e-mail. Public ISP Information Security Policy — exec summary PDF · 2 pages · signed GDPR GDPR Compliance One-Pager PDF · article-by-article mapping DPA Data Processing Agreement (DPA) PDF · with EU SCCs annex · v1.0 SP Sub-processor list PDF · also listed below · last reviewed May 2026 SEC Security & Architecture Documentation — Cyber Full Word document · v1.0 · May 2026 SRB Security review brief — Cyber START HERE Two-minute read · what the scanner can and cannot do, and how to verify it in your own tenant MS Microsoft Graph permissions statement — Cyber v2.0 · 18 Aug 2026 · every permission, why it is needed, and what we deliberately do not request · offered for counter-signature DAST Latest production DAST scan — Cyber CLEAN PDF · 1 June 2026 · 0 High · 0 Medium · 0 Low · OWASP ZAP CAIQ CAIQ v4.0.3 — Cyber VERIFY ↗ CSA STAR self-assessment · verify on the official CSA registry Available on request MS Microsoft Graph permissions — Guard ON REQUEST Mail.Read/ReadWrite, Directory.Read.All · justified per scope DAST Latest production DAST scan — Guard ON REQUEST OWASP ZAP · request the most recent summary Available under NDA ISP Information Security Policy — full NDA Signed PDF · request via e-mail SDL Secure Software Development Lifecycle NDA Full document · request via e-mail PEN External penetration test summary NDA Redacted summary · most recent BCP Business Continuity exercise report NDA Dated · with RTO/RPO achieved ARC Detailed architecture & network diagrams NDA PDF · data flow, network topology RR Risk register — exec summary NDA Sanitized · reviewed quarterly Certifications & assurance Where we are today and what we are working toward. CSA STAR Level 1 — listed GDPR — compliant EU-only data residency Hosting provider: ISO 27001 + SOC 2 audited OWASP ZAP DAST — production scan clean (June 2026) External penetration test — annual SOC 2 Type II — on roadmap ISO 27001 — on roadmap Frameworks our controls align to ISO/IEC 27001 & 27002 · SOC 2 Trust Services Criteria · OWASP ASVS · CIS Critical Security Controls · GDPR · CSA Cloud Controls Matrix v4. Mapping documents available under NDA. Sub-processors Carefully selected, contractually bound. Last reviewed 2026-08-18. Sub-processor Service Region Microsoft Corporation Entra ID authentication + Microsoft Graph (customer-controlled tenant) Customer-controlled Scaleway (EU cloud hosting) Infrastructure-as-a-service hosting of application, database, backups European Union (France, PAR1) Microsoft 365 (Exchange Online) Transactional & notification e-mail delivery European Union Cloudflare, Inc. DNS and edge protection for the public marketing site olyteck.com. Product traffic resolves directly to Scaleway (PAR1). Global (EU PoPs) - marketing surface only Stripe Payments Europe, Ltd. Card payment processing & subscription billing European Union / Ireland Google Safe Browsing URL reputation lookups (opt-in) Global This page is the authoritative, current list of our sub-processors. We post any addition or replacement here at least 30 days before it takes effect, so customers can review and object as set out in our DPA. To be added to our change-notification list, e-mail us. Status & incident response Live system status is published at status.olyteck.com. Customers are notified of personal-data incidents without undue delay and within 72 hours, in line with GDPR Article 33. Report a security issue Customers and third parties can report a suspected security issue to [email protected]. We acknowledge receipt within one business day and engage a responder. Talk to us Need a vendor security questionnaire filled in? We pre-write most answers. Send us your template and we usually return it inside two business days. [email protected] Sign an NDA & get the full pack Detailed S-SDLC, pentest summary, BCP exercise report, full architecture diagrams. Request the pack