Reversibility and exit commitment
Last updated: September 2026
This translation is provided for convenience. Only the French version is legally binding.
Vigicap is published by a small outfit. That is a legitimate reason to wonder what happens if we stop — and the right answer is not to reassure you, it is to make the question inconsequential. This page describes what you get back, when, and on what conditions.
1. The complete export, at any time, without asking us
From Audit log → Full export, any administrator downloads the whole of their agency's data in one click, in JSON format. No prior request, no delay, no charge, no limit on frequency. You do not need our agreement to take your data back: that is the very principle of this page.
The export contains:
- your agency, your user accounts and your invitations;
- your clients, their contacts, their notes, their tags and your team's assignments;
- the complete assessments: evaluations, answers objective by objective, declared and validated levels, and the framework itself — without it, the answers would be no more than a list of identifiers;
- the compliance register and its change history, the action plans, the risks, the suppliers, the incidents and their notifications, the continuity items;
- your quotes and their line items, as well as your service catalogue — which is your commercial work, not ours;
- the entire ISO 27001 file: risk treatment plan, non-conformities, management reviews, as well as your applicability decisions and your justifications. Since the statement of applicability and the state of the clauses are derived from a ReCyF ↔ Annex A mapping table, that table is exported with your data — without it, your justifications would be attached to unreadable control references;
- your policies, your audit log and the history of generated reports — their score and the brand identity at the time of generation. The PDF itself is not retained: it is rebuilt on demand from that data, and remains downloadable from the application for as long as your account is active.
An automated test verifies, on every change to the code, that every table in the database appears in the export or is explicitly excluded with its justification. A completeness promise that is not verified mechanically expires silently with the very next feature.
What the export does not contain, and why
- The audit log beyond the 50,000 most recent entries. It is the only table with no natural bound — one row per modifying action, never purged. Beyond that, the file would become too large to be produced reliably. The export states explicitly whether it has been truncated (auditLogTruncated), and the complete log remains viewable and exportable as CSV from the dedicated page: nothing is lost, but we prefer to write it down rather than let you believe in exhaustiveness.
- Attached files (evidence, ISO evidence) are not in the JSON — a binary file has no place in it. Each entry carries the download path of its file, and the files remain accessible from the application throughout the term of the contract and of the notice period.
- Secrets: password hashes (never stored in clear), auditor share tokens, credentials for your connectors and for your PSA. Their removal is verified at compile time and by a test that inspects the file produced; it is not a drafting instruction. These are access credentials, not data: copying them into a file that travels by e-mail would create a risk instead of solving one.
- Single-use technical tokens (e-mail verification, password reset), which expire within a few hours and have no value outside the platform.
2. An open format, reusable elsewhere
The export is structured, versioned JSON (formatVersion), not a proprietary format only we can read. The field names are those of the data model. A CSV export of the client record is also available for immediate spreadsheet use.
We charge no exit fee, and make the return of your data conditional on nothing: no final settlement, no notice period observed, no prior interview.
3. If Vigicap shuts down
We undertake contractually to:
- give you at least 3 months' notice of the discontinuation of the service, by e-mail to all administrators and by a banner in the application;
- keep the service and the export accessible throughout that notice period;
- keep the export accessible for a further 30 days after the other features are closed;
- publish the documentation of the structure of the exported data, so that another tool or another provider can take it over without us;
- delete the production data within 30 days of your written request, made at any time after the end of the contract. Deletion is carried out manually: no automatic purge is in place to date, as the data processing agreement also states.
A point that matters: backups are not erased on request. They are overwritten by the normal rotation of the backup system, and we do not today guarantee a maximum time to overwrite. The data processing agreement says so in the same terms: two pages contradicting each other on this point would be worth nothing, to you or to us.
4. What we do not promise
The commitments above assume an orderly wind-down. It would be dishonest to claim they cover every case:
- There is today no escrow of code or of data with a third party, nor any continuity arrangement in the event of the publisher's sudden incapacity. That is the real limit of an outfit this size, and it is precisely why the export is free, complete and immediate: the best protection you have is a recent copy at your own premises, not a clause.
- We recommend that you export periodically — quarterly is a reasonable rhythm — and keep the file with your own backups. That recommendation relieves us of nothing; it makes you independent of us.
- We do not guarantee automatic take-up of your data by a third-party tool: we guarantee that it is complete, documented and in a standard format. The import depends on the tool you choose.
- The publishing company is NEXTLAB, registered in France; its particulars appear in the legal notice. The commitments on this page are carried over into the contractual terms signed with each client.
5. Deletion
You may request at any time the deletion of your account and of all your data. The request is handled manually within 30 days: there is not yet a self-service deletion button in the application, and we prefer to write it down rather than leave it to be assumed. Export your data before making the request — deletion is irreversible.
See also the data processing agreement, which restates these obligations under article 28.3.g of the GDPR, and the privacy policy.