Skip to main content

Vendor security sheet

This page answers a vendor security questionnaire in advance. It is meant to be printed or saved as a PDF and passed on as-is by an agency to its client.

Document produced on

1. Publisher identity

  • NEXTLAB SAS
  • SIREN 108 181 421
  • TVA FR26108181421
  • 2 avenue d'Iéna, Résidence Les Jardins de Chaillot, 75116 Paris
  • Participant Identification Code (European Commission) : 861319164

2. Hosting and data location

**Scaleway** — hosting of the application and of the data, in France.

3. Sub-processors

  • **Scaleway** (France) — hosting of the application and of the data. **Processing in France**, by a company incorporated under French law.
  • **Brevo** (Sendinblue, France) — sending of transactional emails. Processing in the European Union.

4. Technical measures

  • Security headers in production: one-year HSTS (max-age=31536000, includeSubDomains), our pages refused inside another site (frame-ancestors “none” and X-Frame-Options: DENY), nosniff, and a Permissions-Policy that declines the camera, microphone, geolocation, payment and USB — none of which the platform ever uses.
  • A content security policy that restricts the origins: base-uri and form-action limited to the site, object-src set to “none”, and a connect-src limited to the site and our payment provider — so a script cannot open a connection to an arbitrary domain. It does allow inline scripts, which Next.js rendering depends on, and images from any HTTPS domain: it is therefore neither a defence against script injection nor a watertight barrier to exfiltration, and we prefer to write that down rather than let the word “strict” imply it.
  • Passwords hashed with argon2id, the algorithm recommended today.
  • Connector credentials encrypted at rest with AES-256-GCM.
  • The connectors that read your tools are read-only, and the refusal is enforced at the transport rather than left to each integration's good intentions: beyond authenticating and closing their own session, they write nothing. The product's only outbound write is the ticket you push yourself to your PSA or RMM, described in article 8 of the data processing agreement.
  • Isolation between agencies verified by 23 automated tests replayed on every code change: an agency trying to read, modify or delete another's data is told “not found”, and the GDPR export contains no row belonging to another client.
  • Rate limiting across the whole API, with stricter counters again on the authentication pages.
  • Audit log exportable as CSV.

5. Data protection

  • In the event of a personal-data breach, notification within 48 hours. That is a contractual undertaking, shorter than the 72 hours of GDPR article 33, precisely to leave you time to notify the authority within it.
  • The data processing agreement within the meaning of GDPR article 28 does not exist in two versions: the document published online is the one that applies, kept up to date, with no separate file to request by email.
  • A complete export of your data at any time, without asking us, and a stated notice period if the service shuts down.

6. Contact

  • Contact : Laurent Bertière — contact@vigicap.fr
  • security@vigicap.fr