Vendor security sheet
This page answers a vendor security questionnaire in advance. It is meant to be printed or saved as a PDF and passed on as-is by an agency to its client.
Document produced on
1. Publisher identity
- NEXTLAB SAS
- SIREN 108 181 421
- TVA FR26108181421
- 2 avenue d'Iéna, Résidence Les Jardins de Chaillot, 75116 Paris
- Participant Identification Code (European Commission) : 861319164
2. Hosting and data location
**Scaleway** — hosting of the application and of the data, in France.
3. Sub-processors
- **Scaleway** (France) — hosting of the application and of the data. **Processing in France**, by a company incorporated under French law.
- **Brevo** (Sendinblue, France) — sending of transactional emails. Processing in the European Union.
4. Technical measures
- Security headers in production: one-year HSTS (max-age=31536000, includeSubDomains), our pages refused inside another site (frame-ancestors “none” and X-Frame-Options: DENY), nosniff, and a Permissions-Policy that declines the camera, microphone, geolocation, payment and USB — none of which the platform ever uses.
- A content security policy that restricts the origins: base-uri and form-action limited to the site, object-src set to “none”, and a connect-src limited to the site and our payment provider — so a script cannot open a connection to an arbitrary domain. It does allow inline scripts, which Next.js rendering depends on, and images from any HTTPS domain: it is therefore neither a defence against script injection nor a watertight barrier to exfiltration, and we prefer to write that down rather than let the word “strict” imply it.
- Passwords hashed with argon2id, the algorithm recommended today.
- Connector credentials encrypted at rest with AES-256-GCM.
- The connectors that read your tools are read-only, and the refusal is enforced at the transport rather than left to each integration's good intentions: beyond authenticating and closing their own session, they write nothing. The product's only outbound write is the ticket you push yourself to your PSA or RMM, described in article 8 of the data processing agreement.
- Isolation between agencies verified by 23 automated tests replayed on every code change: an agency trying to read, modify or delete another's data is told “not found”, and the GDPR export contains no row belonging to another client.
- Rate limiting across the whole API, with stricter counters again on the authentication pages.
- Audit log exportable as CSV.
5. Data protection
- In the event of a personal-data breach, notification within 48 hours. That is a contractual undertaking, shorter than the 72 hours of GDPR article 33, precisely to leave you time to notify the authority within it.
- The data processing agreement within the meaning of GDPR article 28 does not exist in two versions: the document published online is the one that applies, kept up to date, with no separate file to request by email.
- A complete export of your data at any time, without asking us, and a stated notice period if the service shuts down.
6. Contact
- Contact : Laurent Bertière — contact@vigicap.fr
- security@vigicap.fr