Security and compliance

You entrust us with the administration of your infrastructures. Here is how we protect it.

NaoShift manages the platforms you operate for yourself or for your customers. These accesses describe your production: they are treated as such. This page describes our architecture, our commitments and the actual state of our compliance processes.

Vendor
France · capital held in the European Union
Hosting
European Union
Flow direction
Outbound only, from your IT system
Architecture principles

Six decisions built into the design

They are not configuration options: they apply to NaoShift Core, NaoShift Portal and NaoShift AI Ops.

No inbound port at your site

The agent installed in your IT system opens an encrypted outbound connection to the platform. No inbound opening is requested, nothing is installed on the hypervisors. The detailed flow diagram is provided on request.

Read-only by default, opt-in writes

Collection uses a read-only account. Each write capability is enabled target by target with a dedicated least-privilege account, and every action is traced before execution.

Anonymization from collection

Technical data is anonymized from collection: machine, host, cluster names and addresses are replaced by neutral identifiers before analysis. Only your authorized users see the real names, and anonymization is set per organization.

Isolation per organization and per tenant

Each organization's data is isolated at every layer. For the portal, isolation is also created on the hypervisor: pool, VLAN and dedicated account per tenant.

Inventory data, not operational data

NaoShift collects topology, versions, capacities and usage metrics. It collects neither the content of your virtual machines, nor your backups, nor your end customers' data.

Exportable logging

Every action, every right change and every console opening is logged, filterable per tenant and exportable to your SIEM.

Technician at a keyboard in a server room
In your server room

Outbound flow only, from your IT system.

No inbound port, no permanent access kept on the NaoShift side. The detailed flow diagram is provided on request.

Observed and managed scope

The platforms NaoShift reads and manages

Read-only by default on each; writes enabled target by target with a dedicated account. Brands cited for identification only: NaoShift is affiliated with none of these vendors.

  • VMware vSphere
  • Proxmox VE
  • Vates XCP-ng
  • Nutanix Prism Central
  • Microsoft Azure
  • Veeam Backup & Replication
  • Commvault
Frameworks

Where we stand, without rounding up

We display the actual state of each process. An ongoing process is announced as such, and we claim no qualification that belongs to a third party.

NAOSHIFTISO27001Process under way
NAOSHIFTISO 2701727018Planned as extension
NAOSHIFTSecNumCloudNot claimed — deployable inside a qualified perimeter
NAOSHIFTHDSNot claimed — deployable at a certified hosting provider
NAOSHIFTNIS2Voluntary alignment
NAOSHIFTGDPRProcessor

Seals drawn by NaoShift, under our own brand. No certification mark is reproduced: the ISO, ANSSI and HDS logos are reserved for certified or qualified bodies and offerings.

FrameworkStatusWhat it means
ISO/IEC 27001:2022Process under wayInformation security management system being built on the scope "NaoShift SaaS service and its infrastructure". The certificate, its number and its scope will be published here once obtained.
ISO/IEC 27017 and 27018Planned as extensionCodes of practice for cloud service security and for the protection of personal data as a processor. They are obtained as an extension of an ISO 27001 certificate.
SecNumCloud 3.2Not claimed — deployable inside a qualified perimeterNaoShift is not SecNumCloud qualified and does not claim this qualification. The product is designed to be deployed inside a qualified perimeter without creating a gap: outbound flows only, offline licence, separated administration planes, per-tenant logging. A requirement-by-requirement mapping matrix is provided.
HDS — French health data hostingNot claimed — deployable at a certified hosting providerNaoShift does not host health data and is not HDS certified. For a certified institution or hosting provider, NaoShift deploys on-premise inside the existing HDS perimeter; the mapping matrix covers the requirements applicable to a third-party software component.
NIS2 — Directive (EU) 2022/2555Voluntary alignmentNaoShift is not an entity in scope under Article 2 of the directive. Our security measures are aligned with the risk-management measures of Article 21.2, and our commitments to you are contractual. No NIS2 certification exists.
GDPRProcessorRecord of processing activities maintained, Article 28 data processing agreement available for signature, data hosted in the European Union.
Mapping matrix

How NaoShift answers each requirement

The matrix crosses 52 structuring requirements from SecNumCloud 3.2, ISO 27001:2022, NIS2 and SOC 2, each with the expected evidence and the component involved. Requirements specific to a third-party software component deployed inside a qualified perimeter have a dedicated section. It is provided on request, together with the supplier security file.

Incidents

Our commitments if something goes wrong

If you are subject to NIS2, you must alert your CSIRT within 24 hours and notify within 72 hours. Our notification commitments are set contractually so that you can meet yours.

01

First notice

After qualification of a security incident affecting your data or the availability of the service.

02

Detailed notice

Nature, scope, data involved, immediate measures, available indicators of compromise.

03

Analysis report

Root cause, timeline, corrective measures and implementation schedule.

04

Data breach

Notification without undue delay, allowing the controller to comply with Article 33 of the GDPR.

Responsible disclosure

Found a vulnerability?

Write to security@naoshift.io. We acknowledge receipt and keep you informed until the fix. We do not pursue researchers who respect a good-faith test: no access to other customers' data, no service degradation, no disclosure before the fix.

  • Out of scope: denial of service, social engineering, tests on our customers' infrastructures
  • Fixed vulnerabilities are announced to our customers through a security advisory
On request

What we provide to your procurement and security teams

These documents cover most of what supply-chain security, under Article 21.2.d of NIS2, requires you to collect from your suppliers.

Without formality
  • Supplier security file — mapping to Article 21.2 of NIS2
  • ISO 27001, SecNumCloud 3.2 and HDS mapping matrix
  • GDPR data processing agreement, Article 28
  • Architecture diagram and flow description
  • Backup and reversibility policy
Under non-disclosure agreement
  • Information security policy
  • Summary of the latest penetration test
  • Continuity plan and results of the latest restoration test
  • ISO 27001 statement of applicability, once the ISMS is established
  • Certificate and audit report, once obtained
Request the security file

SecNumCloud is a qualification issued by ANSSI to cloud computing service offerings; HDS is a certification of health data hosting providers. NaoShift is neither SecNumCloud qualified nor HDS certified and does not use the ANSSI security visa. Statements about these frameworks describe the product's ability to be deployed inside a perimeter qualified or certified by a third party, and do not extend to the NaoShift service itself.
Security contact: security@naoshift.io

Frequently asked questions

Not yet. The process is under way on the scope of the SaaS service and its infrastructure. The certificate, its number and its scope will be published on this page once obtained. Meanwhile, the security policy and the statement of applicability are shared under non-disclosure agreement.

Your CISO has questions. We have written answers.

Request the supplier security file and the mapping matrix, or schedule a discussion with the team.

We respect your privacy. We use cookies for audience measurement (Matomo) and, with your consent, marketing pixels (Meta, LinkedIn, Google Ads) to measure our campaigns.

Learn more