
You entrust us with the administration of your infrastructures. Here is how we protect it.
NaoShift manages the platforms you operate for yourself or for your customers. These accesses describe your production: they are treated as such. This page describes our architecture, our commitments and the actual state of our compliance processes.
- Vendor
- France · capital held in the European Union
- Hosting
- European Union
- Flow direction
- Outbound only, from your IT system
Six decisions built into the design
They are not configuration options: they apply to NaoShift Core, NaoShift Portal and NaoShift AI Ops.
No inbound port at your site
The agent installed in your IT system opens an encrypted outbound connection to the platform. No inbound opening is requested, nothing is installed on the hypervisors. The detailed flow diagram is provided on request.
Read-only by default, opt-in writes
Collection uses a read-only account. Each write capability is enabled target by target with a dedicated least-privilege account, and every action is traced before execution.
Anonymization from collection
Technical data is anonymized from collection: machine, host, cluster names and addresses are replaced by neutral identifiers before analysis. Only your authorized users see the real names, and anonymization is set per organization.
Isolation per organization and per tenant
Each organization's data is isolated at every layer. For the portal, isolation is also created on the hypervisor: pool, VLAN and dedicated account per tenant.
Inventory data, not operational data
NaoShift collects topology, versions, capacities and usage metrics. It collects neither the content of your virtual machines, nor your backups, nor your end customers' data.
Exportable logging
Every action, every right change and every console opening is logged, filterable per tenant and exportable to your SIEM.

Outbound flow only, from your IT system.
No inbound port, no permanent access kept on the NaoShift side. The detailed flow diagram is provided on request.
The platforms NaoShift reads and manages
Read-only by default on each; writes enabled target by target with a dedicated account. Brands cited for identification only: NaoShift is affiliated with none of these vendors.
Where we stand, without rounding up
We display the actual state of each process. An ongoing process is announced as such, and we claim no qualification that belongs to a third party.
Seals drawn by NaoShift, under our own brand. No certification mark is reproduced: the ISO, ANSSI and HDS logos are reserved for certified or qualified bodies and offerings.
| Framework | Status | What it means |
|---|---|---|
| ISO/IEC 27001:2022 | Process under way | Information security management system being built on the scope "NaoShift SaaS service and its infrastructure". The certificate, its number and its scope will be published here once obtained. |
| ISO/IEC 27017 and 27018 | Planned as extension | Codes of practice for cloud service security and for the protection of personal data as a processor. They are obtained as an extension of an ISO 27001 certificate. |
| SecNumCloud 3.2 | Not claimed — deployable inside a qualified perimeter | NaoShift is not SecNumCloud qualified and does not claim this qualification. The product is designed to be deployed inside a qualified perimeter without creating a gap: outbound flows only, offline licence, separated administration planes, per-tenant logging. A requirement-by-requirement mapping matrix is provided. |
| HDS — French health data hosting | Not claimed — deployable at a certified hosting provider | NaoShift does not host health data and is not HDS certified. For a certified institution or hosting provider, NaoShift deploys on-premise inside the existing HDS perimeter; the mapping matrix covers the requirements applicable to a third-party software component. |
| NIS2 — Directive (EU) 2022/2555 | Voluntary alignment | NaoShift is not an entity in scope under Article 2 of the directive. Our security measures are aligned with the risk-management measures of Article 21.2, and our commitments to you are contractual. No NIS2 certification exists. |
| GDPR | Processor | Record of processing activities maintained, Article 28 data processing agreement available for signature, data hosted in the European Union. |
How NaoShift answers each requirement
The matrix crosses 52 structuring requirements from SecNumCloud 3.2, ISO 27001:2022, NIS2 and SOC 2, each with the expected evidence and the component involved. Requirements specific to a third-party software component deployed inside a qualified perimeter have a dedicated section. It is provided on request, together with the supplier security file.
Our commitments if something goes wrong
If you are subject to NIS2, you must alert your CSIRT within 24 hours and notify within 72 hours. Our notification commitments are set contractually so that you can meet yours.
First notice
After qualification of a security incident affecting your data or the availability of the service.
Detailed notice
Nature, scope, data involved, immediate measures, available indicators of compromise.
Analysis report
Root cause, timeline, corrective measures and implementation schedule.
Data breach
Notification without undue delay, allowing the controller to comply with Article 33 of the GDPR.
Found a vulnerability?
Write to security@naoshift.io. We acknowledge receipt and keep you informed until the fix. We do not pursue researchers who respect a good-faith test: no access to other customers' data, no service degradation, no disclosure before the fix.
- Out of scope: denial of service, social engineering, tests on our customers' infrastructures
- Fixed vulnerabilities are announced to our customers through a security advisory
What we provide to your procurement and security teams
These documents cover most of what supply-chain security, under Article 21.2.d of NIS2, requires you to collect from your suppliers.
- Supplier security file — mapping to Article 21.2 of NIS2
- ISO 27001, SecNumCloud 3.2 and HDS mapping matrix
- GDPR data processing agreement, Article 28
- Architecture diagram and flow description
- Backup and reversibility policy
- Information security policy
- Summary of the latest penetration test
- Continuity plan and results of the latest restoration test
- ISO 27001 statement of applicability, once the ISMS is established
- Certificate and audit report, once obtained
SecNumCloud is a qualification issued by ANSSI to cloud computing service offerings; HDS is a certification of health data hosting providers. NaoShift is neither SecNumCloud qualified nor HDS certified and does not use the ANSSI security visa. Statements about these frameworks describe the product's ability to be deployed inside a perimeter qualified or certified by a third party, and do not extend to the NaoShift service itself.
Security contact: security@naoshift.io
Frequently asked questions
Not yet. The process is under way on the scope of the SaaS service and its infrastructure. The certificate, its number and its scope will be published on this page once obtained. Meanwhile, the security policy and the statement of applicability are shared under non-disclosure agreement.
Your CISO has questions. We have written answers.
Request the supplier security file and the mapping matrix, or schedule a discussion with the team.






