Security and data protection: your contacts are in safe hands
Hosted in France, encrypted at rest and in transit, replicated continuously, auditable at any time.
Hosting your contact lists on an emailing platform means entrusting personal data to a third party. We know that, and it is a responsibility we have carried since 2002. Dedicated servers in France, end-to-end encryption, quarterly pentests, certified external DPO, Alliance Digitale label. Security at Ediware is not a sales argument displayed on a page and then forgotten. It is infrastructure, documented procedures and a team that applies them every day.
Your data hosted in France, on dedicated and certified servers
The question comes up systematically during qualification: “Where is my data stored?” Short answer: in France, on physical servers reserved exclusively for us, in an ISO 27001 certified datacentre.
Certified hosting, not a shared cloud
Our production infrastructure is hosted at Celeste, in the Equinix datacentre in Saint-Denis. Celeste is ISO 27001 certified. Biometric access control, 24/7 surveillance, electrical and cooling redundancy. We use only dedicated servers. In practice, your data does not end up on the same machines as other companies'. It is something many B-to-B clients check first, and rightly so.
No transfer outside the European Union
The contact data hosted on the platform stays in France. Production, backups, long-term archiving: everything is located on national soil. No transfer to third countries. In practice, this also simplifies your own obligations as a data controller under the GDPR.
The rules
- ISO 27001Equinix datacentre in Saint-Denis, operated by Celeste
- Dedicated serversno machine shared with another company
- France onlyproduction, backups and long-term archiving
Several layers of protection between the internet and your data
A password and an SSL certificate are not enough to secure a platform handling contact databases. Ediware's architecture rests on the principle of defence in depth. Each layer protects the next, and several must be crossed to reach the databases.
Network isolation and multi-layer protection
The database servers are not exposed directly to the internet. They are isolated in a private network, a VLAN, accessible only through an encrypted VPN. Between the internet and your data there is a firewall, a WAF, an NGINX reverse proxy, then the application servers. An attacker who got through one layer would face the next. That is the very principle of defence in depth.
Encryption at every stage
At rest, data is encrypted on the disks in AES-256. In transit, communications use TLS 1.3. Externalised backups are encrypted too. For exchanging files containing personal data, only FTPS and SFTP are allowed. Between your browser and the platform, everything is encrypted end to end.
Penetration tests, not just statements of intent
Anyone can claim their platform is secure. It still has to be checked regularly. Automated pentests are carried out every three months, white box and authenticated grey box. A manual penetration test is conducted every year by a PASSI-certified provider. Critical vulnerabilities are fixed within 48 hours, high ones within 7 days. And the results go to a quarterly security committee so that what needs adjusting is adjusted.
The rules
- AES-256encryption at rest on the disks
- TLS 1.3encryption in transit
- Quarterly pentestswhite box and grey box, authenticated
Controlled access: each employee sees only what they need
The risk does not always come from outside. Controlling internal access matters just as much as protection against attacks. Ediware applies the principle of least privilege at every level of the organisation.
Strong authentication and complete traceability
Access to the information system goes through an encrypted VPN. Servers are reachable only by private SSH key through a bastion. A unique identifier for each employee. Passwords of at least 12 characters, stored in a dedicated manager, rotated every 90 days for privileged accounts. An annual review of rights covers the whole scope.
On the client side too, incidentally, access is secured. SSL is compulsory, two-factor authentication is available, and every action is recorded in the logs. You can check who did what and when on your account.
Every action is named
Four identified administrators on the Ediware side, with exhaustive traceability. Support sees only pseudonymised data.
Strict separation of roles
| Role | What they see | Production data |
|---|---|---|
| Developers | Fictional data sets | No access |
| Technical support | Pseudonymised data | No access |
| Campaign management | Strictly what the service requires | No access |
| Administrator access | Four identified employees | With two-factor authentication |
Five copies of your data, on five media, in three separate sites
A server that fails, a datacentre hit by a disaster. These are scenarios we have anticipated, not theoretical hypotheses. Our backup strategy goes beyond the classic 3-2-1 rule.
Real-time replication and daily backups
The databases are replicated in real time to secondary servers. If the main server goes down, failover is immediate. In parallel, daily backups are made by the host and sent, encrypted, to two remote sites in France. Long-term archiving completes the arrangement.
Continuity and recovery plans that do not stay in a drawer
The BCP and DRP are tested every year. Not merely written, tested. In the event of a server failure, service resumes in under an hour thanks to replication. In the event of a complete loss of the main datacentre, the backup infrastructure can be activated in under 12 hours. These times are measured during the annual exercises, not estimated on paper.
Availability above 99.9%
The availability rate of the emailing platform is tracked monthly. The target: stay above 99.9%, which represents less than 8 hours 48 minutes of downtime a year. The infrastructure at Celeste benefits from permanent monitoring by their managed services team.
Our commitments
- 99,9 %availability
- Real-time replicationof the databases
- Daily backupsexternalised
GDPR compliance: documented procedures, a certified DPO, a professional label
Many software publishers display “GDPR compliant” on their site with nothing behind it. At Ediware, compliance rests on complete documentation, a certified external DPO and a professional label issued by Alliance Digitale. Verifiable elements, not declarations.
An independent, trained external DPO
The Data Protection Officer role is entrusted to a specialist outsourced firm. The DPO is CIPM certified by the IAPP, with more than ten years of experience in personal data protection. She comes in every quarter to train the Ediware team on a specific aspect of the GDPR. The last session covered the IT charter.
Impact assessment, registers and contracts in place
An impact assessment, the well-known DPIA, has been carried out by a specialist firm. The register of processing activities is kept up to date. A DPA governs the relationship between Ediware and each of its clients. Retention periods, processing purposes, security measures: everything is set out in documents available on request.
Privacy Protection Pact label since 2019
Ediware has held the Privacy Protection Pact label from Alliance Digitale since 2019. This label verifies that practices are genuinely compliant: data protection policy, people's rights, consent traceability, cookie management, information system security. Renewal requires updating the answers and a periodic verification.
The rules
- CIPM / IAPPcertification of the external DPO
- Privacy Protection Pactlabelled since 2019, Alliance Digitale
- GDPRimpact assessment, registers and contracts in place
If an incident occurs, you are informed within an hour
Zero risk does not exist. No platform can claim otherwise. What counts is how fast a problem is detected, how transparent we are with the clients concerned, and how quickly the damage can be contained.
Classification and escalation
Incidents are classified into four levels of severity. A critical incident, a server compromise or a data leak, triggers an immediate response. System isolation, suspension of suspect access, mobilisation of the CTO, the DPO and the managed services team. Affected clients are informed within an hour. If the breach concerns personal data, the CNIL is notified within 72 hours.
Permanent watch and responsiveness on vulnerabilities
The team follows the CERT-FR and ANSSI security bulletins for every component of our technical stack. Critical patches are applied within 72 hours. In the event of a zero-day vulnerability, a documented emergency procedure allows exposure to be assessed within two hours and a mitigation to be put in place within four. Better to have planned the procedure before the problem arises.
Our commitments
- Within 1 houryou are informed
- Within 72 hoursnotification to the CNIL where applicable
Talk to an expert Tell us about your needs, no obligation
Frequently asked questions about security and data protection
Where is the contact data I entrust to Ediware hosted?
In France, in a datacentre in France, on dedicated servers hosted by Celeste, ISO 27001 certified. The backups are also located in France, on separate sites. No data is transferred outside the European Union.
Is Ediware ISO 27001 certified?
Our host Celeste is ISO 27001 certified. Ediware does not hold the certification in its own name, but has a documented Information System Security Policy and Security Assurance Plan, with quarterly pentests and an annual penetration test by a PASSI-certified provider.
Who has access to my contact data on the platform?
Access is restricted on the principle of least privilege. Four identified administrators have full access with exhaustive traceability. Technical support sees only pseudonymised data. Developers have no access to production data, they work on data sets created from scratch.
What happens in the event of a security breach?
The procedure provides for immediate isolation of the compromised system, suspension of access, correction of the flaw and password resets. Clients are warned within an hour. If personal data is involved, the CNIL is notified within 72 hours, in accordance with the GDPR.
Does Ediware have a DPO?
Yes. The role is entrusted to a specialist outsourced firm, CIPM certified by the IAPP, with more than ten years of experience. The DPO reports to general management and trains the team every quarter. Her appointment is registered with the CNIL.
How does Ediware handle backups?
Real-time replication of the databases, daily backups sent to two separate sites in France, encrypted in AES-256. Restoration is tested monthly on a pre-production environment. In the event of a server failure, service resumes in under an hour.
Is the Privacy Protection Pact label still valid?
Yes, Ediware has held the label since 2019. It is issued by Alliance Digitale and covers data protection, people's rights, consent traceability and system security. Renewal involves updating the answers and a periodic verification by the body.
Can I audit Ediware's security?
Yes. Our contracts provide for audits or inspections. Recent pentest reports are available on request under a confidentiality agreement. The ISSP, the DPA and the SAP are available to clients and prospects who wish to assess our level of security before committing.
Is my data encrypted?
At rest on the disks in AES-256, in transit between your browser and the platform in TLS 1.3, and in the externalised backups in AES-256. Exchanges of files containing personal data go exclusively through FTPS or SFTP.
Your contacts deserve infrastructure that can be audited
Tell us what you need to know about the hosting, the access controls, the backups and the register. You get the answers in writing, whether you sign or not.
