Security & data protection.
Institutional clients work with us because they trust the data, the method — and the way we operate. This page documents the commitments your DPO, your security team and your procurement office will want to verify.
Four commitments.
EU-based hosting
All production data on OVH infrastructure in France (Roubaix region). No data leaves the European Union.
GDPR by design
Subject access, rectification, erasure and portability are operational, not just stated.
Daily encrypted backups
Automated daily backups, encrypted at rest, point-in-time recovery on the database.
ISO 27001 in progress
Formal ISMS being implemented. Target certification: 2027.
Where your data lives.
- Primary hosting: OVH (France, EU). Production servers physically located in OVH data centres, governed by EU data-protection law.
- Database: PostgreSQL on the same EU infrastructure. TLS connections; credentials in environment variables, never in source control.
- Backups: Daily automated backups with retention, encrypted and stored separately from the live database.
- Transport: All public traffic over HTTPS (TLS 1.2+); HSTS enabled on production domains.
- No third-country transfers: Institutional data is not transferred outside the EU. Sub-processors are limited, documented and EU-based wherever feasible.
- Sovereign option: National or sovereign instances can be deployed on your infrastructure with your governance.
Data protection in practice.
OSE in Africa acts as data controller for account holders on Connect, Expert and the newsletter, and as data processor when engaged on a diagnostic or advisory mandate. In both cases we honour the rights granted by the GDPR.
Right of access
Email contact@ose.africa to receive a machine-readable export of your personal data.
Right to rectification
Update profile fields from your account, or request a correction by email.
Right to erasure
Delete your account from settings, or request full erasure by email. Backups are purged within the retention window.
Right to portability
Personal data is exportable as JSON or CSV on request.
Right to restriction
Pause processing while a dispute is resolved. We confirm in writing.
Right to object
Decline analytics tracking; consent is per purpose in the cookie banner.
Privacy contact: contact@ose.africa. A formal DPA is available on request to institutional clients prior to signature. Full policy: /legal/privacy.
How we build.
- Authentication: Argon2id password hashing, short-lived JWT access tokens with rotating refresh tokens; sessions invalidated on password reset.
- Authorization: Role- and tier-based access control on every API endpoint; geographic gating enforced client- and server-side.
- Audit log: Sensitive actions (role changes, access grants, data exports) persisted in an audit table.
- Dependency hygiene: Node.js LTS, Next.js, NestJS, Prisma; security patches applied promptly.
- Secret management: Credentials and tokens stored outside source control, server-side only.
- Security headers: HSTS, X-Frame-Options, nosniff, referrer policy and a Content-Security-Policy under observation before enforcement.
What's next.
- 1
2026 — Formal ISMS rollout
Policies, asset register, incident-response runbook, aligned with ISO 27001 controls.
- 2
2026 — Granular cookie consent
Per-purpose consent (analytics / functional / marketing) with full audit trail.
- 3
2027 — ISO 27001 certification
External audit and certification on the production scope (Atlas + Expert + Connect).
- 4
Ongoing — Penetration testing
Annual third-party penetration test on the public-facing platforms.
What DPOs and procurement ask.
- Where is our data hosted?
- On OVH infrastructure in France (European Union). Production servers, database and backups stay in the EU; no third-country transfer of institutional data.
- Is a Data Processing Agreement available?
- Yes. A DPA is available on request to institutional clients before signature, together with the security overview, hosting attestation and references list.
- Are you ISO 27001 certified?
- Not yet. A formal Information Security Management System aligned with ISO 27001 controls is being implemented, with certification targeted for 2027 on the Atlas, Expert and Connect scope.
- Can you host a sovereign instance?
- Yes. « OSE in [country] » can be deployed on sovereign cloud or local hosting with national governance — see the Gulf sovereign page.
Need the full due-diligence pack?
DPA template, security overview, hosting attestation, references list — available on request to institutional clients. It shortens procurement by weeks.