Skip to content
OSE Galaxy
Trust & compliance

Security & data protection.

Institutional clients work with us because they trust the data, the method — and the way we operate. This page documents the commitments your DPO, your security team and your procurement office will want to verify.

At a glance

Four commitments.

EU-based hosting

All production data on OVH infrastructure in France (Roubaix region). No data leaves the European Union.

GDPR by design

Subject access, rectification, erasure and portability are operational, not just stated.

Daily encrypted backups

Automated daily backups, encrypted at rest, point-in-time recovery on the database.

ISO 27001 in progress

Formal ISMS being implemented. Target certification: 2027.

Infrastructure

Where your data lives.

  • Primary hosting: OVH (France, EU). Production servers physically located in OVH data centres, governed by EU data-protection law.
  • Database: PostgreSQL on the same EU infrastructure. TLS connections; credentials in environment variables, never in source control.
  • Backups: Daily automated backups with retention, encrypted and stored separately from the live database.
  • Transport: All public traffic over HTTPS (TLS 1.2+); HSTS enabled on production domains.
  • No third-country transfers: Institutional data is not transferred outside the EU. Sub-processors are limited, documented and EU-based wherever feasible.
  • Sovereign option: National or sovereign instances can be deployed on your infrastructure with your governance.
GDPR

Data protection in practice.

OSE in Africa acts as data controller for account holders on Connect, Expert and the newsletter, and as data processor when engaged on a diagnostic or advisory mandate. In both cases we honour the rights granted by the GDPR.

Right of access

Email contact@ose.africa to receive a machine-readable export of your personal data.

Right to rectification

Update profile fields from your account, or request a correction by email.

Right to erasure

Delete your account from settings, or request full erasure by email. Backups are purged within the retention window.

Right to portability

Personal data is exportable as JSON or CSV on request.

Right to restriction

Pause processing while a dispute is resolved. We confirm in writing.

Right to object

Decline analytics tracking; consent is per purpose in the cookie banner.

Privacy contact: contact@ose.africa. A formal DPA is available on request to institutional clients prior to signature. Full policy: /legal/privacy.

Application security

How we build.

  • Authentication: Argon2id password hashing, short-lived JWT access tokens with rotating refresh tokens; sessions invalidated on password reset.
  • Authorization: Role- and tier-based access control on every API endpoint; geographic gating enforced client- and server-side.
  • Audit log: Sensitive actions (role changes, access grants, data exports) persisted in an audit table.
  • Dependency hygiene: Node.js LTS, Next.js, NestJS, Prisma; security patches applied promptly.
  • Secret management: Credentials and tokens stored outside source control, server-side only.
  • Security headers: HSTS, X-Frame-Options, nosniff, referrer policy and a Content-Security-Policy under observation before enforcement.
Roadmap

What's next.

  1. 1

    2026 — Formal ISMS rollout

    Policies, asset register, incident-response runbook, aligned with ISO 27001 controls.

  2. 2

    2026 — Granular cookie consent

    Per-purpose consent (analytics / functional / marketing) with full audit trail.

  3. 3

    2027 — ISO 27001 certification

    External audit and certification on the production scope (Atlas + Expert + Connect).

  4. 4

    Ongoing — Penetration testing

    Annual third-party penetration test on the public-facing platforms.

Questions

What DPOs and procurement ask.

Where is our data hosted?
On OVH infrastructure in France (European Union). Production servers, database and backups stay in the EU; no third-country transfer of institutional data.
Is a Data Processing Agreement available?
Yes. A DPA is available on request to institutional clients before signature, together with the security overview, hosting attestation and references list.
Are you ISO 27001 certified?
Not yet. A formal Information Security Management System aligned with ISO 27001 controls is being implemented, with certification targeted for 2027 on the Atlas, Expert and Connect scope.
Can you host a sovereign instance?
Yes. « OSE in [country] » can be deployed on sovereign cloud or local hosting with national governance — see the Gulf sovereign page.
Next step

Need the full due-diligence pack?

DPA template, security overview, hosting attestation, references list — available on request to institutional clients. It shortens procurement by weeks.

The OSE Galaxy

One mission, three levers: build the science and practice of entrepreneurial ecosystems in Africa.

  1. Observewhat makes ecosystems work— OSE
  2. Trainthe builders who construct them— ADALIA
  3. Advancethe science that illuminates them— EERS