Back to home

Security & data protection

Your data deserves an environment designed to protect it.

Security, confidentiality and data control are built into the design of OPERIANCE.

Layers of protection

  1. OrganisationCustomer perimeter
  2. Access controlRoles and permissions
  3. IsolationData separation
  4. DataGoverned usage
  5. Audit logging / monitoringTraceability

Security designed into the product.

01

Organisation isolation

Data and access are structured to maintain a strict separation between the different organisations using OPERIANCE.

02

Access control

The features and data a user can reach depend on their organisation, role and permissions.

03

Privileged access protection

Sensitive administrative access benefits from reinforced mechanisms, including multi-factor authentication.

04

Encryption

Communications rely on appropriate encryption mechanisms, and data benefits from the protections provided by our hosting infrastructure.

05

Audit logging

Sensitive operations and significant administrative actions can be logged to support traceability.

06

Monitoring

Controls and detection mechanisms help identify certain abnormal security events or behaviours.

Hosting

Primary infrastructure hosted in Europe.

OPERIANCE's primary infrastructure is hosted in Ireland, within the European Union.

Some technical services or third-party providers may involve additional processing, in line with their contractual terms and the applicable data protection mechanisms.

Primary region

OPERIANCE
Primary infrastructure
Ireland — European Union

Data & confidentiality

You stay in control of your data.

Export

Users have mechanisms to export the relevant data within their scope of access.

Retention

Retention rules are defined according to the nature of the data and the context in which it is used.

Deletion

Deletion mechanisms are governed to avoid accidental or inconsistent removals.

Access

Data is only accessible to authorised users and services, within their scope.

Learn more about data protection

Artificial intelligence

AI that enriches information — never invents it.

Our models analyse, structure and enrich the information used for qualification and positioning.

Enrich the information. Never invent it.

Information missing from a CV does not necessarily mean the skill is missing.

When information isn't sufficiently established, OPERIANCE flags what still needs to be confirmed.

  • Minimising the data transmitted wherever possible
  • Human and business validation of information that requires confirmation
  • A clear distinction between source information, confirmed information and system-generated analysis

Abuse prevention

Mechanisms designed to limit abnormal usage.

  • Limits on certain requests and usage patterns
  • Access controls
  • Protections on sensitive functions
  • Monitoring of certain events
  • Separation of privileges
  • Restrictions on sensitive administrative operations

Data lifecycle

A governed data lifecycle.

OPERIANCE applies different rules depending on the type of data, its usage, its status and the applicable obligations.

Where it cannot be reliably established that a piece of data may be deleted, the system takes a conservative approach.

  1. 01Creation / import
  2. 02Usage
  3. 03Update
  4. 04Retention
  5. 05Export / end of relationship
  6. 06Deletion or anonymisation according to the applicable rules

Continuity & backups

Continuity and resilience.

OPERIANCE relies on professional cloud infrastructure that includes availability and data protection mechanisms.

  • Managed infrastructure
  • Provider-level redundancy
  • Backups managed by the infrastructure

Precise availability, restoration or continuity commitments depend in particular on the infrastructure services used and the applicable contractual terms.

Integration security

Controlled integrations.

OPERIANCE integrations are designed to limit exchanges to the information required and to use appropriate authentication and authorisation mechanisms.

  • Authentication of calls
  • Appropriate permissions
  • Organisation separation
  • Validation of exchanges
  • Traceability
  • Access revocation when required

Administrative access

Particular attention to sensitive access.

  • MFA for privileged access
  • Logging of sensitive administrative actions
  • Separation of rights
  • Additional controls on critical actions

Due diligence

Does your security team need to go further?

We can provide additional information as part of a security review, a GDPR assessment or a contracting process.

  • Additional security information
  • Data protection details
  • Information on providers and subprocessors where needed
  • Security questionnaires
  • Applicable contractual documentation

Transparency

No promises we cannot demonstrate.

Our approach is to document what is actually implemented and to clearly distinguish verified guarantees from elements that depend on our providers or on specific contractual commitments.

Do you have specific security requirements?

Let's talk with your teams to review your technical, contractual and organisational requirements.