Security & data protection
Your data deserves an environment designed to protect it.
Security, confidentiality and data control are built into the design of OPERIANCE.
Layers of protection
- OrganisationCustomer perimeter
- Access controlRoles and permissions
- IsolationData separation
- DataGoverned usage
- Audit logging / monitoringTraceability
Security designed into the product.
Organisation isolation
Data and access are structured to maintain a strict separation between the different organisations using OPERIANCE.
Access control
The features and data a user can reach depend on their organisation, role and permissions.
Privileged access protection
Sensitive administrative access benefits from reinforced mechanisms, including multi-factor authentication.
Encryption
Communications rely on appropriate encryption mechanisms, and data benefits from the protections provided by our hosting infrastructure.
Audit logging
Sensitive operations and significant administrative actions can be logged to support traceability.
Monitoring
Controls and detection mechanisms help identify certain abnormal security events or behaviours.
Hosting
Primary infrastructure hosted in Europe.
OPERIANCE's primary infrastructure is hosted in Ireland, within the European Union.
Some technical services or third-party providers may involve additional processing, in line with their contractual terms and the applicable data protection mechanisms.
Primary region
Data & confidentiality
You stay in control of your data.
Export
Users have mechanisms to export the relevant data within their scope of access.
Retention
Retention rules are defined according to the nature of the data and the context in which it is used.
Deletion
Deletion mechanisms are governed to avoid accidental or inconsistent removals.
Access
Data is only accessible to authorised users and services, within their scope.
Learn more about data protection
Artificial intelligence
AI that enriches information — never invents it.
Our models analyse, structure and enrich the information used for qualification and positioning.
Enrich the information. Never invent it.
Information missing from a CV does not necessarily mean the skill is missing.
When information isn't sufficiently established, OPERIANCE flags what still needs to be confirmed.
- Minimising the data transmitted wherever possible
- Human and business validation of information that requires confirmation
- A clear distinction between source information, confirmed information and system-generated analysis
Abuse prevention
Mechanisms designed to limit abnormal usage.
- Limits on certain requests and usage patterns
- Access controls
- Protections on sensitive functions
- Monitoring of certain events
- Separation of privileges
- Restrictions on sensitive administrative operations
Data lifecycle
A governed data lifecycle.
OPERIANCE applies different rules depending on the type of data, its usage, its status and the applicable obligations.
Where it cannot be reliably established that a piece of data may be deleted, the system takes a conservative approach.
- 01Creation / import
- 02Usage
- 03Update
- 04Retention
- 05Export / end of relationship
- 06Deletion or anonymisation according to the applicable rules
Continuity & backups
Continuity and resilience.
OPERIANCE relies on professional cloud infrastructure that includes availability and data protection mechanisms.
- Managed infrastructure
- Provider-level redundancy
- Backups managed by the infrastructure
Precise availability, restoration or continuity commitments depend in particular on the infrastructure services used and the applicable contractual terms.
Integration security
Controlled integrations.
OPERIANCE integrations are designed to limit exchanges to the information required and to use appropriate authentication and authorisation mechanisms.
- Authentication of calls
- Appropriate permissions
- Organisation separation
- Validation of exchanges
- Traceability
- Access revocation when required
Administrative access
Particular attention to sensitive access.
- MFA for privileged access
- Logging of sensitive administrative actions
- Separation of rights
- Additional controls on critical actions
Due diligence
Does your security team need to go further?
We can provide additional information as part of a security review, a GDPR assessment or a contracting process.
- Additional security information
- Data protection details
- Information on providers and subprocessors where needed
- Security questionnaires
- Applicable contractual documentation
Transparency
No promises we cannot demonstrate.
Our approach is to document what is actually implemented and to clearly distinguish verified guarantees from elements that depend on our providers or on specific contractual commitments.
Do you have specific security requirements?
Let's talk with your teams to review your technical, contractual and organisational requirements.
