Data & security
What we sign before touching anything
This page exists so your DPO and procurement team find their answers without having to ask us. Every document mentioned is available on request, before any technical meeting and before any signature.
The compliance pack
Five documents, sent together, with no strings and without having to be chased.
- 01
Data processing agreement (DPA)
GDPR Article 28-compliant. Subject matter, duration, nature and purpose of processing, categories of data and data subjects, processor obligations, named sub-processors, technical and organisational measures, and the fate of data at contract end.
- 02
Standard contractual clauses and transfer impact assessment
Morocco has no adequacy decision. The transfer therefore relies on the clauses of decision 2021/914, module 2 or 3 depending on your configuration, together with an impact assessment documenting applicable local law and the supplementary measures in place.
- 03
Pre-filled security questionnaire
Our written answers on identity management, multi-factor authentication, least privilege, encryption in transit and at rest, logging, incident management, access review and business continuity. If your questionnaire is more detailed, we complete it within five business days.
- 04
Company profile
One page: legal name, Moroccan legal identifiers, headcount, professional indemnity insurance, banking references, named contacts for security and data protection.
- 05
Sample deliverable
A real, anonymised framing document with its specification, acceptance cases and exclusion list. It is the best way to judge our standard before entrusting us with anything.
Technical and organisational measures
Access and identity
- Named access only, never a shared account
- Mandatory multi-factor authentication on all client access
- Connection through your bastion and identity provider, not ours
- Least privilege, time-bound access
- Revocation within 24 hours when someone leaves the project
- Quarterly access review, sent to the client
Data
- No client data at rest outside the European Union
- No local copies on workstations
- Pseudonymised or anonymised data in development environments
- Encryption in transit (TLS 1.2 minimum) and at rest
- Access logging retained and available on request
- Deletion or return of data at contract end, with written attestation
Endpoints and network
- Managed endpoints with full-disk encryption enabled
- Centrally managed antivirus and security updates
- Automatic locking and enforced password policy
- Remote access only through VPN or the client's bastion
- Removable media prohibited on projects handling personal data
People
- Confidentiality clause in every employment contract
- Reference checks at hiring
- Annual security and GDPR awareness training, with attendance records
- Formalised equipment return and access revocation on departure
- Two trained people on every client file lasting over three months
Incidents and continuity
- Client notification within 24 hours of a data breach
- Written incident procedure with named roles and a decision tree
- Backups of our own systems tested by restore
- Two contacts per file, to avoid any single point of failure
- Professional indemnity insurance in force
What we do not have
A security page that lists only strengths is not credible. Here is what we cannot claim today.
- We are not ISO 27001 certified. We apply measures aligned with Annex A and document them, but we have no certification audit.
- We have no SOC 2 report. If your procurement process requires one strictly, we cannot meet that at this stage.
- We do not host your data: it stays with your cloud provider, in your tenant. That choice is deliberate, but it means hosting security remains your responsibility.
- Morocco is not an adequate country under the GDPR. The transfer is governed, but it remains a transfer outside the European Union that must be documented in your register.
Security and data protection contact
For any question about security, data protection, or to report a vulnerability, write to the address below. We acknowledge receipt within one business day.
info@azerops.comTwenty minutes is enough to know whether we are useful
No sales deck. You describe the need, we say whether it is in scope, at what price and on what timeline. If it is not for us, we say so during the call.