Data rules before the first line of code.

Before we open a single file, we agree with you in writing what we read, where it is processed, how long it is kept and how it is deleted.

Before any access

Five points agreed in writing.

  1. Confidentiality

    A signed confidentiality agreement comes before any file is shared.

  2. Where, and for how long

    We state in writing, before any access, where your data is processed and for how long.

  3. A dedicated mailbox

    Documents reach a mailbox created for the project, never a personal inbox.

  4. Read-only first

    Write or send rights come only after a separate written agreement.

  5. Deletion and export

    A retention period, automatic deletion, and a full export when you leave.

Controls we can build in

Six controls, agreed project by project.

  • Roles

    Each person sees and does only what their role allows.

  • Two-factor sign-in

    A second factor is required to sign in.

  • Audit trail

    Who opened, changed, approved or sent what, and when.

  • Encrypted document storage

    Documents are encrypted where they are stored.

  • Retention and automatic deletion

    Files are deleted automatically when the agreed period ends.

  • Export at exit

    Your data is exported to you in full, then deleted.

What we say plainly

Straight answers to the usual questions.

We would rather be exact than reassuring.

Where is our data processed?

We state it in writing, before any access: where your data is processed and for how long. We do not publish one general answer here, because it depends on each project and the services it uses.

Who can see our documents?

Only the accounts you approve. Each one has a role and two-factor sign-in, and every action is recorded in an audit trail you can review.

What happens to our data when the project ends?

It is exported to you in full, then deleted, following the retention period and the deletion steps set in the data rules signed at the start.

What about Law 09-08 and the CNDP?

In Morocco, Law 09-08 governs personal data, under the oversight of the CNDP. We list the personal data a project touches, so that your declaration or authorisation request can be prepared. Your counsel confirms what applies to you: this page is not legal advice.

Can we send you our security questionnaire?

Yes, through the form below. We answer it in writing before any access is opened.

IT and security

Send us your IT questionnaire.

Or ask the first question your IT team will ask.

Topic

Thank you. We’ll reply by e-mail.

The message could not be sent. Please try again in a moment.

Start with a 20-minute conversation.

Tell us where you want AI to make a difference first. No commitment at this stage.

Request a first conversation