ICE
To be set
Common Enterprise ID

Security · Data protection
Every control described on this page maps to a mechanism actually implemented in the product. What is not done yet is written here too, on the same page, in the same detail.
Two-factor auth
TOTP
RFC 6238 · recovery codes
Passwords
bcrypt
hashed · cost 12
HSTS
2 years
includeSubDomains · preload
Audit trail
Actor + IP
on every sensitive action
Message us on WhatsApp
Implemented
Six mechanisms, all verifiable in the product: they apply to every hosted institution, with no option and no surcharge.
CSP, HSTS (2 years, includeSubDomains, preload), X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy and Permissions-Policy (camera, microphone, geolocation disabled) apply to every route. The header that advertises the framework is removed.
Each user turns 2FA on from their own account: a TOTP secret compatible with Google Authenticator, Authy or 1Password, single-use recovery codes, and disabling from the same screen.
bcrypt with a cost of 12, for passwords and API keys alike. An API key is shown once, at creation: after that only its hash exists on the server.
Permissions are recomputed from assigned roles, in institution or platform scope. An assignment that reaches its expiry date stops granting access immediately, with no manual step.
Every sensitive action is written with its author, the entity and its id, the IP address, the user agent and the timestamp. The trail is indexed by institution and by date.
Every record carries its institution id and queries are filtered on it. Domain, theme and public content are institution-specific as well.
Transparency
A security page is judged as much on what it refuses to display as on what it announces. Here is the real state of the open work.
No ISO 27001 or SOC 2 certification
We display no certification logo, because we hold none. The controls above are verifiable in the product; they are not audited by a third party.
No published availability figure
We publish no uptime percentage: there is neither an independent measurement instrument nor a contractual service-credit mechanism that would make it verifiable.
Application-level isolation, not Row-Level Security yet
Isolation between institutions is enforced by the code. Moving to PostgreSQL RLS policies is planned and documented in our architecture blueprint; until it ships, we do not claim it.
Content Security Policy still being tightened
The CSP is active across the domain but still allows the inline scripts and styles the framework needs. Moving to a nonce-based policy is tracked work, not an already-ticked box.
Rate limiting is per instance
The counter that limits public forms and key-authenticated APIs lives in memory, so it is per application instance. A multi-replica deployment must add gateway-level limiting.
Morocco compliance
Administrative and tax identifiers for the institution, verifiable with official authorities.
ICE
To be set
Common Enterprise ID
RC
To be set
Commercial Register
IF
To be set
Tax ID
CNSS
To be set
Social security
CNDP · Law 09-08
This institution's CNDP declaration status is not published on this site. The compliance tooling described below is available in the admin workspace regardless.Not stated
Tooling
Compliance is assessed by the CNDP, not by a badge on a website. What we provide is the tooling — available in the institution's admin workspace.
Eight-control checklist
The points to verify before an audit review or a CNDP enquiry, each with its status.
Processing register
Purposes, legal bases and retention periods, documented in the same place as the data.
Transfer mapping
The minimum mapping the CNDP requires for processing that leaves Moroccan territory.
72-hour notification
The breach-notification path towards the CNDP and towards the people concerned.
This tooling helps your institution meet its obligations. It is neither legal advice nor a declaration filed on your behalf.
Transparency
E-mail, SMS and WhatsApp delivery, as well as payments, go through an abstraction layer: the provider actually used is a configuration choice, specific to each institution and each environment. So we would rather not display a generic list here that would not match your instance.
Still have a question?
Message us on WhatsApp — your chat arrives with the context of this page.
Leadership, IT or DPO: send us your questions or your assessment grid. We answer point by point, stating what is in place and what is not yet.
No document is promised blind: we answer your grid rather than sending a generic brochure.