Security
Your continuity plans hold your most strategic information. Here's how we protect them.
Encryption everywhere
TLS 1.2 minimum (TLS 1.3 supported) in transit, AES-256 at rest. Keys managed by our cloud infrastructure.
Strong authentication
TOTP 2FA with recovery codes, enterprise OpenID Connect sign-in (Entra ID, Okta) on request, sessions in secure cookies (__Host-, HttpOnly) with rotation and remote revocation.
RBAC access control
Separate platform and organization roles, full action auditing, SHA-256 tamper-evident chain.
European hosting
Business data hosted in the European Union (Convex on AWS Ireland, web servers at OVHcloud in France). Sub-processors outside the EU are listed on the Trust Center, with their safeguards.
Audit & logging
Every sensitive action is logged with IP, User-Agent, country and cryptographic hash. Apache cross-check for forensic spoofing detection.
Anomaly detection
Brute-force, credential stuffing and unusual-country logins auto-detected and notified to administrators.
Where ResiPlan stands
What exists today for ResiPlan as a vendor. The product helps customers prepare for DORA, NIS2 and ISO 22301; it does not make them compliant on its own.
- GDPR — processor (Art. 28)DPA available
- DORA — contractual clauses (Art. 30)Annex to the DPA
- ISO 27001Not certified
- SOC 2Not certified
- ISO 22301 (for ResiPlan itself)Not certified
Report a vulnerability
We welcome responsible disclosure. No legal action will be taken against good-faith security researchers.
Or see security.txt for technical details (RFC 9116).