Audit

You can audit DataBait

You do not have to take our word for it. The Terms of Service give the Client the right to request a technical audit of the Solution, carried out by a qualified independent auditor agreed between the parties, within a written and binding framework. This contractual right adds to two independent qualifications covering our hosting foundation: SecNumCloud (ANSSI) for the infrastructure, ISO 27001 for its operator.

  • Contractual technical audit
  • Qualified independent auditor
  • SecNumCloud-qualified hosting · ISO 27001

A contractual right

An audit right written into the contract

Article 9.3 of the Terms of Service allows the Client to request a technical audit of all or part of the Solution. This is not a sales promise, nor a clause to be negotiated case by case: it is a binding contractual provision, present in the contract by default.

The audit is carried out by a qualified independent auditor, chosen by agreement between the Parties and, failing agreement, appointed by the interim relief judge. So you are relying neither on an audit we would produce ourselves, nor on a provider imposed on you: the third party doing the checking is independent, and you take part in choosing it.

The procedure

How an audit unfolds

A clear framework, known in advance, that applies to every client. Four steps, from the request to the operations.

  1. You request the audit and propose an auditor

    The Client requests the audit and proposes an independent auditor. The auditor is agreed between the Parties; failing agreement, the scope of the assignment may be set by the interim relief judge, within the requirements of article 9.3.

  2. The three Parties sign a tripartite agreement

    Every audit is conditional on first concluding a written tripartite agreement between the Client, the Provider, and the auditor, signed by all three before any operations begin. This agreement sets the scope, the dates, the location, the methodology, and the exhaustive list of items that may be disclosed. Operations may not start less than one month after it is signed.

  3. You settle the scope and the methodology

    The agreement sets out the exact scope of the audit (code, platform, compliance, cybersecurity) and the methodology chosen: for cybersecurity, black, grey, or white box. What will be examined, and how, is written down before anything starts.

  4. The audit takes place on site

    Operations take place on site, on our premises or those of our partners, never remotely. The Client may request one audit per calendar year. At the end, the auditor delivers a confidential audit report, reserved for the sole use of the Client and the Provider.

The auditor

Who may audit

An audit right is only worth something if the auditor has the skills to exercise it. The clause sets qualification requirements according to the type of audit.

Cybersecurity audit

The auditor must be an organisation PASSI-qualified by ANSSI, and the staff it assigns must be certified OSCP, CEH, CISSP, or CISA. Every individual involved is personally bound by the same qualification and confidentiality requirements.

GDPR compliance audit

The auditor must be certified CIPP/E, DPO, or equivalent. As with cybersecurity, the qualification applies to the auditor and to each member of its staff alike.

Confidentiality and right of refusal

The auditor, and where applicable each member of its staff, enters into a confidentiality agreement with the Provider before operations begin. The Provider holds a right of reasoned refusal over the staff proposed: the auditor remains bound by the same obligations as we are.

The framework

A framework that protects both parties

The DataBait infrastructure holds the evidentiary material of every one of its clients. The safeguards around the audit do not limit your right: they protect every client, you included.

Confidentiality

The report and the scope stay confidential

No information relating to the Provider's IP addresses, domain names, or infrastructure outside your strict contractual scope may be disclosed to the auditor or appear in its report. The audit report is itself confidential, reserved for the Client and the Provider, and the auditor keeps no copy of it. You audit what concerns you, not other clients' data, and the same holds the other way round.

On site

On site, with no capture

The audit takes place on our premises, never remotely. The auditor may not bring any third-party electronic device onto them, and any capture (photograph, video, screenshot, file copy, recording) is prohibited. Only equipment supplied by the Provider is used. These rules preserve the integrity of the shared infrastructure on which everyone's evidence rests.

Frequency and cost

Once a year, at the Client's expense

The Client may request one audit per calendar year, and bears the full cost: the auditor's fees, provision of premises and equipment, the time our teams spend on it, and the advisory costs tied to the tripartite agreement. A framework we stand behind, which keeps the audit for genuine verification.

Liability

Joint and several liability

The Client is jointly and severally liable, alongside the auditor, for any breach by the auditor or its staff of the obligations under article 9.3, the tripartite agreement, and the confidentiality agreements. Any audit conducted outside this procedure is null and void, and may be suspended without notice. The framework holds both parties to the same standard.

Three checks

The audit does not replace third-party certifications

Your own audit is only one of the three assurances available to you. It adds to two qualifications covering DataBait's hosting foundation, issued, audited, and renewed by independent bodies.

So three independent checks are added to the vendor's word: yours on the Solution, ANSSI's on the infrastructure, and the ISO certification body's on its operator. The French chain of control and data minimisation are detailed on the Sovereignty page; the regulatory obligations covered are detailed on the Compliance page.

See the Sovereignty page

Three independent levels of verification

  • Your technical audit: a contractual right (Terms of Service art. 9.3), by an independent auditor agreed between the parties
  • SecNumCloud-qualified hosting · ANSSI: it is the infrastructure hosting DataBait that is qualified, at the highest level of the French trusted cloud framework, with data in France
  • ISO 27001: the operator of that infrastructure is certified, audited, and renewed by an external body
  • eIDAS timestamp: every piece of evidence sealed by a QTSP on the EU Trusted List

Auditing the Solution

Can we audit DataBait?

Yes. Article 9.3 of the Terms of Service gives the Client the right to request a technical audit of all or part of the Solution, carried out by a qualified independent auditor chosen by agreement, under a written tripartite agreement signed before any operations begin.

How many audits may we request?

One technical audit per calendar year.

Who chooses the auditor?

The auditor is agreed between the Client and the Provider; failing agreement, the scope of the assignment may be set by the interim relief judge. The auditor must meet qualification requirements: for cybersecurity, an organisation PASSI-qualified by ANSSI with staff certified OSCP, CEH, CISSP, or CISA; for GDPR compliance, CIPP/E, DPO, or equivalent certification.

Can the audit be done remotely?

No. Operations take place exclusively on site, on the premises of the Provider or its partners. No third-party electronic device may be brought in, and any capture is prohibited.

Who bears the cost of the audit?

The full cost is borne by the Client: the auditor's fees, provision of premises and equipment, the time the Provider's teams spend on it, and the costs tied to the tripartite agreement.

What can the audit cover?

All or part of the Solution: code, platform, compliance, cybersecurity. The exact scope is settled in the tripartite agreement. No information outside your strict contractual scope, and none of the infrastructure or data of other clients, is disclosed to the auditor.

Does the audit replace SecNumCloud or ISO 27001?

No, it adds to them. Note the distinction: the SecNumCloud qualification covers the infrastructure hosting DataBait, not DataBait itself. It is issued by ANSSI, and the ISO 27001 certification covers the operator of that infrastructure. Your contractual audit stacks on top of these two assurances, both audited and renewed by independent bodies.

Get in touch

Check for yourself

We would be glad to introduce the team and the Solution, and to walk you through the audit framework and our partners' certifications. Book 30 minutes: we will answer all your due diligence questions.

Reply within 24 business hours

Request a demo or ask a question

Pick your channel. We reply within 24 business hours.