Sovereignty

Your data stays with you, ours stays under French jurisdiction

Sovereignty is built into the design of DataBait: the solution rests on an exclusively French and European chain of control (company, directors, host, infrastructure) and on a strict data minimisation principle. At no point does your data leave your information system.

Sovereignty by design

Three questions determine which legal regime your data falls under: who owns the vendor, under which law the infrastructure runs, and what is actually stored. At DataBait, all three answers are French, and the third one is “nothing”.

0record Of your organisation's data stored with us Neither your database nor your files are ever sent to us
100% French capital No foreign shareholding
3links Under French law, end to end Vendor company, qualified host, certified operator

End-to-end French chain of control · No transfer outside the European Union

Chain of control

An end-to-end French chain of control

The principal, the qualified host, and the certified operator all fall under the same sovereign jurisdiction. No link in the chain escapes French and European law.

A company incorporated under French law

DataBait is registered with the Paris RCS and wholly owned by French interests: its founders and their entities. No foreign shareholding, no non-European control: it falls exclusively under French law and European Union law, GDPR included.

SecNumCloud-qualified infrastructure

The infrastructure is hosted on a platform qualified SecNumCloud by ANSSI, the highest French standard for trusted cloud: data located exclusively in France, French and European law applying to the exclusion of all others, immunity to extraterritorial laws, including the US CLOUD Act.

ISO 27001-certified operator

Operations are run by a company incorporated under French law and certified ISO 27001, 100% owned by French entities and individuals. The certification is audited and renewed by an independent external body.

Data minimisation

We store none of your data

Your database and your files are never sent to us and never leave your information system.

The only things retained on our infrastructure are the inbound emails and SMS received by the fictitious accounts, when their sender is not on the allowlist you define. In other words, we retain only messages that originate outside your organisation and are potentially unlawful, precisely the elements that make up the evidence being sought.

What this means for your compliance. The messages retained contain, by construction, no business data belonging to your organisation. Your exposure surface at a third party is therefore nil: there is nothing on our side that could constitute a leak of your data.

The scope, point by point

  • Your database: never transmitted
  • Your customer files: never transmitted
  • Inbound emails and SMS outside the allowlist: retained, as elements that make up the evidence
  • Business data of your organisation retained with us: none
  • At the end of the contract: returned on request, no residual data of yours

Verifiable by third parties

Contractual and certified guarantees

Our sovereignty commitments do not rest on our word alone: they are written into the contract and audited by independent bodies.

Sovereignty foundation

SecNumCloud-qualified hosting · ISO 27001 · Contractual audit rights

  1. SecNumCloud · ANSSI

    Data hosted in France, on infrastructure qualified at the highest level of the French trusted cloud framework.

  2. ISO 27001

    Certified operator, incorporated under French law, audited and renewed by an external body.

  3. Audit rights · Terms of Service

    The Terms of Service give the Client the right to request a technical audit of the Solution (art. 9.3), by a qualified independent auditor.

  4. Extraterritorial laws

    No transfer outside the EU, immunity to the CLOUD Act and to non-European orders.

  5. Reversibility

    At the end of the contract, the messages retained are returned to you on request. No residual data of yours.

The SecNumCloud qualification, the ISO 27001 certification, and the contractual audit rights stack up: to the vendor's word are added assurances verifiable by independent third parties.

Sovereignty and data protection

Where is the data hosted?

On infrastructure qualified SecNumCloud by ANSSI, located exclusively in France. No transfer outside the European Union. The SecNumCloud qualification is the highest French standard for trusted cloud.

Can the CLOUD Act or a foreign authority access your data?

No. The SecNumCloud qualification guarantees that French and European law alone applies, and immunity to extraterritorial laws, notably the US CLOUD Act. The chain of control is French end to end: vendor company, qualified host, and certified operator all fall under French jurisdiction.

Exactly what data does DataBait retain?

DataBait stores none of your data. Your database and your files are never sent to us. The only things retained are the inbound emails and SMS received by the fictitious accounts when their sender is not on your allowlist, that is, messages originating outside your organisation and potentially unlawful, which contain no business data belonging to your organisation.

Can we audit DataBait?

Yes. The Terms of Service give the Client the right to request a technical audit of the Solution (article 9.3), carried out by a qualified independent auditor, within a written and binding framework. This contractual audit stacks on top of the assurances given by independent third parties: the SecNumCloud qualification issued by ANSSI and the operator's ISO 27001 certification, both audited and renewed by external bodies.

See the detailed audit procedure

What happens to the data at the end of the contract?

All retained messages are returned to you on request. Since none of your organisation's data was ever copied there, no residual data of yours exists to recover or erase.

Get in touch

Let us introduce the team and the product

We would be glad to introduce the team and the product to you in detail at a meeting, and to answer all your questions about sovereignty and the protection of your data.

Reply within 24 business hours

Request a demo or ask a question

Pick your channel. We reply within 24 business hours.