Security
This English version is provided for convenience. In case of discrepancy, the French version prevails.
Version of 1 October 2026. You entrust us with working data, sometimes sensitive. This page explains how we protect it, and what we do not claim.
Where your data is#
In France, at Scaleway, in its data centres in the Paris region. Scaleway is ISO/IEC 27001 and HDS certified: these are our host’s certifications, not node.this’s. No data leaves the European Union unless you choose so yourself (your own key for an AI provider outside the EU, or signing in with Google). Our list of processors is public, and any change is announced to you 30 days in advance.
How it is protected#
- Encrypted in transit (HTTPS everywhere) and at rest (database and files).
- Private by default: every request checks that you are allowed to access what you ask for; a project is visible only to you, to the members of your team and to the people you share it with.
- Download links signed, valid for 15 minutes.
- Passwords kept in hashed form by our authentication service; the application itself never sees any. You can also sign in with Google.
- Two-factor authentication available: a code from an authenticator app, asked at each sign-in, that you turn on from your account.
- Backed up every 6 hours, backups kept for 30 days, and their restoration is tested.
Who can access it at our end#
Nobody views the content of your projects without your written request. When you ask us to, for a diagnosis for instance, the viewing covers only the project, or the space, you designate, and it is recorded. The only exception is a legal obligation, of which you are informed unless the law forbids it.
If something happens#
Every data breach is documented, and you are notified without undue delay and, where possible, no later than 48 hours after its discovery, so that you can meet your own obligations. Think you have found a vulnerability? Report it.
What we do not claim#
- node.this is not HDS or ISO 27001 certified: our host is, not the service itself.
- No third-party penetration testing yet: it is planned.
- All customers’ computations run on shared infrastructure; your data is separated by access control, not by dedicated machines.
Going further#
A detailed security file, and answers to your security questionnaire, are provided to you on request at contact@tyo-data.fr. Our terms of use also provide for a right of audit.
There are no articles to list here yet.