All compliance documents
- Version
- 1.0 · Effective 2026-08-11
- Owner
- security@depozza.eu
- Review cycle
- Annual
- Mapped controls
- SOC 2 CC7 · ISO 27001 A.5.24–A.5.28 · GDPR art. 33–34
Detection
- Application and server errors are captured centrally and reviewed.
- Automated security scans run against the database configuration and dependencies.
- Anyone — user, host or researcher — can report a suspected issue to security@depozza.eu.
Severity levels
- P1 — confirmed exposure of personal data, payment data or account takeover. Response starts immediately.
- P2 — exploitable vulnerability with no evidence of exploitation. Response within 1 business day.
- P3 — low-impact issue or hardening gap. Scheduled into normal work.
Response steps
- Contain: revoke the affected credentials or access path first.
- Assess: determine which data and which users are affected, using the audit log.
- Remediate: ship the fix and verify it against the original report.
- Record: document timeline, root cause and follow-up actions.
Notification
If a personal-data breach is likely to result in a risk to individuals, Depozza notifies the competent supervisory authority (CNIL) within 72 hours of becoming aware of it, and informs affected users without undue delay when the risk is high. Notifications describe what happened, what data was involved and what users should do.
After the incident
Every P1 and P2 incident gets a written post-incident review with concrete preventive actions and an owner. Reviews are kept as evidence for audits.
Questions about this document
security@depozza.euThis document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.