Information security policy

The top-level policy: what Depozza protects, who is accountable, and the rules everyone working on the platform follows.

All compliance documents
Version
1.0 · Effective 2026-08-11
Owner
security@depozza.eu
Review cycle
Annual
Mapped controls
SOC 2 CC1–CC2 · ISO 27001 cl. 5, A.5.1

Purpose and scope

This policy covers the Depozza platform (web application, database, background jobs) and all personal and transactional data processed by Depozza SAS. It applies to founders, employees, contractors and anyone with access to production systems.

Objectives

  • Confidentiality: personal data, contracts and payment references are visible only to the parties entitled to see them.
  • Integrity: bookings, payouts and dispute records cannot be altered outside the documented application flows.
  • Availability: the marketplace and its data remain accessible, with restorable backups.

Accountability

Depozza SAS's management is accountable for information security. A single named security owner maintains these policies, triages vulnerability reports sent to security@depozza.eu, and reviews access at least annually.

Rules that apply to everyone

  • Multi-factor authentication on every account that can reach production or the payment provider.
  • No production personal data in local development, screenshots or support tickets.
  • No shared logins; access is personal and revoked when someone leaves.
  • Security concerns are reported immediately, without fear of blame.

Enforcement and review

Breaching this policy can lead to access being withdrawn and, for contractors, to contract termination. The policy is reviewed at least once a year and whenever the platform changes materially.

Questions about this document

security@depozza.eu

This document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.