Trust centre

Commitments that can be verified.

A supplier of critical systems must accept being audited. Six areas set out what we commit to, what is measured, and how an organisation can check it.

Request the security documentation

  1. 01

    Security

    Security is built into the system lifecycle, from design to decommissioning.

  2. 02

    Data and sovereignty

    Data entrusted to us remains the property of the client organisation.

  3. 03

    Continuity

    Continuity is proven by a restoration exercise, not by a document.

  4. 04

    Compliance

    No certification is displayed until it is obtained and verifiable.

  5. 05

    Reversibility

    The exit plan is settled before commissioning, not at the point of departure.

  6. 06

    Transparency

    What is public, what is shared, what never leaves.

Pre-qualification

The complete documentation is shared, not published.

Internal policies, current attestations, insurance cover and authorised references are provided to an identified organisation once the request has been qualified. What we publish here is what can be published without exposing a client.

What you receive

Eighteen documents, three per area.

  • Security

    • Detailed security statement by domain.
    • Vulnerability management policy and committed timeframes.
    • Incident response procedure and client notification terms.
  • Data and sovereignty

    • Statement of data residence by component.
    • Key management and custody arrangements.
    • Processing register applicable to the engagement envisaged.
  • Continuity

    • Backup policy and schedule of restoration exercises.
    • Recovery objectives proposed for the scope envisaged.
    • Report of the most recent exercise on a comparable scope.
  • Compliance

    • Complete internal policies and current attestations.
    • Anti-corruption commitment and code of conduct.
    • Insurance cover and tax certificates.
  • Reversibility

    • Reversibility policy and template exit plan.
    • List of export formats by type of system.
    • Template handover file delivered at the end of an engagement.
  • Transparency

    • List of subcontractors and hosts applicable to the engagement.
    • Change log of the published policies.
    • Security advisories concerning systems operated for the client.

Request the security documentation

Site security

Report a vulnerability.

Konect Groupe welcomes vulnerability reports concerning its publicly exposed systems. The procedure, the scope and the commitments made to those who report are published.

Responsible disclosure policy

Consultations · Pre-qualifications · Partnerships

Let’s discuss your project.

Describe your priority, its operating context and the intended outcome. We will route the enquiry to the right person.