Trust centre
Commitments that can be verified.
A supplier of critical systems must accept being audited. Six areas set out what we commit to, what is measured, and how an organisation can check it.
Pre-qualification
The complete documentation is shared, not published.
Internal policies, current attestations, insurance cover and authorised references are provided to an identified organisation once the request has been qualified. What we publish here is what can be published without exposing a client.
What you receive
Eighteen documents, three per area.
Security
- Detailed security statement by domain.
- Vulnerability management policy and committed timeframes.
- Incident response procedure and client notification terms.
Data and sovereignty
- Statement of data residence by component.
- Key management and custody arrangements.
- Processing register applicable to the engagement envisaged.
Continuity
- Backup policy and schedule of restoration exercises.
- Recovery objectives proposed for the scope envisaged.
- Report of the most recent exercise on a comparable scope.
Compliance
- Complete internal policies and current attestations.
- Anti-corruption commitment and code of conduct.
- Insurance cover and tax certificates.
Reversibility
- Reversibility policy and template exit plan.
- List of export formats by type of system.
- Template handover file delivered at the end of an engagement.
Transparency
- List of subcontractors and hosts applicable to the engagement.
- Change log of the published policies.
- Security advisories concerning systems operated for the client.
Site security
Report a vulnerability.
Konect Groupe welcomes vulnerability reports concerning its publicly exposed systems. The procedure, the scope and the commitments made to those who report are published.
Consultations · Pre-qualifications · Partnerships
Let’s discuss your project.
Describe your priority, its operating context and the intended outcome. We will route the enquiry to the right person.