Trust
Commitments that can be verified.
A supplier of critical systems must accept being audited. This page sets out what we commit to and how an organisation can check it.
Our commitments
Security and resilience
Security is built into the life cycle of a system, from design through to decommissioning. Segmentation, least privilege, traceability of privileged access, vulnerability management against committed timescales, and continuity plans proven by exercise rather than by drafting.
Data protection
Data entrusted to us remains the property of the client organisation. We apply minimisation, separation by purpose, encryption at rest and in transit, and a defined retention period for each processing activity. No derived use is made of data from an engagement.
Responsible use of technology
Every system serves a legitimate, documented purpose proportionate to the need. Decisions with significant effect stay under human control. Limits, responsibilities and conditions of use are explicit.
Ethics and integrity
We decline engagements whose purpose contravenes fundamental rights. Our anti-corruption arrangements, conflict-of-interest rules and internal reporting procedure are provided during pre-qualification.
Quality and continuity
Every increment is checked against acceptance criteria defined before it starts. Maintenance in operational and security condition is the subject of commitments distinct from those covering initial construction.
Sovereignty and reversibility
The place of deployment, the control of the keys and the exit plan are settled before go-live. Interfaces and formats are documented so that another supplier can take the work over.
Verification
What can actually be measured.
A security commitment that translates into no observable quantity commits nobody. The three quantities below can be written into a contract, and they are the ones on which we accept being judged.
- The level of service maintained during an incident, function by function.
- The time between an event occurring and its detection by the organisation.
- The time to restore, observed during an exercise rather than estimated.
Service level during an incident
Levels, from top to bottom:nominal servicereduced service, essential functions maintainedservice interrupted
- Prepared organisation
- Unprepared organisation
- Before
- Critical assets are inventoried and the response has been rehearsed.
- Detection
- The anomaly is seen by monitoring, not reported by the user.
- Containment
- The affected perimeter is isolated; essential functions hold.
- Recovery
- Restoration follows a tested procedure, within a defined time.
Disclosure regime
What is public, what is provided, what never is.
This division does not vary with the interlocutor or with the commercial stakes of the consultation. Knowing it in advance avoids a request we could not answer.
Published on this site
- Commitments on security, data protection and responsible use.
- Deployment modes offered and the principle of key custody.
- The company’s registration identifiers.
- Responsible disclosure policy and reporting address.
Provided at pre-qualification
- Full internal policies and current attestations.
- Capability statement matched to the scope of the consultation.
- References, with the prior written agreement of the organisation concerned.
- Curricula of the individuals proposed and insurance cover.
Never provided
- The name of a client not authorised for publication, in any form.
- The architecture, configuration or vulnerabilities of a system operated by a client.
- Data processed in the course of an engagement, including anonymised data.
- Operational capabilities whose disclosure would expose an organisation.
Certifications
What we do not display.
No certification appears on this site until it has been obtained and verified. A process under way is not a certification, and an internal roadmap is not an achievement.
Current attestations, insurance policies and full internal policies are provided on request during pre-qualification, to an identified organisation.
No certification badge or logo is used decoratively: any future claim will identify a verifiable certificate and its exact scope.
Site security
Report a vulnerability.
Konect Groupe welcomes vulnerability reports concerning its publicly exposed systems. The procedure, the scope and the commitments made to those who report are published.
Responsible disclosure policyConsultations · Pre-qualifications · Partnerships
Let’s discuss your project.
Describe your priority, its operating context and the intended outcome. We will route the enquiry to the right person.