← Home Security & Sovereignty

Built for the requirements
of public and private organizations.

Security and compliance are not boxes to tick on an RFP. They are the foundations of our platform. This page details how your data is hosted, encrypted, isolated and remains accessible to you.

Sovereign hosting in France.

Vantarian is hosted exclusively on OVH infrastructure. No client data is stored or transferred outside the European Union.

The OVH infrastructure used is certified HDS (Healthcare Data Hosting) and PCI-DSS. These certifications cover the host infrastructure and form the compliance foundation we rely on.

Location France
Host OVHcloud
Infra certifications HDS · PCI-DSS · ISO 27001
Cloud Act Not applicable - French operator

Encryption in transit and at rest.

All communications between your users and the platform are encrypted with TLS 1.3, with systematic HTTPS redirection. Certificates are renewed automatically.

At rest, data stored in the database is encrypted, with keys managed via the OVH KMS. Files uploaded to the platform are also stored on encrypted volumes.

Backups are encrypted with keys separate from those used in production and replicated across multiple French data centers.

One database per client. No exception.

Each client organization has its own dedicated database, its own application environment, its own files isolated on disk. No data is shared between clients.

This strongly isolated multi-tenant architecture guarantees that any failure or malformed query on one environment cannot, under any circumstances, expose another client's data.

Database Dedicated per client
Files Isolated per instance
Backups Compartmentalized per instance
Logs Separated per client

GDPR compliance · Article 28.

Vantarian acts as a data processor within the meaning of Article 28 of the GDPR. We systematically sign a compliant data processing agreement with each of our clients.

  • Register of processing activities kept up to date and made available
  • Configurable retention policy per data type
  • Data subject rights: access, rectification, erasure, portability
  • Logging: every access or modification is traced
  • Data Protection Officer identified and reachable
  • Breach notification within regulatory deadlines

SSO, MFA, password policy.

Vantarian supports single sign-on via your corporate directory. Your users log in with their usual credentials, without creating a new account.

  • SSO SAML 2.0 / OpenID Connect (Azure AD, Microsoft 365, other IdPs)
  • Multi-factor authentication enabled for sensitive profiles
  • Password policy configurable per instance
  • Granular roles and permissions, customizable per workflow
  • Automatic logout after inactivity, configurable

Your data belongs to you.

At any time, you can request a complete extraction of your data in standard format. We provide a structured export covering:

  • Application data in CSV or JSON format depending on entities
  • Generated files and documents, in their original tree structure
  • Access logs and modification history
  • Data schema documentation to facilitate handover

Backups, continuity, support.

  • Automatic daily backups, configurable retention
  • Backup replicas on separate data centers
  • Documented disaster recovery plan, tested annually
  • 24/7 monitoring of critical services
  • Support during business hours, commitments by criticality level
Security questions?

We respond to RFPs and security questionnaires.

Whether you're preparing an RFP, a technical specification or a security questionnaire to fill out, we respond precisely within the deadlines you give us. Write to us describing your need.

Contact us