Bizzdesign Unify: An AI-native platform for faster, better transformation decisions.
Technical and organizational measures related to Bizzdesign Products
1. Horizzon
1.1. Confidentiality (Access Control & Encryption)
- Access Control: Logical access is restricted through a formal Access Control Policy. External administrative access requires Multi-Factor Authentication (MFA) and is routed via encrypted VPN/TLS channels.
- Encryption:
- In transit: All data transmitted over public networks is encrypted using industry-standard protocols (HTTPS/TLS 1.2 or higher).
- At rest: Customer data is encrypted at rest using AES-256 (managed via AWS KMS).
- Network Security: We use hardened network perimeters, firewalls with restrictive policies, and a Web Application Firewall (WAF) to protect against unauthorised access and common web threats (SQLi, XSS).
1.2. Integrity (Data & System Security)
- Vulnerability Management: We conduct regular vulnerability scanning and periodic third-party penetration testing. Security patches are evaluated and applied every two weeks, with expedited timelines for critical issues.
- Malware Protection: Managed antivirus and anti-malware protections are in place, with signature definitions updated at least daily.
- Change Management: Changes to production environments follow a formal Change Management procedure, including code reviews, automated testing, and segregation of duties (whereby access to production is restricted to authorised personnel without development responsibilities).
1.3. Availability and Resilience
- Infrastructure: Hosted on Amazon Web Services (AWS) with a multi-zone architecture to ensure high availability (99.6% SLA).
- Backups: Automated, encrypted daily backups are performed and stored in two geographically separate locations, supporting a Recovery Point Objective (RPO) of 24 hours.
- Disaster Recovery: A documented Business Continuity and Disaster Recovery plan is maintained and tested twice a year, with a Recovery Time Objective (RTO) of 3 days.
1.4. Organisational Measures
- Personnel Security: All employees undergo background checks prior to hiring and must complete regular security awareness training.
- Incident Response: Our Incident Response Plan establishes formal procedures for detecting, reporting, and responding to security events, including root cause analysis.
- Third-Party Risk: Vendors and sub-processors are managed under a Third-Party Management Policy, which includes annual due diligence assessments of their security posture (e.g., review of AWS SOC reports).
- Internal Audits: The Global IT & Security Manager conducts annual internal audits and quarterly checks to verify the effectiveness of our controls.
1.5. Data Minimisation and Transparency
- Audit Logging: The Horizzon platform maintains comprehensive audit logs of administrative and user activity, accessible to customers via the UI or Open API.
- Data Retention: Data is retained and disposed of in accordance with our Data Management Policy, ensuring secure erasure of media upon decommissioning.
2. Hopex
2.1. Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
- Verification of the security level of the cloud application provider before hiring them.
- Enabled two-factor authentication for our entire information system.
- Implemented strict user and access lifecycle processes.
- Implemented regular security reviews (access reviews, backup integrity reviews, vulnerability reviews, etc.).
- Implementation of data classification and retention policies (to ensure data confidentiality).
2.2. Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
- Implementation of a security incident management process.
- Implementation of a personal data backup policy.
2.3. Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing
- Implementation of regular security reviews (access reviews, back-up integrity reviews, vulnerability reviews, etc.).
- Establishment of security monitoring committees (risk committee, HR committee, IT committee, legal committee).
2.4. Measures for user identification and authorisation
- Activation of a two-factor authentication for our entire information system.
- Implementation of strict user and access life cycle processes.
- Implementation of regular security reviews (access reviews, back-up integrity reviews, vulnerability reviews, etc.).
2.5. Measures for the protection of data during transmission
- Use of encrypted communication (TLS 1.3).
2.6. Measures for the protection of data during storage
- Use of encrypted storage (AES 256).
- Implementation of a strict access management policy.
2.7. Measures for ensuring physical security of locations at which personal data are processed
- Implementation of a physical security policy.
- Implementation of regular security reviews (access reviews, integrity reviews of backups, vulnerability reviews, etc.).
2.8. Measures for ensuring events logging
- Implementation of a log management policy (365 days retention).
- Concentration of logs in a log well.
2.9. Measures for ensuring system configuration, including default configuration
- Implementation of anti-malware agent.
- Implementation of a secure gateway for Cloud applications.
2.10. Measures for internal IT and IT security governance and management
- Implementation of an information systems security policy.
- Implementation of an IT Charter.
2.11. Measures for certification/assurance of processes and products
- Certification SOC2 TYPE2.
2.12. Measures for ensuring data minimisation
- Enumeration of the category of personal data collected and processed
2.13. Measures for ensuring limited data retention
- Implementation of a data retention policy.
2.14. Measures for allowing data portability and ensuring erasure
- Implementation of a data reversibility process in case of expiration or termination of contracts.
