English English

Security at ecosio

Protecting every connection

Security at ecosio

Overview

As the trusted intermediary for our customers’ business communications, ecosio recognises the responsibility that comes with processing and routing business-critical data. Protecting the confidentiality, integrity and availability of our platform is central to how we operate.

Our security programme is built on robust governance, well-defined policies and proven operational processes that align with recognised international standards.

This page provides an overview of the certifications, controls and practices that help safeguard our platform and customer data.

Compliance certifications

CLICK TO DOWNLOAD OUR CERTIFICATES

Open source dependencies & licenses

Apache-2.0

Artistic-2.0

BlueOak-1.0.0

BSD-2-Clause

BSD-3-Clause

CC-BY-3.0

CC-BY-4.0

LGPL-3.0 / LGPL-3.0-only

MIT

MUI X Pro commercial license (where applicable)

Python-2.0

Unicode-3.0

Unicode-DFS-2016

Zlib

Data subprocessors

AWS

Data Storage / Data Hosting. US

ecosio Affiliate service

Subsidiary company. DE

ecosio Affiliate service

Subsidiary company. UK

Google Cloud Platform

Data Storage / Data Hosting. IE

DataDog

Infrastructure and Network monitoring. US

Security controls

Security governance

ecosio operates an Information Security Management System (ISMS) and a Business Continuity Management System (BCMS), with clear accountability for security governance, risk management, security operations, and incident response.

Security policies

Security policies define expected behaviour and acceptable use across the organisation. Access to systems is granted only after required onboarding steps are completed.

Security awareness training

Training and awareness activities are continuous, so personnel understand the security responsibilities relevant to their roles.

Risk management

We manage security as a risk-based programme. ecosio performs risk assessments, maintains risk treatment actions, and reassesses risks when material changes occur.

Supplier management

Supplier onboarding includes risk due diligence proportional to vendor criticality. Supplier controls are aligned to criticality and monitored over the life of the relationship.

Access lifecycle governance

We maintain formal processes for joiners, movers, and leavers, as well as for changes and approvals, so that access rights and production changes remain controlled and auditable.

Regulatory obligations

ecosio supports customer compliance needs through documented controls, secure processing practices, and controlled evidence sharing.

Cloud infrastructure

We rely on major cloud providers’ security capabilities and implement configuration baselines, access controls, monitoring, and resilience patterns appropriate to service objectives. Where applicable, workloads are designed for high availability across zones and to support continuity strategies.

Network segmentation

The platform is hosted on cloud infrastructure with layered network protections. We separate environments and apply segmentation to limit lateral movement and reduce blast radius.

Vulnerability management

Vulnerability management and security testing support continuous hardening and remediation across platform components.

Endpoint protection

Workforce endpoints are centrally managed and required to meet baseline controls. Endpoint protection is in place to reduce malware risk and to support detection of suspicious activity.

Access management

Access is role-based and aligned to least privilege. Strong authentication is enforced for workforce and administrative access. Authentication and access events are logged and monitored, and access rights are reviewed periodically to ensure they remain appropriate.

Privileged access

Administrative access is highly restricted to authorised personnel only, protected with MFA, and subject to enhanced monitoring. Privileged activities are logged so we can detect misuse and support forensic investigation when needed.

Secure development lifecycle

Security is integrated into engineering practices. Changes are reviewed, tested, and promoted through segregated environments. We use automated checks where applicable and maintain processes and security scanners to manage vulnerabilities and security defects.

Third-party components

We manage third-party components as part of our overall risk programme. Dependencies are assessed and monitored throughout their lifecycle.

Data classification

We classify information and apply handling requirements based on sensitivity. Where we use test data, the approach is governed by anonymisation to avoid unintended exposure.

Encryption

Data is protected in transit using TLS 1.2 and 1.3 and protected at rest using industry-standard encryption (e.g., AES-256), with key and certificate lifecycle controls.

Data retention

Data protection requirements are addressed through defined handling, retention, and deletion concepts. Contractual documentation (e.g., DPAs) can be provided for customer engagements.

Security monitoring

ecosio operates centralised monitoring capabilities to identify abnormal activity across key systems. Alerts follow defined escalation paths, and log collection and retention are governed to support both security detection and operational resilience.

Threat intelligence

We incorporate relevant threat intelligence to tune detections, prioritise remediation, and adapt monitoring to emerging threats.

Incident response

We follow a documented incident lifecycle. Incidents are assessed against contractual and regulatory obligations, and customers are informed via defined channels when notification is required. Service availability and major incidents are communicated via the public status page.

Backups

Backups are performed regularly and stored redundantly. Restore procedures are tested on a defined cadence.

Disaster recovery

For larger-scale disruption scenarios, recovery is supported by infrastructure automation and Infrastructure-as-Code, enabling rapid reprovisioning and controlled restoration.

Service maintenance

Our operational processes are designed to minimise disruption and provide predictable communications. Planned maintenance and relevant service updates are communicated through agreed channels.

FAQs

Do you support security questionnaires and customer audits?

Yes. We support customer security due diligence.

Evidence is shared in a controlled manner (need-to-know) and can be provided where appropriate.

Yes. We provide a data processing agreement to support GDPR-aligned processing arrangements.

Service availability and major incident communications are shared via our public status page.

We use TLS 1.2 and TLS 1.3 for data transmitted over untrusted networks. Certificates and renewal are managed through defined lifecycle controls.
Data at rest is protected using industry-standard encryption (e.g.,AES-256), with defined key and certificate lifecycle controls. Access to cryptographic material is restricted and monitored.
Access is role-based and aligned to least privilege. Strong authentication is enforced for workforce and administrative access, and access rights are reviewed periodically.
Yes. We use vetted subprocessors for cloud hosting, security monitoring, communications, and operational tooling.

We follow a documented incident lifecycle. Incidents are assessed against contractual and regulatory obligations.

Customers are informed via defined channels when notification is required.

Dernière ligne droite avant la facturation électronique en France

Tout pour finaliser votre préparation avant le go-live :

FAQ : les réponses aux questions clés

Checklist : les actions prioritaires

Guide pays : calendrier et obligations

Livre blanc : bien choisir votre solution

Replay : les conseils de nos experts