Security ● Hosting ● Compliance
Robust Security
You entrust Stafiz with the management of your business: your projects, your time spent, your costs, and your margins. This page details how this data is hosted, protected, and backed up.
- ISO 27001 certified
- Amazon Web Services Hosting
- Data replicated in France
- Electronic invoicing compatible
ISO 27001
certification obtained
99.8%
average annual availability
3 sites
accommodation with automatic relay
30 days
daily backups kept
Certifications and compliance
Stafiz relies on a recognized international standard for information security, and on dedicated partners for regulated processing.
ISO 27001 Certification
Stafiz is ISO 27001 certified, the international standard for information security management. It governs risk identification, internal processes, and technical measures applied to data protection.
Electronic invoicing
Stafiz is a solution compatible with electronic invoicing. Invoice sending and receiving flows rely on our partner Iopole, a specialist in electronic invoice transmission.
Our security and compliance information is centralized in the Stafiz Trust Center .
Accommodation
Our website is hosted by Amazon Web Services, one of the world's most recognized hosting providers. This hosting offers us several advantages:
- Secure infrastructure.
- Dynamic capacity: the servers automatically adjust when additional capacity is needed, or in the event of a production surge on our platform. This prevents outages and, for you, the loss of access to your account and data.
- Backup servers and environments: The servers are located at three different sites. If one fails, the other two instantly take over. If the failure causes Stafiz to shut down at one of the sites, the configuration allows for the creation of a new environment within minutes.
Security measures
Site security is ensured through various means:
- Hosting security: see the previous section.
- System security: Stafiz software is developed on Laravel, which contains many levels of security at the core of its functions.
- Cybersecurity: the software code is protected against classic attacks: SQL injections, cookie theft, communication interception, XSS.
- HTTPS connection: 2048-bit RSA (SHA256withRSA). We have an A rating from SSL Labs.
- Security alerts: Activity on the platform uses secure connections. Alerts are automatically sent to our teams when an action triggers one of the many security checks we have defined.
- Encryption: confidential data (names, passwords) is encrypted.
Our software has been audited by an external consulting firm that performs penetration tests on the code. These audits are replicated regularly as new lines of code are added to the software, particularly when entire modules are added.
Access rights
User access rights are defined by your company's administrators. If a user attempts to access a page for which they are not authorized, they are blocked and an alert is sent to our technical and security teams for investigation.
Service commitment
The service is maintained operational and online 24/7/365, with an average annual uptime of 99.8%. Any incident can be reported to the support line by phone or email. Upon opening an incident, a unique identifier is assigned to track it until its resolution. All incident processing begins with classification:
Blocking incident
An essential feature may no longer function, even partially. The resolution time or implementation of a workaround will be 1 business day from the date the incident is reported.
Embarrassing incident
The service is disrupted but may still function, although the service level cannot be guaranteed. The resolution time is 3 business days from the date the incident is reported.
Minor incident
The service is not disrupted and can operate at the guaranteed service level. The response time is 30 business days from the date the incident is reported.
DILYNX SAS undertakes to maintain the service operational and online under the conditions described above. Penalties may be applied if this commitment is not met: the fixed penalty amount is equal to 30% of the monthly fee for the period during which the downtime exceeded the contractual commitment. To benefit from the penalties, the Client must submit a written request to Stafiz within five (5) business days of discovering the breach of said commitments.
Backups and reversibility
All the data you entrust to us is stored using Amazon Web Services' RDS system. The data is replicated across multiple servers distributed in several geographical areas (in France) to ensure maximum security against loss.
Copies of the database are made daily and kept for 30 days.
Data reversibility: As a Stafiz user, you can extract all your data at any time via the export pages provided in the tool. Data reversibility is guaranteed during your subscription and for up to 30 days after the end of your service subscription.
The Stafiz Trust Center
Certifications, security measures and associated documentation: everything is gathered in one place, for your technical, purchasing and legal teams.