Edusign

Security and dataprotection

Technical and organisational measures for data security and protection. Last updated 19 August 2025.

ESCP Business SchoolLe WagonVeoliaUniversité Paris CitéSKEMA Business SchoolCADFEMVinci EnergiesUniversité de BordeauxÉcole PolytechniqueJedha BootcampL'OréalUniversité de RennesHEC ParisLaho FormationRenaultUniversité de Bretagne OccidentaleKEDGE Business SchoolCompétences & DéveloppementUbisoftIÉSEGFasterclassSephoraSciences Po BordeauxL’École des CSEPernod RicardBSBFormatexSafranCentrale NantesAlternance Conseil FormationLegrandCentraleSupélecAriane MéditerranéeEurofins ScientificInstitut Mines-TélécomRocket SchoolBureau VeritasISTECInetumErametBoulangerCroix-Rouge françaiseESCP Business SchoolLe WagonVeoliaUniversité Paris CitéSKEMA Business SchoolCADFEMVinci EnergiesUniversité de BordeauxÉcole PolytechniqueJedha BootcampL'OréalUniversité de RennesHEC ParisLaho FormationRenaultUniversité de Bretagne OccidentaleKEDGE Business SchoolCompétences & DéveloppementUbisoftIÉSEGFasterclassSephoraSciences Po BordeauxL’École des CSEPernod RicardBSBFormatexSafranCentrale NantesAlternance Conseil FormationLegrandCentraleSupélecAriane MéditerranéeEurofins ScientificInstitut Mines-TélécomRocket SchoolBureau VeritasISTECInetumErametBoulangerCroix-Rouge françaiseESCP Business SchoolLe WagonVeoliaUniversité Paris CitéSKEMA Business SchoolCADFEMVinci EnergiesUniversité de BordeauxÉcole PolytechniqueJedha BootcampL'OréalUniversité de RennesHEC ParisLaho FormationRenaultUniversité de Bretagne OccidentaleKEDGE Business SchoolCompétences & DéveloppementUbisoftIÉSEGFasterclassSephoraSciences Po BordeauxL’École des CSEPernod RicardBSBFormatexSafranCentrale NantesAlternance Conseil FormationLegrandCentraleSupélecAriane MéditerranéeEurofins ScientificInstitut Mines-TélécomRocket SchoolBureau VeritasISTECInetumErametBoulangerCroix-Rouge françaiseESCP Business SchoolLe WagonVeoliaUniversité Paris CitéSKEMA Business SchoolCADFEMVinci EnergiesUniversité de BordeauxÉcole PolytechniqueJedha BootcampL'OréalUniversité de RennesHEC ParisLaho FormationRenaultUniversité de Bretagne OccidentaleKEDGE Business SchoolCompétences & DéveloppementUbisoftIÉSEGFasterclassSephoraSciences Po BordeauxL’École des CSEPernod RicardBSBFormatexSafranCentrale NantesAlternance Conseil FormationLegrandCentraleSupélecAriane MéditerranéeEurofins ScientificInstitut Mines-TélécomRocket SchoolBureau VeritasISTECInetumErametBoulangerCroix-Rouge française

Security measures

Last updated : 19 August 2025

Introduction

Edusign strives to be as transparent as possible when it comes to managing your data. For more information, you can also consult our privacy policy, as well as our commitments on AI and student data.

We have implemented technical and organisational measures to protect your personal data. These measures are regularly updated to provide the best possible level of protection.

Trust Center - official source

All our security, privacy and compliance information is maintained and updated in the Trust Center (policies, certifications, architecture, availability, procedures).

This page provides a summary and practical references: for details and updates, please refer to the Trust Center first.

Access the Trust Center

Data transfers and encryption

The entire data processing chain is secured by encryption. Edusign uses modern encryption technologies compliant with standards set by ANSSI.

  • Transaction security via TLS encryption to and from our services.
  • At-rest encryption of documents before and after signing using AES-256 bit encryption.
  • Use of keys greater than 2048 bits and secure protocols such as RSA.

Certifications

Edusign holds certificates for electronic signature, electronic seal and timestamping. Details of these certificates are available on request at support@edusign.fr.

To ensure ongoing compliance, we conduct regular audits.

Development security

Internal development processes are in place for our teams to ensure secure development of our solution. A security officer is responsible for organising, managing and monitoring security measures for information system security management.

  • Following best practices set by the Open Web Application Security Project (OWASP).
  • "Security by design" approach. In other words, development is not carried out before an analysis of the security consequences.
  • Automatic and manual testing.
  • Code reviews and modifications.
  • Peer evaluation.

Personnel management

All Edusign employees are familiar with IT tools. They are trained in IT security best practices recommended by ANSSI. Furthermore, employees are kept informed of the latest practices and technological developments in IT security. Edusign employees act knowingly and do their utmost to protect your personal data.

The following measures are in place:

  • Information security and personal data protection training for new employees.
  • Regular communications to all teams to raise awareness.
  • Access and role management policy.
  • Password management policy.
  • Confidentiality commitment.

We have implemented a role management policy and, as such, we limit access to each employee's role in accordance with the principle of least privilege. A rights management review is carried out quarterly.

Infrastructure access

Edusign relies on hosting partners to ensure optimal security of its infrastructure, having notably implemented an information systems security policy meeting the requirements of several standards and certifications (PCI-DSS certification, ISO/IEC 27001 certification, SOC 1 TYPE II and SOC 2 TYPE II attestations, etc.).

Physical access management

  • Identity verification.
  • Centralised door access management via badge system.
  • Single-person airlock.
  • Surveillance equipment.

Logical access control to data

  • Password management policy.
  • Firewall & regularly updated antivirus.
  • Logging & documented access control policy.

Vulnerability detection

Edusign regularly performs analyses to detect potential vulnerabilities. Edusign also engages third parties to refine these analyses. Measures are then implemented to eliminate or limit these vulnerabilities. Non-exhaustive list of protocols in place:

  • Bug bounty programme
  • Regular vulnerability scanning
  • Vulnerability alerts and monitoring
  • Code reviews

Incident management

In the event of a breach in the vulnerability detection programme leading to a cyber attack, Edusign commits to notifying clients and competent authorities of the information necessary to best manage the vulnerabilities. Edusign will respond as quickly as possible to requests from authorities and clients regarding this breach.

To date, Edusign has not experienced any breach of its IT system leading to access to personal data. We do our utmost to keep it that way.

Service availability and data backup

Edusign does everything possible to guarantee high availability and service continuity. Your data is stored on secure servers with daily backup to another server. Non-exhaustive list of protocols in place:

  • Real-time server and database monitoring with alerts.
  • Notification protocols in the event of partner failure.
  • Scalable servers with redundant backup.
  • Vulnerability and intrusion testing.
  • Business continuity plan.
  • Disaster recovery plan.

In the event of service unavailability, Edusign will inform its users by any means. For any questions regarding technical and organisational measures for data security and protection, please contact support@edusign.fr.

View previous versions of our security policy