Skip to content
[Security and data]

Your clients’ data stays yours.

Veille handles confidential professional information: site profiles, registers, reports. Here is how it is protected, and how the decision stays human.

[01]

Isolation per firm

Each firm is isolated from the others. Every request is filtered by firm, and any identifier sent by the browser is checked again on the server.

  • Role-based access: owner, administrator, consultant, junior, viewer.
  • Private files, served only through temporary links.
  • Encryption in transit (TLS) and of secrets at rest.
  • Audit log of approvals, deliveries and permission changes.
[02]

Hosting and sub-processors

Servers, database, files and backups are hosted in the European Union. Emails go through Resend (United States), covered by standard contractual clauses. The list of sub-processors is public; any addition is announced 30 days in advance.

[03]

Law 09‑08 and GDPR

We apply Moroccan Law 09‑08, under the supervision of the CNDP, and the GDPR for people in the European Union. For your clients’ data, your firm is the controller and Asrar acts as processor, under the data processing agreement.

[04]

Mandatory human approval

No match enters the register and no report is sent without the approval of an authorised consultant. A report can only contain approved items: the rule is enforced by the server.

  • Juniors prepare; consultants, administrators and owners approve.
  • Every approval keeps its author, its date and the text it relies on.
  • A rejection comes with a reason, which can become a firm rule.
[05]

Artificial intelligence

By default, a built-in, deterministic engine runs on our servers and sends nothing to a third party. A model provider (Anthropic) can be enabled: it only receives the passages it needs and does not train its models on your data. The content of texts is treated as data, never as an instruction.

[06]

Retention and deletion

Registers, reports and approvals are kept for 2 years with Solo and 7 years with Cabinet. You can export your data at any time. When a firm is deleted, its data is erased from active systems within 30 days, then from backups within a further 35 days. An archived client stays available read-only.

[07]

Report a vulnerability

Write to security@asrar.example. We acknowledge receipt and keep you informed of the fix.