Skip to content
GMAO CLOUD
en

Trust

Where your data lives and what happens if something breaks

These are the two questions any serious client ends up asking, usually in the form of a thirty-page questionnaire. Here are the answers, without having to request them.

Hosting and isolation

Where your installation lives and why it doesn’t share space with anyone else’s.

  • Servers in Europe

    Physical servers spread across several data centers in France. The distribution is deliberate: an incident at one center shouldn’t be able to take down the whole service.

  • One environment per client

    Each client runs in its own isolated containerized environment, with its own configuration. It’s not a shared database with a column separating one client from another.

  • Databases separate from the code

    Databases live on servers independent from the application and from the files. This improves performance and keeps a restore a well-bounded operation.

  • Files in replicated storage

    Images, documentation and work-order attachments are kept in object storage in Paris, replicated in Madrid. Both locations are within the European Union.

What happens if something fails

Database backups run daily and are stored in two separate locations: our own local storage and a private cloud repository, with a thirty-day retention. That covers both the disaster scenario —losing a server— and the far more common one: someone deleted or changed something they shouldn’t have and you need to go back to the snapshot from the day before yesterday. There’s also a written disaster-recovery procedure, with ordered steps to bring the service back up on new infrastructure: provision a server, point the domain, restore the proxy, bring up the containers from the image registry, reconnect file storage and restore the database. Being written down is what separates a plan from an intention.

Access and traceability

Who can get in, what they can do, and what gets logged.

  • Permissions by role

    Each role —manager, technician, client, subcontractor— reaches only what it’s meant to, and that limit is enforced on the server, not just in what appears on screen.

  • Action log

    Who accessed, what they did, when and from what address. Including failed access attempts, usually the first thing an audit asks for.

  • Encrypted communications

    All traffic goes over HTTPS with automatic redirection, and passwords are stored hashed, never in plain text.

  • Configurable password policy

    Your administrator decides the requirements: expiry, complexity and whether reuse is allowed. You control access security, not us.

  • Non-guessable files

    Documents and images are stored under a hash-generated name, so they can’t be reached by guessing URLs.

  • Separate environments

    Development, staging and production are isolated, and every change goes through code review before reaching production.

ISO 27001: where we stand and where we are heading

GMAO CLOUD is not ISO 27001 certified yet, but we’re working on it: we’ve started the conversations and committed to obtaining the certification before 31 December 2027. We say so before you ask, and with what is already done: a full assessment against the standard, point by point, with the results documented: we meet the most relevant mandatory requirements —access management, traceability, encrypted communications, upload validation, environment separation, code review— and we’ve identified and planned what’s missing, mainly two-factor authentication and a centralized security-alerting system. Until the certification arrives we’d rather show you the assessment than hang a badge on ourselves: if your procurement department needs the detail for a tender, we’ll send it over.

Shall we look at it with your way of working?

Leave your details and we will get in touch to see whether we fit. No commitment, no lock-in period.

We reply within one working day.

Data protection

What you need to be able to answer when someone asks you.

  • Export and deletion

    A person’s information can be exported and deleted, which is what makes the rights of access and erasure actually exercisable.

  • Data minimization

    We collect what’s needed to manage maintenance and no more. Fields that aren’t needed aren’t requested.

  • Data within the European Union

    Both the application servers and the file storage and its replica are located within European Union territory.

  • Scoped subcontractor access

    External providers who access the system do so through their own portal, limited to the jobs assigned to them.

What’s not there yet

Two-factor authentication is only partially built and can’t be activated yet. There’s no centralized system to detect anomalous access, so monitoring relies on log review. Session timeout on inactivity works on the web but not yet on the mobile apps. And periodic security testing is planned, not implemented. We publish this because a vendor that only shows the column of things it got right forces the client to discover the rest on their own, usually at the worst possible moment.

Frequently asked questions

Can I require two-factor verification for my whole team?

You set the access policy within the options the system offers. It’s worth deciding it explicitly rather than leaving it to each person’s judgment, because the security of a carelessly shared account is only as strong as its weakest link, not the average.

What happens to my data if I stop being a client?

It’s yours, and you take it with you. It’s a question worth asking any vendor before signing, not after: several years of maintenance history is an asset with value of its own, and a system you can’t leave with your data in hand is a risk, no matter how well it works while it lasts.

Where is my data hosted?

On physical servers in European Union data centers, in France, with file storage in Paris and its replica in Madrid. None of it leaves EU territory.

Do I share an installation with other clients?

No. Each client has its own isolated containerized environment, with its own configuration, and databases live on servers separate from the application.

How often are backups taken and how long are they kept?

They run daily and are kept in two separate locations, with a thirty-day retention. They let you both recover the service and undo a specific change that shouldn’t have been made.

Do you have ISO 27001 certification?

Not yet, but we’re working on it: we’ve started the conversations and committed to obtaining it before 31 December 2027. We already have the full assessment against the standard and we meet the most relevant mandatory requirements. If you need the assessment detail for a tender, we’ll provide it.

Is there two-factor authentication?

Not yet. It’s partially built and will be enabled per user or per company. In the meantime, the password policy —expiry, complexity and reuse— is configured by each installation’s administrator.

Missing something for your questionnaire?

If your procurement or IT department needs the technical detail, write to us and we’ll send it over.