Servers in Europe
Physical servers spread across several data centers in France. The distribution is deliberate: an incident at one center shouldn’t be able to take down the whole service.
Trust
These are the two questions any serious client ends up asking, usually in the form of a thirty-page questionnaire. Here are the answers, without having to request them.
Where your installation lives and why it doesn’t share space with anyone else’s.
Physical servers spread across several data centers in France. The distribution is deliberate: an incident at one center shouldn’t be able to take down the whole service.
Each client runs in its own isolated containerized environment, with its own configuration. It’s not a shared database with a column separating one client from another.
Databases live on servers independent from the application and from the files. This improves performance and keeps a restore a well-bounded operation.
Images, documentation and work-order attachments are kept in object storage in Paris, replicated in Madrid. Both locations are within the European Union.
Database backups run daily and are stored in two separate locations: our own local storage and a private cloud repository, with a thirty-day retention. That covers both the disaster scenario —losing a server— and the far more common one: someone deleted or changed something they shouldn’t have and you need to go back to the snapshot from the day before yesterday. There’s also a written disaster-recovery procedure, with ordered steps to bring the service back up on new infrastructure: provision a server, point the domain, restore the proxy, bring up the containers from the image registry, reconnect file storage and restore the database. Being written down is what separates a plan from an intention.
Who can get in, what they can do, and what gets logged.
Each role —manager, technician, client, subcontractor— reaches only what it’s meant to, and that limit is enforced on the server, not just in what appears on screen.
Who accessed, what they did, when and from what address. Including failed access attempts, usually the first thing an audit asks for.
All traffic goes over HTTPS with automatic redirection, and passwords are stored hashed, never in plain text.
Your administrator decides the requirements: expiry, complexity and whether reuse is allowed. You control access security, not us.
Documents and images are stored under a hash-generated name, so they can’t be reached by guessing URLs.
Development, staging and production are isolated, and every change goes through code review before reaching production.
GMAO CLOUD is not ISO 27001 certified yet, but we’re working on it: we’ve started the conversations and committed to obtaining the certification before 31 December 2027. We say so before you ask, and with what is already done: a full assessment against the standard, point by point, with the results documented: we meet the most relevant mandatory requirements —access management, traceability, encrypted communications, upload validation, environment separation, code review— and we’ve identified and planned what’s missing, mainly two-factor authentication and a centralized security-alerting system. Until the certification arrives we’d rather show you the assessment than hang a badge on ourselves: if your procurement department needs the detail for a tender, we’ll send it over.
Leave your details and we will get in touch to see whether we fit. No commitment, no lock-in period.
What you need to be able to answer when someone asks you.
A person’s information can be exported and deleted, which is what makes the rights of access and erasure actually exercisable.
We collect what’s needed to manage maintenance and no more. Fields that aren’t needed aren’t requested.
Both the application servers and the file storage and its replica are located within European Union territory.
External providers who access the system do so through their own portal, limited to the jobs assigned to them.
Two-factor authentication is only partially built and can’t be activated yet. There’s no centralized system to detect anomalous access, so monitoring relies on log review. Session timeout on inactivity works on the web but not yet on the mobile apps. And periodic security testing is planned, not implemented. We publish this because a vendor that only shows the column of things it got right forces the client to discover the rest on their own, usually at the worst possible moment.
You set the access policy within the options the system offers. It’s worth deciding it explicitly rather than leaving it to each person’s judgment, because the security of a carelessly shared account is only as strong as its weakest link, not the average.
It’s yours, and you take it with you. It’s a question worth asking any vendor before signing, not after: several years of maintenance history is an asset with value of its own, and a system you can’t leave with your data in hand is a risk, no matter how well it works while it lasts.
On physical servers in European Union data centers, in France, with file storage in Paris and its replica in Madrid. None of it leaves EU territory.
No. Each client has its own isolated containerized environment, with its own configuration, and databases live on servers separate from the application.
They run daily and are kept in two separate locations, with a thirty-day retention. They let you both recover the service and undo a specific change that shouldn’t have been made.
Not yet, but we’re working on it: we’ve started the conversations and committed to obtaining it before 31 December 2027. We already have the full assessment against the standard and we meet the most relevant mandatory requirements. If you need the assessment detail for a tender, we’ll provide it.
Not yet. It’s partially built and will be enabled per user or per company. In the meantime, the password policy —expiry, complexity and reuse— is configured by each installation’s administrator.
If your procurement or IT department needs the technical detail, write to us and we’ll send it over.
Accessibility
Saved in this browser. Light or dark theme is set from the footer.