Contents
- Article 1 - Data protection
- Article 2 - Access and authentication
- Article 3 - Authorisations and internal access
- Article 4 - Bank access
- Article 5 - Hosting security
- Article 6 - Application security
- Article 7 - Logging and detection
- Article 8 - Incident and breach management
- Article 9 - Continuity and backups
- Article 10 - Subprocessor security
- Article 11 - The User's role
- Article 12 - Reporting vulnerabilities
- Article 13 - Payment security
- Article 14 - Communications security and anti-phishing
- Article 15 - Security and artificial intelligence
- Article 16 - Physical security of infrastructure
- Article 17 - Awareness and confidentiality
- Article 18 - Environment partitioning
- Article 19 - Assessment and continuous improvement
- Article 20 - Limits
Protecting Users' financial data is a priority for Evorax Technologies. This policy describes, in detail, the technical and organisational measures implemented to ensure the security, integrity, confidentiality and availability of the Noryo service (hereinafter the "Service") and of the data processed within it. It supplements the Privacy Policy.
Article 1 - Data protection
1.1 Encryption in transit
Exchanges between the applications, the servers and the providers are encrypted using secure transport protocols (TLS), in order to prevent any interception or alteration.
1.2 Encryption at rest
Documents uploaded by the User are stored encrypted at rest with the storage provider.
1.3 Data partitioning
Strict access rules, applied at the database level, ensure that each User can access only their own data.
1.4 Minimisation
The Service is designed so as to limit the data processed to what is necessary, and to favour, where possible, processing on the User's device.
Article 2 - Access and authentication
2.1 Sign-in
Sign-in is carried out by username and password, or through third-party identity providers, at the User's choice.
2.2 Two-factor authentication
Two-factor authentication is available and recommended in order to strengthen the protection of the account.
2.3 Biometric lock
On the mobile applications, a biometric lock may be enabled by the User, adding protection at the device level.
2.4 Session management
Sessions are managed by means of secure tokens and may be revoked, in particular upon sign-out.
Article 3 - Authorisations and internal access
Access to data by authorised persons is limited to what is strictly necessary, according to the principle of least privilege, and is subject to confidentiality undertakings.
Article 4 - Bank access
Access to accounts is carried out on a read-only basis, through an authorised provider; banking credentials are never retained by the Publisher (see the Account Access Terms (Open Banking)).
Article 5 - Hosting security
The Service relies on hosting providers selected on the basis of the guarantees they offer, whose main database infrastructure is located within the European Union and whose document storage is located in France. The list is set out in the Register of Subprocessors.
Article 6 - Application security
6.1 Development
The Service is developed in accordance with practices aimed at preventing common vulnerabilities and at incorporating security from the design stage.
6.2 Dependencies
The third-party components used are monitored in order to apply the relevant security patches.
Article 7 - Logging and detection
Security and audit logs are kept in order to detect and prevent abuse and unauthorised access, in compliance with the retention periods indicated in the Privacy Policy.
Article 8 - Incident and breach management
8.1 Procedure
The Publisher implements incident management procedures enabling security events to be detected, analysed and remedied.
8.2 Notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, the Publisher carries out the notifications required by the regulations, in particular to the supervisory authority within the legal time limits and, where applicable, to the affected individuals.
Article 9 - Continuity and backups
Secure backups are carried out in order to ensure the resilience of the data and the continuity of the Service. They are kept for a limited and rolling period, under the conditions described in the Storage Policy.
Article 10 - Subprocessor security
The subprocessors engaged by the Publisher are bound by contractual undertakings imposing appropriate guarantees as to security and confidentiality, in accordance with Article 28 of the General Data Protection Regulation.
Article 11 - The User's role
Security is shared. The User is invited to choose a strong and unique password, to enable two-factor authentication, to protect access to their devices and to keep them up to date. Evorax Technologies never asks for a User's password; any such request must be regarded as fraudulent. Any suspicious access must be reported without delay to legal@noryo.app.
Article 12 - Reporting vulnerabilities
Any suspected vulnerability must be reported in accordance with the Responsible Disclosure Policy.
Article 13 - Payment security
Payments made on the website are processed by a specialised payment provider, subject to the security standards applicable to the card payment sector. The Publisher does not store any full bank card number or any associated security data. Transactions may be subject to strong customer authentication (SCA).
Article 14 - Communications security and anti-phishing
The Publisher communicates with the User through controlled channels, principally from the noryo.fr domain. It never asks for the User's password, nor for the disclosure of banking credentials, nor for card data by email or by telephone. Any such request must be regarded as a phishing attempt and reported without delay to legal@noryo.app.
Article 15 - Security and artificial intelligence
Processing operations involving artificial intelligence favour, where possible, execution on the User's device and the transmission of only the information necessary for the response. The associated guarantees are described in the AI Transparency Policy.
Article 16 - Physical security of infrastructure
The Service relies on hosting providers whose data centres implement physical security measures, such as access control, surveillance and redundancy. The Publisher does not directly manage these infrastructures, but selects its providers on the basis of such guarantees.
Article 17 - Awareness and confidentiality
Persons authorised to access data are bound by an obligation of confidentiality and are made aware of security and data protection requirements.
Article 18 - Environment partitioning
The development, test and production environments are kept separate. Access to production data is restricted to authorised persons and logged.
Article 19 - Assessment and continuous improvement
The Publisher carries out security reviews, takes account of reports received under the Responsible Disclosure Policy and updates its measures in order to maintain a level of protection appropriate to the state of the art and to the risks.
Article 20 - Limits
No security mechanism can guarantee absolute protection. The Publisher implements measures proportionate to the state of the art and to the risks, and updates them regularly.