Security and compliance
Missivia is designed for regulated environments. This page lists verifiable facts about how the platform handles data; it is written for data protection officers and information security officers. It describes what is in place, not what is planned.
Hosting and sub-processing
- Hosted in France: Scaleway SAS, Paris region (fr-par).
- No third-party e-mail service provider: the integrated MTA delivers messages directly to the recipients’ mail servers, from the platform’s own IP addresses.
- No third-party analytics or telemetry, on this website, in the platform or in the console.
- DNS only: no CDN or intermediary proxy in front of the API; traffic reaches the infrastructure hosted in France directly.
- A single sub-processor: the hosting provider.
- Outbound calls without personal data only: recipients’ mail servers (e-mail delivery), certificate authority (issuance and renewal of TLS certificates), Microsoft SNDS and Google Postmaster Tools (reputation data about our own IP addresses and domains).
Data protection
- Encryption in transit: TLS with HSTS for the API, the console and this website; STARTTLS for SMTP exchanges.
- Encryption at rest of signing keys (DKIM) and secrets (webhooks) with AES-256-GCM; API keys stored hashed; console passwords hashed with Argon2id.
- Encrypted backups (
age), decryption key kept off the instance; restore tests performed and recorded. - Retention periods enforced by automatic purge: events and audit log kept 13 months by default, adjustable per tenant.
- Erasure and portability through the API: physical deletion of the contact, anonymisation of events, export of all of a contact’s data in one call.
- Tenant isolation enforced on every query: the tenant is derived from the API key, never passed as a parameter; a resource belonging to another tenant is not found.
Consent and data-subject rights
- Consent per purpose, with proof: who, when, wording shown, source of collection. A refusal is kept as proof.
- Two separate pixels: a deliverability pixel (exempt, writes only the last-open date, to the day) and a performance pixel, inserted only if a valid tracking consent exists at render time.
- Unsubscribe link in every marketing e-mail, one-click unsubscribe (RFC 8058) and
List-Unsubscribe/List-Unsubscribe-Postheaders. - Transactional e-mails kept separate from marketing e-mails: distinct legal basis, no performance measurement.
Traceability and operational security
- Audit log of every write and of every read of personal data: who, with which key, when, request identifier.
- Security event logging (rejected authentications, revoked keys, threshold breaches).
- Brute-force protection on API keys: authentication failures rate-limited per IP address.
- TOTP two-factor authentication mandatory for platform operators.
- Least-privilege API keys: scopes and restriction by IP address or CIDR range.
- Monitoring of software dependencies and published vulnerabilities.
- Written security incident procedure: qualification, containment, notification to the CNIL within 72 hours, information of the tenants concerned.
- Responsible disclosure of a vulnerability: security@dataventure.com.
Health data hosting (HDS)
HDS certification applies to a legal entity that hosts health data on behalf of a third party, for one or more of the six activities of the French HDS framework — not to a piece of software. Missivia is not itself HDS-certified. Three levels must be distinguished; they form a trajectory, not an achievement.
| Level | Who | Status |
|---|---|---|
| Infrastructure (activities 1 to 4) | Scaleway SAS | Deployable on HDS-certified infrastructure (Scaleway, activities 1 to 4), on request and under contract. Outside such a contract, hosting is “Scaleway Paris”, not “HDS”. |
| Operations (activity 5) | Dataventure Group | System administration falls to Missivia’s operator; the corresponding certification is contracted case by case, depending on the scope entrusted. |
| Technical measures of the platform | Code, deployment, instance | Measures listed on this page, audited on 2026-09-11. Necessary, not sufficient. |
Missivia can also be deployed, on request and under contract, on Scalingo, a French PaaS certified HDS for all six activities of the framework (LNE certificate no. 38436, valid until 11 September 2028), which then covers the infrastructure, the application hosting platform and outsourced backups.
Consequently, no health data should be entrusted to the platform without a specific prior contract defining the scope, the deployment environment and the responsibilities of each party.
Last update: 2026-09-11 · Questions and reports: security@dataventure.com