Last updated: September 10, 2026
This page describes, without marketing filler, the technical and organizational measures that are actually active today in AppManager and in how we operate — not a wishlist. If something isn't implemented yet, it doesn't appear here.
All traffic to apph.app is encrypted over HTTPS, with HSTS enabled to always force the secure connection. The site sends headers that block common attack vectors: clickjacking protection, content-type sniffing prevention, a restrictive referrer policy, and a permissions policy that denies camera, microphone and geolocation access by default.
No password is ever stored in plain text: they're derived with scrypt and a random salt unique to each account, and compared with a constant-time algorithm to avoid leaking information through timing. Access to AppManager is by invitation, with distinct roles (admin / team member), and an account can be suspended instantly if needed.
Relevant platform actions — documents issued, data changes, sends — are written to an internal audit log. This isn't a promise: it's the same table we use ourselves to verify every change before calling it done, and it feeds the real metrics on the admin dashboard.
Publicly exposed self-service forms and widgets (bookings, contact, request tracking) are rate-limited per IP to slow down automated abuse, on top of validating and whitelisting the fields they accept before touching any real data.
When an AI agent prepares an action that leaves your organization toward a third party — for example, reaching out to a new company in the prospecting module — the agent builds the profile, the qualification and the proposal, but no real send ever goes out without a person reviewing and approving it individually. This isn't a "trial period until we earn trust": it's the standing policy, and changing it would require an explicit decision from you, not a silent automation.
To discover and pre-qualify companies for B2B prospecting in France we use the official French government public API (recherche-entreprises.api.gouv.fr / data.gouv.fr). In every other market we operate in, we apply the same standard using that country’s equivalent official public source (business registry, open-data portal, or regulator). We never scrape private directories without a legal basis to justify it, in any market.
Unless otherwise agreed in writing, you retain ownership of your data, your content and the final product we deliver. We retain ownership of the tools, reusable components and know-how used to build it — not of your information. More detail in our terms of service and our privacy and cookie policy.
Primary hosting (application, database, files) is located in France, on OVHcloud servers — no data is replicated outside the European Union for this part. Generative AI features — the pre-qualification and front-desk assistant, as well as assisted drafting of reminders, follow-ups and automations in AppManager — use Anthropic's models (Claude), in the United States, and may transmit the data strictly needed for the task (for example a client name, an amount, a date). For every invoiced client, these features run on Anthropic's commercial offering (API, with a data processing agreement and no training on their data), activated from invoicing onwards. The full sub-processor list and the status of the applicable safeguards are provided on request.
For any client whose data AppManager processes on their behalf (domiciliation, CRM, invoicing…), AppH acts as a processor under article 28 GDPR. The downloadable summary covers the mandatory content of a sub-processing annex: purpose and duration of processing, nature and purpose, categories of data and data subjects, processor obligations (confidentiality, security, use of sub-processors with prior authorization, assistance to the controller, breach notification, deletion or return of data at contract end). Download the summary (PDF, French — the contract language). This document is informational: the signed annex is part of each client contract and will be issued by the billing entity once it is registered.
The pre-qualification and reception assistant informs, guides and prepares files — it performs no automated identity verification and issues no compliance opinion under anti-money-laundering and counter-terrorist-financing rules (AML/CFT, known in France as LCB-FT). For a domiciliation agent operating under prefectural approval, those checks remain, as today, the responsibility of your team and your authorized internal procedures; the assistant makes no decision in their place.
Overview of the main categories of personal-data processing carried out by AppH. The full register (art. 30 GDPR), in more detail, is kept internally.
Available today, on request: completed security questionnaire, full sub-processor list, architecture and stack description, and a scoped pilot (PoC) on synthetic data or a mock API, with no access to your sensitive intellectual property.
Once the company is registered (Kbis): contract and DPA (art. 28) signed by the invoicing entity, mutual non-disclosure agreement, professional liability insurance certificate and registration details (SIREN, EU VAT number). We will let you know as soon as they are available.