AppH
News AI Pre-qualification
See all services AI agents Automation Web applications System repair E-commerce
Process AppManager
See all sectors Business domiciliation Transport Optics Tourism Agricultural production management 360° architecture & engineering
Trust & security Client portal AI reception assistant Sign up your company
Partner Program Investors Contact
ES EN FR PT
Log in Talk to us
ES EN FR PT
TRUST & SECURITY

Trust, security and your data

Last updated: September 10, 2026

This page describes, without marketing filler, the technical and organizational measures that are actually active today in AppManager and in how we operate — not a wishlist. If something isn't implemented yet, it doesn't appear here.

1. Encryption and security headers

All traffic to apph.app is encrypted over HTTPS, with HSTS enabled to always force the secure connection. The site sends headers that block common attack vectors: clickjacking protection, content-type sniffing prevention, a restrictive referrer policy, and a permissions policy that denies camera, microphone and geolocation access by default.

2. Passwords and access control

No password is ever stored in plain text: they're derived with scrypt and a random salt unique to each account, and compared with a constant-time algorithm to avoid leaking information through timing. Access to AppManager is by invitation, with distinct roles (admin / team member), and an account can be suspended instantly if needed.

3. Everything is logged

Relevant platform actions — documents issued, data changes, sends — are written to an internal audit log. This isn't a promise: it's the same table we use ourselves to verify every change before calling it done, and it feeds the real metrics on the admin dashboard.

4. Rate limits on public endpoints

Publicly exposed self-service forms and widgets (bookings, contact, request tracking) are rate-limited per IP to slow down automated abuse, on top of validating and whitelisting the fields they accept before touching any real data.

5. AI never acts alone toward the outside

When an AI agent prepares an action that leaves your organization toward a third party — for example, reaching out to a new company in the prospecting module — the agent builds the profile, the qualification and the proposal, but no real send ever goes out without a person reviewing and approving it individually. This isn't a "trial period until we earn trust": it's the standing policy, and changing it would require an explicit decision from you, not a silent automation.

6. Where the data we use comes from

To discover and pre-qualify companies for B2B prospecting in France we use the official French government public API (recherche-entreprises.api.gouv.fr / data.gouv.fr). In every other market we operate in, we apply the same standard using that country’s equivalent official public source (business registry, open-data portal, or regulator). We never scrape private directories without a legal basis to justify it, in any market.

7. GDPR in practice, not just on paper

  • Every processing activity has a specific legal basis, never a generic one: consent for the newsletter and performance cookies; legitimate interest or pre-contractual measures for the contact form and the pre-qualification chat.
  • Visit analytics data is automatically purged after 13 months — the ceiling set by the CNIL for France, and the equivalent limit under applicable local law in every other market; never an arbitrary period.
  • Commercial communications include a real opt-out path, applied in the flow itself, not just mentioned in a legal text.

8. Your data stays yours

Unless otherwise agreed in writing, you retain ownership of your data, your content and the final product we deliver. We retain ownership of the tools, reusable components and know-how used to build it — not of your information. More detail in our terms of service and our privacy and cookie policy.

9. Hosting and sub-processors

Primary hosting (application, database, files) is located in France, on OVHcloud servers — no data is replicated outside the European Union for this part. Generative AI features — the pre-qualification and front-desk assistant, as well as assisted drafting of reminders, follow-ups and automations in AppManager — use Anthropic's models (Claude), in the United States, and may transmit the data strictly needed for the task (for example a client name, an amount, a date). For every invoiced client, these features run on Anthropic's commercial offering (API, with a data processing agreement and no training on their data), activated from invoicing onwards. The full sub-processor list and the status of the applicable safeguards are provided on request.

10. GDPR sub-processing (article 28) — downloadable annex

For any client whose data AppManager processes on their behalf (domiciliation, CRM, invoicing…), AppH acts as a processor under article 28 GDPR. The downloadable summary covers the mandatory content of a sub-processing annex: purpose and duration of processing, nature and purpose, categories of data and data subjects, processor obligations (confidentiality, security, use of sub-processors with prior authorization, assistance to the controller, breach notification, deletion or return of data at contract end). Download the summary (PDF, French — the contract language). This document is informational: the signed annex is part of each client contract and will be issued by the billing entity once it is registered.

11. What the AI assistant does not do: identity and AML/CFT

The pre-qualification and reception assistant informs, guides and prepares files — it performs no automated identity verification and issues no compliance opinion under anti-money-laundering and counter-terrorist-financing rules (AML/CFT, known in France as LCB-FT). For a domiciliation agent operating under prefectural approval, those checks remain, as today, the responsibility of your team and your authorized internal procedures; the assistant makes no decision in their place.

12. Processing register — public summary

Overview of the main categories of personal-data processing carried out by AppH. The full register (art. 30 GDPR), in more detail, is kept internally.

  • Prospects and site visitors (contact form, pre-qualification chat) — purpose: respond and qualify the need. Legal basis: pre-contractual measures / legitimate interest. Retention: 3 years without contact.
  • AppManager user accounts (your team) — purpose: provide and secure access to the service. Legal basis: performance of the contract. Retention: duration of the contract + legal obligations.
  • Business data entered by our clients (e.g. domiciliation files, invoices, KYC pieces) — purpose set by the client, who is the controller for this data; AppH acts as processor. Retention: set by the client / applicable legal periods (e.g. 5 years for domiciliation pieces, French Commercial Code).
  • Site visit analytics — purpose: measure audience and improve the site. Legal basis: consent / legitimate interest. Retention: 13 months (CNIL ceiling, see section 7).

13. Continuity, reversibility and documentation for your due diligence

  • Two-factor authentication (TOTP): available on every AppManager account and enforceable per role (for example, mandatory for administrators).
  • Backups: daily and encrypted (database, application and configuration), currently kept on the main server; the external replica (off the server) is being activated. Target maximum data loss (RPO): 24 hours.
  • Reversibility: at the end of the contract, full export of your data in a standard format; the intellectual-property split (work built specifically for you versus AppH's reusable components) is set out in a contract annex.

Available today, on request: completed security questionnaire, full sub-processor list, architecture and stack description, and a scoped pilot (PoC) on synthetic data or a mock API, with no access to your sensitive intellectual property.

Once the company is registered (Kbis): contract and DPA (art. 28) signed by the invoicing entity, mutual non-disclosure agreement, professional liability insurance certificate and registration details (SIREN, EU VAT number). We will let you know as soon as they are available.

This page describes the platform's actual state as of the date above, not an independent third-party certification (such as SOC 2 or ISO 27001) — we don't hold one today. If your organization needs a formal security questionnaire or a data processing agreement (DPA) to move forward, write to us at [email protected] and we'll handle it case by case.
© 2026 AppH Privacy & cookies