Trust Center

Security & privacy — Olyteck Cyber

How we protect your Microsoft 365 data, where it lives, who can touch it, and the documents you need for procurement. Filter by product below. Updated continuously.

All products Cyber Ask Studio Guard
EU
Hosting region
France · European Union (Scaleway PAR1)
🔒
Encryption
TLS 1.2+ · AES-256 at rest
M
Authentication
Microsoft Entra ID · MFA inherited
📄
Data minimisation
Counts findings, never files

Our security posture in one paragraph

Olyteck Cyber authenticates users through your own Microsoft Entra ID tenant, reads configuration and permission metadata through Microsoft Graph, and stores only aggregate findings — the detailed evidence stays in your administrator's browser. It does not read message bodies, file contents or attachments.

Product site: https://cyber.olyteck.com

Sales & security questionnaires
Need a vendor security questionnaire filled in, or a custom NDA-protected document pack? E-mail [email protected] — typical turnaround is one to two business days.

Documents

Showing documents for Olyteck Cyber. Items marked NDA or ON REQUEST are released to qualified prospects and customers via e-mail.

Public

Available under NDA

Certifications & assurance

Where we are today and what we are working toward.

CSA STAR Level 1 — listed GDPR — compliant EU-only data residency Hosting provider: ISO 27001 + SOC 2 audited OWASP ZAP DAST — production scan clean (June 2026) External penetration test — annual SOC 2 Type II — on roadmap ISO 27001 — on roadmap
Frameworks our controls align to
ISO/IEC 27001 & 27002 · SOC 2 Trust Services Criteria · OWASP ASVS · CIS Critical Security Controls · GDPR · CSA Cloud Controls Matrix v4. Mapping documents available under NDA.

Sub-processors

Carefully selected, contractually bound — those that apply to Olyteck Cyber. Last reviewed 2026-06-19.

Sub-processorServiceRegion
Microsoft CorporationEntra ID authentication + Microsoft Graph (customer-controlled tenant)Customer-controlled
Scaleway (EU cloud hosting)Infrastructure-as-a-service hosting of application, database, backupsEuropean Union (France, PAR1)
Microsoft 365 (Exchange Online)Transactional & notification e-mail deliveryEuropean Union
Cloudflare, Inc.DNS & edge protection for the public marketing surfaceGlobal (with EU PoPs)
Stripe Payments Europe, Ltd.Card payment processing & subscription billingEuropean Union / Ireland

This page is the authoritative, current list of our sub-processors. We post any addition or replacement here at least 30 days before it takes effect, so customers can review and object as set out in our DPA. To be added to our change-notification list, e-mail us.

Status & incident response

Live system status is published at status.olyteck.com. Customers are notified of personal-data incidents without undue delay and within 72 hours, in line with GDPR Article 33.

Report a security issue

Customers and third parties can report a suspected security issue to [email protected]. We acknowledge receipt within one business day and engage a responder.

Talk to us

Need a vendor security questionnaire filled in?

We pre-write most answers. Send us your template and we usually return it inside two business days.

[email protected]

Sign an NDA & get the full pack

Detailed S-SDLC, pentest summary, BCP exercise report, full architecture diagrams.

Request the pack