Security Policy
The security of our customers' data is a top priority. This page describes the technical and organisational measures implemented to protect your data against any unauthorised access, loss or alteration.
1. Data encryption
1.1. In transit
All communications between your browser/API and our servers are encrypted via TLS 1.2+ (HTTPS). Certificates are renewed automatically.
1.2. At rest
Stored data (database, S3 files) is encrypted at rest with AES-256.
2. Access control
2.1. Authentication
- User authentication by password (hashed with bcrypt) or OAuth 2.0 (Google, etc.)
2.2. Internal access management
- Principle of least privilege: access limited to what is strictly necessary
- Mandatory multi-factor authentication for administrators
- Logging of all administrator access
- Immediate revocation of access when a team member leaves
3. Infrastructure and hosting
Our infrastructure is hosted by Scaleway (France) and OVH (France). The servers are:
- Located in ISO 27001, SOC 2 certified data centres
- Isolated via virtual private clouds (VPC)
- Protected by firewalls and security groups configured with whitelisting
- Subject to automatic security updates
4. Backups
- Automatic daily database backups
- Backups encrypted and stored in a separate geographic location
- Backups retained for 7 days
- Regular restoration tests
5. Monitoring and detection
- 24/7 system monitoring
- Anomaly detection (suspicious login attempts, traffic spikes, etc.)
- Automatic alerts in the event of a security incident
- Centralised logging of application and system logs
6. Vulnerability management
- Weekly automated vulnerability scans
- Critical security updates applied within 48 hours
- Quarterly review of software dependencies
7. Business continuity
In the event of a major incident, our business continuity plan (BCP) provides for:
- Restoration of the service within 24 hours
- Maximum data loss (RPO) of 3 hours
- Proactive communication to customers via Discord and email
8. Compliance and certifications
We comply with the OWASP Top 10 and GDPR standards.
9. Vulnerability reporting
If you discover a security vulnerability, please report it to us responsibly at:
Email: contact@jimble.dev
We undertake to respond within 48 hours and to handle the issue with the highest priority.
10. Training and awareness
Our entire team attends annual training on security best practices (password management, phishing, data protection, etc.).
Last updated: 7 July 2026