jimble.dev

Security Policy

The security of our customers' data is a top priority. This page describes the technical and organisational measures implemented to protect your data against any unauthorised access, loss or alteration.

1. Data encryption

1.1. In transit

All communications between your browser/API and our servers are encrypted via TLS 1.2+ (HTTPS). Certificates are renewed automatically.

1.2. At rest

Stored data (database, S3 files) is encrypted at rest with AES-256.

2. Access control

2.1. Authentication

2.2. Internal access management

3. Infrastructure and hosting

Our infrastructure is hosted by Scaleway (France) and OVH (France). The servers are:

4. Backups

5. Monitoring and detection

6. Vulnerability management

7. Business continuity

In the event of a major incident, our business continuity plan (BCP) provides for:

8. Compliance and certifications

We comply with the OWASP Top 10 and GDPR standards.

9. Vulnerability reporting

If you discover a security vulnerability, please report it to us responsibly at:
Email: contact@jimble.dev
We undertake to respond within 48 hours and to handle the issue with the highest priority.

10. Training and awareness

Our entire team attends annual training on security best practices (password management, phishing, data protection, etc.).

Last updated: 7 July 2026