This English version is provided for information purposes. In the event of any discrepancy, the French version prevails.
This document constitutes Annex 1 — Technical and organisational measures referred to in Article 16.6 of the general terms and conditions of sale.
Transition to the Ovastack platform
In 2025, the Cloudbizz platform migrated to Ovastack, a hyperconverged cloud infrastructure hosted and operated by the NET COMPUTER GROUP SA teams in Belgium. This document describes the security, hosting, backup and authentication measures in force on this platform. Primary authentication is provided by Cloudbizz OneKey, which replaces Okta, used by the previous platform.
A1. Where is the data located?
The data is physically hosted in two separate data centres in Belgium (Digital Realty BRU1 and BRU3, in Zaventem), which ensures geographical redundancy. These facilities meet high security and compliance standards, including ISO 27001 certification.
A2. How is the security of the premises ensured?
The premises benefit from security and resilience measures, including:
- redundancy of critical infrastructure;
- a continuous and secure power supply;
- air conditioning and environmental control;
- fire detection and protection systems;
- leak detection and technical monitoring.
A3. How is the security of the server rooms ensured?
Access to the server rooms is controlled and monitored 24 hours a day, 7 days a week, by on-site security staff. Once access rights have been verified and validated, access is granted through secure control mechanisms (badge and additional devices depending on the requirements of the site). Sensitive areas are covered by video surveillance.
A4. How are user identification and authentication ensured?
The platform uses Cloudbizz OneKey as its primary authentication solution. The measures in place include:
- multi-factor authentication (MFA), with support for modern methods (authenticator app, biometrics);
- protection against brute-force attacks, through throttling or lockout after repeated attempts;
- sign-in policies and risk signals: contextual checks and anomaly detection;
- full traceability of sign-in events for audit purposes.
A5. How is access to user data secured?
Each client company benefits from strict logical isolation of its data and resources.
Principles applied
- Separation of environments per client.
- Access restricted to authorised administrators.
- Logging and traceability of actions.
Enhanced protection
- EDR solution protecting endpoints and servers.
- DNS filtering for web browsing.
- Blocking of malicious domains.
A6. Data backups
The continuity strategy includes several levels of redundancy:
- Continuously: frequent snapshots, copied to a dedicated backup infrastructure.
- Daily: backup of complete environments (virtual machines and workloads), with replication to a second site.
The infrastructure is redundant at several levels (connectivity, network, compute, storage) in order to limit the impact of a failure. The detailed arrangements are set out in the backup policy.
A7. Platform protection software and mechanisms
The platform relies on a combination of built-in security controls and complementary tools:
- EDR / endpoint protection
- Active protection of servers.
- DNS filtering
- Secure Internet browsing.
- Anti-spam
- Advanced email security.
- Encryption
- TLS for all communications.
- Firewalls and access control lists
- Strict network segmentation.
- Monitoring
- Log collection and 24/7 alerting.
A8. Service guarantees (SLA) and insurance
NET COMPUTER GROUP SA commits to high service levels: network availability ≥ 99.5% and power supply availability ≥ 99.98%. Several SLA levels are offered, from the SLA Standard (reasonable efforts) to the SLA DRS (Disaster Recovery System), which guarantees a recovery time of 4 hours for critical incidents. See the Service Level Agreement.
In addition to its third-party liability insurance, NET COMPUTER GROUP SA has specific insurance covering cyber risks.
A9. Ovastack platform
The Ovastack platform brings major improvements in security, resilience and performance.
Architecture
- Enhanced isolation and partitioning of environments.
- Hyperconverged architecture with centralised management.
- Network segmentation and fine-grained flow control.
Proactive security
- Intrusion monitoring and detection.
- Configuration hardening.
- Automated update management.
- Built-in disaster recovery.
A10. Modern authentication with Cloudbizz OneKey
Cloudbizz OneKey offers simpler, faster and more secure authentication, aligned with current industry standards:
- Modern MFA (app, biometrics).
- Passwordless option (passkeys).
- Phishing protection.
- Contextual access policies.