GalyctMSP

Trust center

Trust is documented. It is not a badge.

The trust center gathers what can be published without exposing sensitive mechanisms: location, security, continuity, subprocessors, incidents, maintenance, reversibility and policies.

99.9%platform availability target
1 hmaximum data loss in a disaster (RPO)
4 hmaximum time to restore service (RTO)
30 dminimum backup immutability

Sovereignty

  • hosted in France; processed in France or the European Union;
  • critical technical subprocessors based in France or the Union;
  • legally European providers preferred, to limit extraterritorial exposure;
  • the AI engine processes data in France or the European Union.

Sovereignty is used as defined in the framework published by Galyct (in French).

Identity and access

  • MFA mandatory for every MSP and client account, no exceptions;
  • passkeys (WebAuthn);
  • OIDC single sign-on for client organizations on the Performance or Sovereignty plan (Microsoft Entra ID, Google Workspace or any OpenID Connect provider), with the Galyct second factor always required;
  • stricter policies at the partner's choice: IP addresses, session length, trusted devices, re-authentication for sensitive actions.

Continuity

Backups that get restored, and proven.

  • encrypted backups replicated to a geographically separate site, in France or the Union;
  • at least 30 days of immutability;
  • quarterly restore tests, with time-stamped proof and an alert on failure;
  • a summary of the tests published here, without sensitive technical detail.

Last restore test

Published after each quarterly test.

Date and result of the latest test, updated by the platform.

Status and incidents

What happens on the platform, said in time.

Service status

Real-time or near real-time availability, ongoing incidents, planned maintenance and recent history. Planned maintenance is announced at least 7 days ahead, except for urgent security fixes.

See status

Security incidents

Notification as soon as a potential impact on data or service is identified. A post-incident report is mandatory for any major or critical incident: cause, timeline, impact, measures, prevention. A non-sensitive summary is published.

SeverityUpdate frequency
Criticalevery 30 minutes
Majorevery 2 hours
Significantat least daily, until closure

Subprocessors

The list is public, and it does not change without notice.

Galyct publishes the list of its critical subprocessors, with their role and location.

  • 30 days' notice before any change of critical subprocessor, except for security emergencies;
  • partners and clients may raise a reasoned objection during that period;
  • if the objection is well founded, Galyct looks for an alternative;
  • if no reasonable alternative exists, the service can end without penalty, with a full data export.

See the subprocessor register (in French)

Independent audits

Regular independent security audits, at most every 24 to 36 months, and earlier after a major change, a significant incident or a critical architecture change. A non-sensitive summary is published.

Mandates

Your provider's access is scoped, dated and revocable.

Mandatory mandate

  • one Galyct template, mandatory clauses cannot change;
  • annexes uploaded, versioned, reviewable by Galyct;
  • expiry, reminders, renewal on the client's explicit approval.

Immediate revocation

  • from the client portal, with re-authentication and MFA;
  • the provider's actions are blocked immediately;
  • an automatic closure report goes to the client and to Galyct.

Change of provider

  • new mandate and explicit client confirmation;
  • scheduled switchover, at least 48 hours' technical notice, no overlap;
  • the client can cancel up to 24 hours before; notifications 2 days before, 1 day before and at switchover;
  • a transfer report goes to the client, the new provider and Galyct, never to the previous one.

Reversibility

Leaving should be as easy as arriving.

  • an exit package at any time: readable PDFs, reusable CSV and JSON, original files;
  • scope: mandates, reports, history, evidence, documents, actions, incidents, assessments, useful configuration;
  • API export for the client and the mandated provider, every call logged;
  • sensitive or large exports: re-authentication and MFA;
  • 30 days to recover data after service ends, then deletion and a downloadable deletion certificate.
CategoryTarget retention
Detailed technical logs12 months
Evidential history of provider actionsmandate term + 5 years
Ongoing dispute or proceedingsuntil closure, for the necessary data only

Documents

Versioned documents, explicitly accepted.

Every structuring document is versioned. A substantial change requires a new explicit acceptance, within the relevant scope.

The data processing agreement (DPA) is available on request before signing, then signed in the partner area.

  • partner agreement and program charter;
  • brand and badge usage rules;
  • Academy and certification terms;
  • support policy, SLAs and calculation rules;
  • mandate between provider and client;
  • DPA and GDPR framework;
  • mediation, sanction and appeal rules;
  • subprocessing, reversibility and deletion policy;
  • NARA policy: authorised and forbidden actions.

A security question before you commit?

Support and the partner team answer your security questionnaires during the sandbox.