<aside> 🗣 Classification: PUBLIC This page is shared externally to Alan prospects, customers, and business partners. 🇫🇷 translation: La conformité à DORA chez Alan (FR)
⚖️ For more information on information security at Alan, head up to Alan Security Statement (EN)
</aside>
Alan's ISO 27001 certification provides a strong foundation for information security. For customers subject to DORA, we provide the following additional assurances on ICT third-party risk management (Articles 28-44).
| Question | Answer |
|---|---|
| Do your contracts include DORA-compliant clauses? | Yes. Our agreements with financial entities include: service descriptions and SLAs; security and incident notification requirements; audit and access rights; subprocessor notification and consent; data location specifications (EEA); exit and data portability procedures; cooperation with competent authorities; and termination rights for material non-compliance. |
| How do you address ICT concentration risk? | We operate on multi-region cloud infrastructure (AWS Frankfurt and Paris) with real-time data replication, standard export formats (JSON, CSV, APIs), no proprietary lock-in, and documented exit procedures. We regularly assess alternative providers for critical and important services. |
| Do you maintain a register of subprocessors? | Yes. We maintain a current list of critical and important ICT providers including services provided, data access scope, and geographic locations. |
| How do you manage subprocessor changes? | Material changes to critical and important functions are communicated to affected customers with advance notice where feasible. All critical subprocessors are contractually bound to equivalent security and resilience requirements. |
| Question | Answer |
|---|---|
| What are your incident notification timelines? | For material ICT incidents: |
| • Initial notification: Within 24 hours of classification | |
| • Intermediate update: Within 72 hours (impact, remediation status) | |
| • Final report: Within 30 days (root cause, corrective actions) | |
| Notifications include affected systems, impact on data CIA, estimated recovery time, and remediation steps. | |
| How do you classify and detect incidents? | We maintain 24/7 monitoring with automated alerting. Incidents are classified by severity based on impact to availability, integrity, and confidentiality. All incidents are logged with timeline, actions taken, and lessons learned. |
| Do you notify customers of security incidents? | Yes. We notify customers of any confirmed incident materially affecting their data, service delivery, or regulatory obligations (GDPR breaches, DORA-reportable events). |
| Question | Answer |
|---|---|
| What are your RTO and RPO commitments? | • RTO (Recovery Time Objective): To be defined per service. |
| • For Alan core services: 99,85%, with: Acknowledge within 1 business hour / Workaround within 2 business days / Resolution with 5 business days | |
| • RPO (Recovery Point Objective): 24 hours (daily backups with point-in-time recovery) | |
| How often do you test resilience? | • Disaster recovery tests: At least annually with documented results |
| • Vulnerability assessments: Regular automated and manual testing | |
| • Penetration testing: Independent third-party tests at least annually. Test results, findings, and remediation plans are documented, and executive summaries are available upon request. | |
| How is infrastructure redundancy ensured? | Multi-AZ deployment on AWS with automated failover, geographically distributed backups (Frankfurt production, Paris replication), and documented Business Continuity and Disaster Recovery Plans. |
| Question | Answer |
|---|---|
| Where is customer data hosted and processed? | All production data resides in the European Economic Area (AWS Frankfurt and Paris regions). All production data resides on an HDS-certified architecture. |
| Do you transfer data outside the EEA? | Only where operationally necessary (certain SaaS tools), limited to minimum required data, and protected by Standard Contractual Clauses, adequacy decisions, and supplementary technical measures (encryption, pseudonymization, access controls). Transfer impact assessments are documented. |
| Question | Answer |
|---|---|
| How can customers exercise audit rights? | We support proportionate audit mechanisms: |
| • Assurance reports: Annual ISO 27001 surveillance summaries and penetration test executive summaries | |
| • Pooled audits: ISO 27001 certification and independent third-party reports accepted in lieu of individual audits | |
| • On-site audits: Available for justified regulatory requirements with reasonable advance notice and subject to contractual clauses | |
| • Information requests: Documented process for security control, incident, and subprocessor inquiries | |
| Will you cooperate with competent authorities? | Yes. We commit to cooperate with supervisory authorities and facilitate customer compliance with regulatory requests. |
| Question | Answer |
|---|---|
| How is ICT risk governed? | Security and operational resilience overseen by executive leadership (CTO, CISO, DPO). Risk-based approach using EBIOS Risk Manager methodology. Documented ISMS aligned with ISO 27001:2022. Annual reviews, audits, and continuous improvement process. |
| What documentation can you provide for DORA due diligence? | • ISO 27001 certificate and scope |
| • Outsourcing Policy | |
| • Security Statement | |
| • Privacy Policy and DPA | |
| • Subprocessor list with locations | |
| • Latest pentest and audit summaries | |
| • BCP/DR Plan summary• Incident response procedures | |
| • Tailored Security Assurance Plan (upon request) |
| Purpose | Contact |
|---|---|
| Security and resilience matters | [email protected] |
| Data protection and privacy | [email protected] |
| Contractual and operational matters | Your dedicated account manager |