Your industrial data is secure, and your requirements are met
Dedicated server architecture, sovereign hosting, and 24/7 monitoring by the EDF Group. Yxir meets the most stringent security standards in the nuclear, defense, and aerospace sectors.
EDF Group
Servers in France
24/7 monitoring
Nuclear · Defence · Aeronautics
Infrastructure & Hosting
Choice of provider and location — AWS Cloud (France region), EDF sovereign cloud, or customer-owned infrastructure, depending on your regulatory requirements
Servers in France — Data centers in France with a secure EDF landing zone. Backup servers are also located in France
Data sovereignty — Sovereign hosting options (EDF Cloud, Cloud Sense) for data subject to French jurisdiction requirements
Contractual commitment — Data location and hosting commitments verifiable by CISOs, with enforceable contractual clauses
Data Security
Your data with you, not with us - Your data remains on your dedicated servers; Yxir does not have access to your data outside the contractual scope
Full encryption - All data is encrypted in transit and at rest. We already fully meet the encryption requirements of customers such as Safran, Thales and EDF.
Customer isolation - Strictly separate databases (tenant isolation), isolated environments, no data shared between customers
Data classification - Compatible with sensitive data up to C4E level
GDPR compliance - Controlled data lifecycle, retention and purge policy, right to be forgotten respected
Access Management & Traceability
Multi-provider SSO - Support for OpenID Connect protocols (Microsoft Entra ID, Google Workspace) and SAML v2.0 (Okta, other providers).
Customer-delegated MFA - Multi-Factor Authentication managed by your identity provider (Entra ID, etc.), with no credential storage at Yxir
Role system (RBAC) - Default roles (Admin, Editor, Viewer) + custom roles. Permissions per database, per property, per action (create/read/update/delete)
Dynamic permissions - Advanced formula-based rules: restrictions according to document status, creator, workflow stage, department, etc.
Access logs and full history - Log accessible to admins, traceability of all changes, ability to roll back
AI governance
Compliance
EDF Group security policy - Security practices aligned with EDF Group cyber requirements, documented and auditable procedures
Field validation in demanding sectors - Security architecture validated by the CISOs of Safran, Thales, EDF, Framatome and Naval Group
Annual pentests - Regular penetration tests by a specialised external company, vulnerabilities remediated according to criticality
Continuous cyber monitoring - EDF Group cyber services provide monitoring and 24/7 oversight of the infrastructure
Documentation on request - Incident management procedures, infrastructure administration, security policy provided to CISOs on request
