Download this must-have guide to start your marketing automation journey.

DORA compliance: secure your data with Webmecanik

Secure your data and your marketing and sales operations with a French, reliable solution designed to meet security, resilience, and compliance requirements.

More than 700 clients trust us,
from startups to major players in finance.

A solution tailored to the requirements of the financial sector

The DORA regulation strengthens the requirements imposed on financial-sector actors regarding digital operational resilience and the management of risks related to their technology service providers. As a French editor of marketing automation and CRM solutions, Webmecanik implements security, continuity, and governance measures that meet the key expectations for TIC providers.

Data hosting in France, access protection, incident management, business continuity, and oversight of subcontracting: our organization and commitments are designed to enable organizations subject to DORA to evaluate Webmecanik as a reliable technology partner.

Your data hosted and protected in France

The data entrusted to Webmecanik are hosted in France at OVH. Daily backups are also performed at OVH and Clever Cloud, on infrastructure located in France.

This control over data location limits dependencies on non-European infrastructures and provides greater visibility into the chain of providers involved in delivering our services.

Security built into our solutions

Security is an integral part of the design and operation of our solutions. Webmecanik in particular applies systematic code reviews, OWASP Top 10 recommendations, and regular vulnerability scans. An EDR solution also ensures continuous monitoring of threats.

Communications are encrypted via TLS 1.2 and TLS 1.3, and sensitive access is protected using mechanisms such as multi-factor authentication, SSO, and applying the principle of least privilege.

Proactive business continuity

Webmecanik has a Business Continuity Plan enabling the management of major incidents and ensuring service recovery. Our containerized infrastructure is based in particular on Kubernetes to strengthen the availability of our solutions.

In the event of a critical situation, a dedicated crisis team can be activated. Our recovery objectives provide for 50% of capacity restored within 24 hours and 100% within 72 hours.

Security regularly tested

Our security level is regularly assessed to identify and correct any potential vulnerabilities. Penetration tests are carried out by independent external providers every two years. Any critical vulnerabilities identified are subject to a prioritized remediation plan.

We also carry out regular vulnerability scans in order to maintain an appropriate level of security over time.

Structured incident management

Webmecanik has processes to detect, qualify, handle, and document incidents that may affect the availability, integrity, or confidentiality of its services.

As part of our contractual commitments, notification procedures may in particular specify the nature of the incident, its scope, the services or data concerned, the initial remediation measures, as well as the corrective actions implemented. These arrangements complement the commitments already applicable under GDPR.

A managed chain of subcontractors

Oversight of technology providers is one of the important challenges of DORA. Webmecanik keeps updated information relating to subcontractors involved in the delivery of its services, in particular for hosting, backup, routing, CDN, technical diagnostics, artificial intelligence, or managed hosting.

This information can be shared with our clients to enable them to accurately assess their chain of providers.

Documented commitments to meet your requirements

To support organizations subject to DORA in assessing their technology providers, Webmecanik can provide several elements that help document its level of security, resilience, and governance:

  • Security Assurance Plan (PAS): it presents the measures implemented by Webmecanik regarding security, access management, data protection, business continuity, and incident management.
  • DORA contractual annex: it allows us to formalize our commitments relating to service security, incident notification, subcontracting, the right to audit, business continuity, and reversibility.
  • Information about our subcontractors: we can share the information needed to identify and assess the providers involved in delivering our services.
  • Security and resilience evidence: depending on the applicable needs and confidentiality conditions, different supporting documents may be provided to support our clients’ assessment and audit processes.

Webmecanik, a French editor to keep control of your data

The design of our products, our support, and data hosting are based on a French and European environment. This control over our technology chain helps us limit critical dependencies, maintain control over the data entrusted to us and meet the levels of requirements expected by organizations in the most regulated sectors.

FAQ

What is the DORA regulation?

DORA, for Digital Operational Resilience Act, is an EU regulation aimed at strengthening digital operational resilience for financial sector actors. It governs in particular the management of risks related to information and communication technologies (ICT), incident management, resilience testing, and the use of third-party technology service providers.

Who does the DORA regulation apply to?

DORA concerns many organizations in the European financial sector: credit institutions, investment firms, payment institutions, insurers, asset management companies, as well as certain crypto-asset service providers. The regulation also sets requirements for how these actors assess and oversee their ICT service providers.

Is Webmecanik compliant with DORA?

Yes. Webmecanik implements the security, resilience, business continuity, and risk management measures expected under DORA for its CRM and marketing automation services.

As a technology provider, we therefore support organizations subject to DORA by providing them with a secure environment, a managed chain of subcontractors, and the contractual and documentation elements needed to evaluate their provider.

What security measures does Webmecanik implement?

Webmecanik applies several measures to protect data and access to its solutions: encryption of communications via TLS 1.2 and TLS 1.3, multi-factor authentication, SSO, rights management according to the principle of least privilege, code reviews, vulnerability scans, and penetration tests carried out by external providers.

Why choose a French solution like Webmecanik in the context of DORA?

Choosing Webmecanik means relying on a French editor whose data is hosted in France and whose chain of providers is reliable. This proximity also makes it easier to discuss the security, contracting, continuity, and audit requirements needed by organizations operating in regulated sectors.

Adopt the marketing and CRM solution used
by more than 700 businesses

Webmecanik supports you at every stage of the sales funnel, from the first interaction to conversion—so you can turn your data into a real growth lever.