Trust

Security & compliance at Sesterce

Audited. Certified. Sovereign.

Sesterce operates under the most stringent security frameworks in the European data-center industry. Every certification, every audit report, every sub-processor — published here for you and your risk team.

Certifications

Frameworks, passed.

Active

SOC 2

Security, availability, and confidentiality controls audited by an independent third-party over a 12-month observation window. Covers all Sesterce Cloud and AI Factory operations.

Renewed Q1 2026 · EY France

Active

ISO/IEC 27001

International standard for Information Security Management Systems (ISMS). Covers risk assessment, access control, cryptography, operations, supplier relationships, and continuous improvement.

Valid until 2027 · AFNOR

Active

ISO/IEC 42001

First European AI infrastructure operator certified for AI Management System (AIMS) — covering responsible AI governance, risk, transparency, and the entire model lifecycle on our platform.

Certified Q1 2026 · first EU DC

In audit

SecNumCloud 3.2

French sovereign cloud qualification by ANSSI. Enforces strict data residency, supply-chain control, and operator independence for workloads subject to the French Military Programming Law (LPM) and state sensitivity.

Valence-01 · target Q2 2026

Active

HDS — Hébergeur de Données de Santé

French health data host certification for processing personal health data on behalf of hospitals, pharmaceutical research, and medtech customers. Full separation from commercial workloads.

Certified 2025 · Bureau Veritas

Active

GDPR & Data Residency

EU-only data processing by default. Named Data Protection Officer. Complete sub-processor list published and versioned. DPA executed per-contract. Article 32 technical and organizational measures documented.

CNIL-aligned

Active

Tier III+ Uptime Institute

Every Sesterce AI Factory is designed and audited to Uptime Institute Tier III+ Constructed Facility — concurrently maintainable, N+1 redundancy across power, cooling, and network.

Valence-01 · Paris-01 constructed

Active

NIS2 & DORA

Compliant with the EU NIS2 directive for essential service providers and DORA for financial-sector workloads. 72-hour incident notification, tested business continuity, supply-chain risk register.

EU-wide · from Oct 2024

For your risk team

Everything you need in one place.

Security resources

Audit reports

SOC 2, ISO 27001, and penetration test summaries available under NDA to qualified prospects.

Request access

Security resources

Sub-processors

Every vendor we share data with — NVIDIA, Schneider, Vast Data, OVHcloud. Versioned, dated, publicly signed.

View list

Security resources

SLAs & uptime

99.99% cluster uptime SLA, 24/7 NOC, 15-minute response, P90 ticket resolution within 4 hours.

Read the SLA

Security resources

DPA & contracts

Pre-negotiated Data Processing Agreement, standard contractual clauses, and Schrems II addendum ready to sign.

Request DPA

Security resources

Status & incident history

Live status page with per-site uptime, maintenance windows, and 24-month historical incident log with post-mortems.

status.sesterce.com

Security resources

Security whitepapers

Technical and organizational measures, encryption architecture, key management, supply-chain hardening.

Request whitepapers

Your risk team first

Questions your auditors need answered?

Our security team will respond to any formal RFI within 2 business days. Include your SIG Lite, CAIQ, or custom questionnaire.