Security · Confidentiality · Method

Security and confidentiality in every engagement

Security isn’t only about your infrastructure — it starts with the way we work.

This is the operational posture Fixery applies to every engagement, in concrete terms — access, secrets, backups, incidents.

Remote support across mainland France, and on-site by appointment.

What we apply

Six principles, upheld on every engagement

Not a decorative stance — simple rules, verifiable and maintained.

Least privilege

Only the access that’s strictly needed, granted narrowly and revoked the moment it’s no longer useful.

MFA on critical access

Strong authentication on sensitive tools and accounts, on Fixery’s side and on yours wherever possible.

Secrets management

No passwords or keys in plain text in our exchanges — and rotation is possible without breaking everything.

Backups & reversibility

A clear distinction between a backup that has been verified and a restore that has actually been tested. We don’t assume — we check.

Discreet logging

Logs that are useful for technical diagnosis, with no excessive data collection and no needless retention.

Incident handling

Isolate, identify the cause, restore a safe state, fix it for good and document it to prevent recurrence.

The technical posture

Reducing the attack surface, for the long term

Beyond each engagement, Fixery keeps a consistent technical posture: fewer dependencies, patches applied without delay, a backed-up configuration and useful supervision — never hidden data collection.

Updated: July 2026

Limited dependencies

We keep third-party components to the strict minimum, favour those that are well maintained and rule out obscure or abandoned ones. Fewer dependencies mean less exposed surface.

Controlled patching

Priority security updates are handled quickly, with no prolonged version freeze. The goal is a reasonably high patch level, with no backlog building up.

Configuration backups & recovery

Critical deployment settings are documented and backed up, so we can return quickly to a coherent state when needed. No sensitive point depends on unwritten memory.

Useful supervision, no tracking

We monitor availability and critical errors, with diagnosis-oriented logging. No marketing tracking, no advertising cookies, no personal data collected without a clear need.

Confidentiality & GDPR

Confidentiality comes first, especially in sensitive fields — legal and healthcare. Data minimisation, explicit purposes and GDPR compliance frame every engagement.

Our commitment

A posture, not a promise

We aim for a high security posture — verifiable and maintained. We never promise “absolute” security or total protection, because that would be technically and legally untenable. Our commitment is concrete: reduce the attack surface and apply strict best practices, especially where confidentiality and GDPR compliance come first.

Your questions

Frequently asked questions

How do you manage access to our systems?

On a least-privilege basis: only the rights that are strictly necessary, granted narrowly and revoked the moment they’re no longer useful. Sensitive accounts and tools are protected with strong authentication (MFA) wherever possible.

Do you promise “absolute” security?

No, never — that would be technically and legally untenable. We aim for a high security posture, verifiable and maintained: a reduced attack surface and strict best practices.

Are my backups really reliable?

We draw a clear line between a backup that has been verified and a restore that has actually been tested. A backup is only considered reliable once it has been verified and, ideally, tested. We don’t assume — we check.

What happens in the event of a security incident?

We isolate the exposure, identify the likely cause, restore a safe state, fix it durably and document it — the aim is to remove the cause of recurrence, not just the symptom.

Repair. Maintain. Make it last.

Let’s talk about your setup

A clear conversation to understand your environment and scope what needs securing first.

[email protected] · +33 6 08 68 44 03 · quick reply during business hours · Poitiers (86)