Built for sensitive workforce environments
Protecting workforce data requires more than isolated technical measures. It depends on controlled access, clear responsibilities, traceable activity and consistent governance across entities, systems and jurisdictions.
-
01
Controlled access
Permissions can be configured by role, organizational unit, responsibility and data sensitivity. Multi-factor authentication and single sign-on provide additional identity controls.
-
02
Protected data
Data is encrypted at rest using established technologies that include AES-256, BitLocker and Transparent Data Encryption. Data in transit is protected using TLS 1.2 or later.
-
03
Complete traceability
Technical logs record key activities, including the creation, modification and deletion of information. Detailed histories support internal reviews, investigations and audits.
-
04
Documented governance
Formal security, privacy, risk and incident-management policies support consistent oversight and are reviewed regularly.
-
ISO/IEC 27001
Sigmia’s Information Security Management System is certified to ISO/IEC 27001, an international standard for managing information security risks through documented controls and continuous review.
-
SOC 2 Type II
Sigmia undergoes an annual SOC 2 Type II examination covering controls related to security, confidentiality and traceability over a defined review period. SOC 2 Type II is an independent assurance report, not a certification.
-
HDS health data hosting
Sigmia holds an extension to its HDS certification scope for applicable health data hosting services in France.
-
Responsible business practices
Sigmia has received an EcoVadis Bronze rating. In Canada, Sigmia also holds Concilivi and Great Place to Work recognition.
-
Canada and Quebec
The platform supports access governance, activity traceability and consent-management processes relevant to PIPEDA and Quebec Law 25, including the recording, granting and withdrawal of consent.
-
European Union
Configurable capabilities can support GDPR governance, including retention policies, privacy parameters, processing records, access controls and processes for data-subject requests.
These capabilities support compliance programs but do not independently guarantee an organization’s compliance.
Controls aligned with different privacy environments
Sigmia generally acts as a data processor or service provider when processing information for a client. The client remains responsible for determining the lawful purposes, accuracy, retention and authorized use of its workforce data.
Secure cloud infrastructure on Microsoft Azure
Sigmia uses Microsoft Azure infrastructure. Azure maintains certifications and assurance reports that include ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 1 and SOC 2 Type II.
Depending on the deployment and contractual requirements, data may be hosted in France or elsewhere within the European Union.
Hosting regions, subprocessors and transfer arrangements are reviewed during the security and procurement process.
Defined procedures for managing information risk
Sigmia maintains a formal Information Systems Security Policy and a corporate social responsibility policy. Both are reviewed regularly.
Security and privacy risks are assessed through documented processes. Data Protection Impact Assessments may be conducted for processing activities that present elevated privacy risks.
Incident-management procedures guide assessment, escalation and regulatory notification. The appropriate organization notifies the relevant authority when required by applicable legislation and contractual responsibilities.
Evidence for security and procurement reviews
Subject to confidentiality requirements and availability, Sigmia can provide documentation supporting client due diligence.
Documentation may include:
- Certification scopes
- SOC 2 Type II information
- Security questionnaires
- Hosting and data-residency information
- Privacy and data-processing documentation
- Subprocessor information
- Business continuity information
Frequently asked questions
Yes. Sigmia’s Information Security Management System is certified to ISO/IEC 27001. The current scope and validity period can be confirmed through the applicable certificate.
Sigmia undergoes an annual SOC 2 Type II examination. Access to the report may be subject to confidentiality and due-diligence requirements.
Sigmia applies encryption, granular permissions, multi-factor authentication, single sign-on and detailed technical logging.
No platform can independently guarantee an organization’s overall compliance. Sigmia provides controls that support compliance, while each client remains responsible for its legal and governance obligations.
Sigmia uses Microsoft Azure. Available hosting locations depend on the selected deployment and contractual requirements.
Organizations evaluating Sigmia can contact its security and compliance specialists. Certain documents may require a confidentiality agreement.