Hosted in Europe
Production runs in OVH data centres in the European Union. A client-dedicated instance, isolated from every other tenant, is available on the Professional and Enterprise plans.
Security & compliance
IRIS holds your sales, stock and supplier data. This page explains where it lives, who can reach it, how it is backed up, and what we commit to contractually. Ask us for the full security documentation before your pilot.
Production runs in OVH data centres in the European Union. A client-dedicated instance, isolated from every other tenant, is available on the Professional and Enterprise plans.
Each client has its own database and its own encryption keys for stored credentials. There is no shared table between clients.
Roles (Admin, Planner, Manager, Executive) with scopes by brand, category and store, multi-factor authentication, and single sign-on with your identity provider.
Every forecast override, order validation, transmission, transfer and user change is written to an audit log with who, what and when. The log is exportable.
Encrypted daily backups retained for 30 days, stored in a second EU location, with restoration tested on a schedule.
Export everything in CSV at any time. At contract end your data is returned and deleted from production and backups within 30 days.
| Area | What IRIS does |
|---|---|
| Encryption in transit | All traffic to IRIS and to the API uses TLS 1.2 or higher. ERP connections use HTTPS, SFTP or a VPN tunnel; plain FTP is never used. |
| Encryption at rest | Databases, file storage and backups are encrypted at rest on the hosting provider's storage. ERP credentials are encrypted at application level with a per-client key. |
| Authentication | Passwords hashed with a modern algorithm, MFA available for every user and enforceable per role, SSO (SAML / OpenID Connect), session expiry and login rate limiting. |
| Authorisation | Role-based access with scopes by brand, category and store. Approval thresholds decide which orders need a human validation. |
| ERP integration | IRIS reads items, stock, sales and suppliers, and writes only purchase orders and transfer orders, each carrying the IRIS reference. The ERP account used by IRIS is created by you with the minimum rights needed. |
| Monitoring | Infrastructure and application monitoring with alerts to the IRISYS on-call engineer. Failed ERP transmissions raise alerts to the planner and the administrator. |
| Backups and recovery | Daily encrypted backups, 30-day retention, copy in a second EU location. Recovery objectives are written into the contract. |
| Software supply chain | Dependencies are updated on a regular cycle and scanned for known vulnerabilities before each release. |
| Vulnerability disclosure | Report a vulnerability to security@irisys.cloud. We acknowledge within two business days and keep you informed until it is fixed. |
IRISYS processes your data under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for European clients, the GDPR. A data processing agreement is signed with every contract.
Item, stock, sales and supplier data from your ERP, and the accounts of your users (name, work email, role). IRIS does not need your customers' personal data; sales are processed at store and SKU level.
OVH SAS (hosting, EU) and the email provider used for notifications. The full list is in the data processing agreement and updated with 30 days' notice.
Production and backups stay in the European Union. Client-dedicated instances can be placed in a specific EU region on request.
[À COMPLÉTER] Third-party audits and certifications will be listed here as they are completed. Our security documentation and questionnaire answers are available under NDA.
Documented incident response and continuity plans. Clients are informed of a security incident affecting their data without undue delay, and within 72 hours at the latest.
IRIS is delivered as a managed service on OVH in the EU, with a client-dedicated instance available. On-premise deployment is not offered; it would remove the monitoring and update guarantees described on this page.
Read access to items, stock, sales and suppliers, and write access limited to purchase orders and transfer orders. You create the account and can revoke it at any time.
Only the engineers assigned to your account, for support and maintenance, under a confidentiality agreement. Every access is logged and available to you on request.
Yes. Architecture, controls, backup and incident procedures and our answers to standard security questionnaires are shared under NDA before the pilot.
Send us an anonymised sales export. We show you your forecasts and order proposals within 10 days.