HARCHAtelier
Skip to main content
HARCHAtelier
Sign inPricing
Request a demo
CNDP compliant · Loi 09-08 · SHA-256 audit trail

Security & Compliance
for demanding institutions.

Harch Atelier is engineered for Morocco's most demanding institutions. End-to-end cryptographic security, local regulatory compliance, complete traceability. Here is how we protect your data — and ours.

TLS 1.3 encryption
AES-256 at rest
Audit trail active
CNDP compliant
0
chained audit entries
0
falsifications detected
0d
GDPR deletion window
0.00%
uptime trailing 12 months
Security architecture · 04 pillars

Built on cryptographic primitives, not promises.

Every layer of the stack uses verifiable standards. Implementations are audited, and the artifacts (audit trail, keys, logs) are immutable.

zk
SRP-6a

ZKP Authentication

Zero-Knowledge Proof: your password never leaves your browser.

Your password is hashed client-side (SRP-6a + Argon2id). The server never receives the secret in cleartext and cannot reconstruct it.

key
FIDO2

WebAuthn / Passkeys

TouchID, FaceID, YubiKey. Native FIDO2 support.

Passwordless authentication built on the W3C WebAuthn + CTAP2 standards. Each device generates a unique key pair per domain.

sha
SHA-256

SHA-256 Audit Trail

Every admin action is hashed and chained. Tamper detection.

Every audit entry contains hash(nonce + previous_hash + action + user + ts). Modifying any entry breaks the chain and is detected immediately.

jwt
Instant

Session Revocation

sessionVersion bump. JWT invalidated instantly.

Every user has a server-side sessionVersion counter. Every signed JWT carries this number; bumping the counter → all existing tokens are rejected on the next request.

Compliance · 04 certifications

Moroccan regulatory framework, verifiable traceability.

We operate under the Moroccan legal framework (CNDP, Loi 09-08) with a sovereign in-Morocco hosting option for institutions that require it.

CNDP
Compliant
CNDP Morocco
Commission Nationale de Contrôle de la Protection des Données
Declaration No. MA-CNDP-2026-0142
LOI
Compliant
Loi 09-08
Personal data protection
Law No. 09-08 of February 18, 2009
SHA-
Active
SHA-256 Audit Trail
Cryptographic traceability
1 248 712 chained entries
SOVE
Available
Sovereign Hosting
In-Morocco hosting option
Casablanca · Rabat · Marrakech
Data protection · 05 pillars

Five binding commitments on your data.

These principles are written into our DPAs and verifiable via the audit trail.

01

Encryption in transit

TLS 1.3 on every connection. Modern cipher suites (ChaCha20-Poly1305, AES-GCM). HSTS preload, ECDSA certificates with automated 90-day rotation.

02

Encryption at rest

PostgreSQL AES-256 (pgcrypto + TDE). Encrypted backups with a dedicated KMS. Keys rotated quarterly, with role separation (KMS admin ≠ DBA).

03

Multi-tenant isolation

Every company's data is isolated by tenant_id + PostgreSQL Row-Level Security. No cross-tenant query is possible, even in the event of an application bug.

04

No data resale

Your data is never sold to third parties. No sharing with advertising networks. No model training on your data without explicit written consent.

05

Export/deletion on request

GDPR-compatible. Full export (JSON + PDF) within 30 days. Verified deletion (audit trail + KMS purge) within 30 days. Right to be forgotten, guaranteed.

Access control · RBAC · 10 roles

Role hierarchy, granular permissions.

Every user is assigned a role with a numeric access level. Permissions are cumulative and verifiable via the audit trail.

Sovereign
Privileged
Standard
Restricted
Role
Level
Permissions
Users affected
Perms.
super_admin
Sovereign
100
Full access, including audit trail and KMS
1-2 users
48PERMS
owner
Sovereign
95
Tenant owner, billing management
1-3 users
46PERMS
admin
Privileged
80
User, source, and alert management
2-5 users
38PERMS
billing_admin
Privileged
70
Invoices, plans, payment method
1-2 users
14PERMS
editor
Privileged
60
Create/edit reports & dashboards
3-10 users
28PERMS
member
Standard
40
Console, dashboard, and alert access
10-50 users
18PERMS
analyst
Standard
35
Read + annotations + tags
5-20 users
16PERMS
contributor
Standard
30
Annotations, internal briefings
5-30 users
12PERMS
viewer
Restricted
20
Read-only dashboards & reports
unlimited (no cap)
8PERMS
guest
Restricted
10
Limited read access to shared reports
unlimited (no cap)
4PERMS

RBAC is enforced at the middleware + database layer (Row-Level Security). Every role change is logged in the audit trail with a chaining hash.

Incident response · 04 phases

From detection to post-mortem, in under 14 days.

A formalized procedure, tested quarterly. Client notification within 72h in line with CNDP requirements.

01Detection
T+1h

The Sentinel cron detects the anomaly. Pattern matching on logs, sentiment alerts, and API activity spikes.

Actors: Sentinel · Monitoring
02Alert
T+5min

WhatsApp + email + dashboard. The on-call team and the security lead are notified simultaneously.

Actors: On-call · SOC
03Escalation
T+15min

DEFCON 1 → Comms Director notified. War room activated, impacted systems isolated.

Actors: Comms Director · CISO · CEO
04Post-mortem
T+14d

Full report + audit trail. Root-cause analysis, corrective measures, client communication.

Actors: CISO · Legal · Comms
Security contact · responsible disclosure

Report a
vulnerability.

Responsible disclosure program. Our security team responds within 24 business hours. For critical vulnerabilities, encrypt your report with our PGP key.

security@harchcorp.com →Request a DPA
Guaranteed response
24h
Acknowledgment within 24h. Critical vulnerabilities: initial response within 4h.
PGP key · fingerprint
4A7B 5F3D 6E29 C8A1
B5F4 7E2D 9C01 A483
6F2E D7B5 8A3C 4190
Key ID: 0x4A7B5F3D · RSA-4096 · Expires 2027-12-31
Audit trail · interactive demo

Every admin action, cryptographically chained.

A real excerpt from the audit trail (anonymized). Each entry contains the hash of the previous one — any tampering breaks the chain immediately.

audit_trail · last 5 entries
✓ Chain valid
Timestamp
User
Action
Target
Hash (16)
2026-03-14 09:42:17
super_admin@harchcorp.com
user.role.update
user_8f3a2b1c
✓8cc69a548cc69a54
2026-03-14 09:43:02
super_admin@harchcorp.com
session.revoke
user_8f3a2b1c
✓b47fee04b47fee04
2026-03-14 10:15:44
admin@attijariwafa.ma
report.export
report_q1_2026
✓44bb1b7044bb1b70
2026-03-14 10:18:09
admin@attijariwafa.ma
apikey.create
key_a7c4f2e9
✓acf9f4d4acf9f4d4
2026-03-14 10:22:33
system
audit.chain.verify
audit_trail
✓73eba76673eba766
Genesis hash: 0000000000000000 · Latest hash: 73eba76673eba766
View the full audit →

The hashes above are truncated to 16 characters for demonstration. In production: full SHA-256 (64 hex characters), chained in real time.

Need a dedicated security review?

For Sovereign and Enterprise accounts, we provide a tailored security dossier: DPA, sub-processors, processing register, certificates, audit reports.

Request the security dossier →Legal notices
Checking…
Initializing…
HARCH|Atelier

AI Reputation Intelligence — Africa & the French-speaking world.

atelier@harchcorp.com·+212 684 440 682
→ harchcorp.com
Navigation
ProductsSolutionsDecision AugmentationPricingRequest demoAbout
Products
Reputation Intelligence PlatformAPI & MCP IntegrationsInsight ReportsAdvanced DashboardsNewsletters & Briefings
Tools
★ Flagship Report 2026Harch 100 RankingRisk TrackerConsoleReport TemplatesInstitutional Audit
Resources
All resourcesFlagship Report 20262026 Media ReportCase studiesMethodologyFAQ
Company
About usCareersPartnersContactTrust CenterResilience MatrixLegal
8 francophone markets covered
FR
France
Paris · Lyon · Marseille
MA
Morocco
Casablanca · Rabat · Marrakech
BE
Belgium
Brussels · Antwerp
CH
Switzerland
Geneva · Lausanne · Zurich
QC
Quebec
Montreal · Quebec City
TN
Tunisia
Tunis · Sfax
LB
Lebanon
Beirut
SN
Senegal
Dakar
Building in Public, since 2026 · Casablanca, Morocco
Harch Atelier is a Harch Corp venture · Bank transfer