WakaStart doesn't bolt compliance on after development. It's built into the code from the moment it's generated. Every SaaS delivered natively embeds ISO 27001, NIS2, GDPR, HDS and eIDAS rules — with no separate compliance project and no extra budget.
Certifications & Compliance
Every rule natively embedded in your SaaS through Cybercoding
ISO 27001
Natively ready
NIS2
Zero Trust native
HDS
Health data
eIDAS 2.0
Qualified signature
GDPR
Native & CNIL
Digital vault
WORM · Evidential
OVH France
100% sovereign
Post-quantum
ML-DSA · ML-KEM
ISMS rules natively embedded in every build
WakaStart does not certify your SaaS — this certification is issued by an accredited external COFRAC auditor. What WakaStart does is deliver software where every line of code already meets the requirements of the ISO 27001 standard. The result: the certification audit that follows takes a few weeks instead of 18 months.
ISO 27001 compliance report
Audit-readyBuilt-in NIS2 compliance — 2027 deadline
The NIS2 directive requires B2B digital service providers to meet strict requirements for risk management, business continuity and incident traceability. WakaStart natively implements Zero Trust architecture, multi-datacentre geo-redundancy and the incident notification mechanisms required by NIS2.
NIS2 Zero Trust architecture
CompliantA legal requirement for any SaaS processing personal health data
In France, hosting or processing personal health data without HDS certification is a criminal offence. WakaStart relies on OVH's HDS-certified infrastructure to guarantee full legal compliance — strict partitioning of medical data, ANS-specific audit logs, compliant hosting contracts.
HDS compliance — Health data
CompliantThe eIDAS 2.0 regulation and the EUDI Wallet
Via the WAKA-SIGN module, your SaaS natively integrates qualified electronic signature (QES) — the highest level recognised under the European eIDAS 2.0 regulation. Your contracts, quotes and documents carry full legal value across all 27 EU member states, with no need for an external provider.
WAKA-SIGN — eIDAS 2.0
ActiveCNIL compliance built in from code generation
GDPR imposes precise technical obligations: data minimisation, traceable consent, right to erasure, records of processing activities. WakaStart natively generates all of these mechanisms in your SaaS — including consent forms, CNIL audit logs and data reversibility procedures.
WORM Object Lock · Blockchain · SHA-256 · Legal value
Via WAKA-SEAL, every archived document is cryptographically sealed, timestamped and stored in WORM (Write Once, Read Many) mode. Not even a root administrator can modify or delete an archive. The cryptographic block chaining guarantees that any tampering attempt immediately breaks the chain and triggers an alert.
WAKA-SEAL — Evidential archiving
ActiveInfrastructure & Encryption
Every security component is configured, tested and documented by our CISOs — not left to the discretion of a developer coding on a Friday evening.
Keycloak IAM — Identities & Access
Centralised identity management, SSO (Google, Microsoft, Apple, AD, SAML, OIDC), MFA, 3-tier multi-tenant RBAC. No implicit access — every permission is explicitly defined.
RBAC · ABAC · JWTVault — Secrets & Credentials
Encrypted storage of all secrets (API keys, database credentials, tokens). Automatic rotation, role-based access, strict Dev/Staging/Production isolation. No hard-coded secrets in the code.
Zero Secrets · Auto rotationSIEM — Real-time monitoring
Centralised logging with OpenTelemetry, Prometheus, Grafana. Real-time alerts on intrusion attempts, authentication errors and abnormal behaviour. Dedicated Auditor role.
OpenTelemetry · GrafanaWAF & Antivirus
Application firewall active on all instances. Mandatory antivirus scanning on all uploaded files. Protection against OWASP Top 10 attacks, DDoS, SQL injection, XSS.
WAF · OWASP · AntivirusSAST/DAST — Automated scans
Static and dynamic analysis on every build. Zero critical vulnerabilities allowed in production — the pipeline is blocked until the report is clean. CVEs on all dependencies checked continuously.
SAST · DAST · CVEEncrypted backups
Automated backups twice daily, AES-256 encryption, triple-redundant storage across 3 OVH France geographic zones, monthly restore testing. RPO < 1h, RTO < 4h.
AES-256 · Triple redundancyYour questions
Does WakaStart produce SaaS ready for ISO 27001 certification?
WakaStart natively embeds the requirements of the ISO 27001 standard into every SaaS it delivers. Official certification is issued by an accredited external COFRAC auditor — not by WakaStart. What WakaStart does is deliver software whose architecture, documentation and controls are already compliant with the standard, so the certification audit that follows is fast, predictable and free of surprises.
Where is my customers' data hosted?
100% in France, on OVH infrastructure. Two datacentres in France in active geo-redundancy. No data ever transits to servers outside the EU. For HDS projects (health data), hosting takes place on OVH's specifically HDS-certified infrastructure. For customers requiring maximum isolation, on-premise Runtime mode runs the application within your own infrastructure.
How does multi-tenant partitioning work?
Cybercoding applies native Row-Level Security (RLS) at the PostgreSQL database level. Every request is intercepted at the Gateway and enriched with the tenant_id from the JWT. It is technically impossible for a request from Tenant A to access Tenant B's data — even in the event of an application bug. This partitioning is verified with every build via SAST/DAST scans.
Is our data used to train your AI models?
No. Your specifications, source code and production data are protected by Zero Data Retention (ZDR) contractual clauses with every AI provider used by WakaStart. Your intellectual property remains yours — it is never used to train any public or third-party model.
How are secrets and credentials managed?
All secrets (API keys, database credentials, authentication tokens) are stored in an encrypted Vault with Dev/Staging/Production isolation. No secret is ever hard-coded in the code — the SAST pipeline blocks any build containing a plaintext secret. Key rotation is automated. Developers never have access to production secrets.
What does NIS2 compliance actually involve?
The NIS2 directive (fully applicable since 2024) requires all B2B digital service providers to meet obligations including: documented risk management, a business continuity plan, incident notification within 24 hours, supply chain security and data encryption. WakaStart natively embeds all of these mechanisms — you can demonstrate NIS2 compliance to your enterprise clients from the moment your SaaS is delivered.
Does the digital vault have legal value in France?
Yes. WAKA-SEAL evidential archiving produces immutable archives with eIDAS 2.0-compliant qualified timestamping and blockchain-anchored SHA-256 cryptographic chaining. These archives are admissible as evidence before French and European courts. The one-click forensic report contains all the integrity evidence needed for an ISO 27001 audit or legal proceedings.
Our free audit answers this question within 48 hours. Our CISO analyses your architecture, maps out non-compliance issues and provides you with a compliance roadmap with fixed timeline and budget. Free, confidential, no obligation.