Security

Security

Reporting a security incident


If you detect a security incident or alert, report it promptly to CERT Erium:  https://www.erium.fr/cert/ 
Any security incident identified by our internal teams, or notified by a third party, is analyzed by our technical team — supervised by Erium's CISO and Technical Director — to confirm whether it is a genuine incident and, where applicable, to determine:
  • the impacted scope (affected user accounts, functionalities, data types, etc.);
  • the likely consequences;
  • the origin;
  • the start date;
  • the remediation, containment or mitigation measures.
This information is communicated to the customers directly affected within a maximum of 3 working days. The exact timing depends on the incident's severity and on whether customers need to implement security measures.