Security and compliance
How Socrate protects access to your data, point by point, for your IT department.
Two hosting modes
By default, Socrate and Syrona are installed on your servers, in your country. As an option, Socrate runs them in its sovereign European cloud: hosted in France by Scaleway, with a SecNumCloud hosting option available.
Compare the two modes →Sign-in through your identity provider
Agents sign in through your organization's SSO: Microsoft Entra ID, Google Workspace, ADFS, Okta, Keycloak or any OIDC provider. Socrate never sees passwords. Self-registration is disabled: an account exists because your directory, your identity provider or an administrator decided so.
Accounts aligned with your directory
Accounts, groups and departments can be synchronized from your directory or pushed via SCIM 2.0. Leavers are deactivated automatically. In strict mode, only your directory grants access to the platform.
Role- and group-based access
Access is granted through roles and groups, down to each building block. When rules conflict, deny wins. Access is recomputed on every request: a revocation applies from the next one.
Audit logging
Every change to your organization's configuration is recorded: author, action and change, with secrets masked. In strict mode, every account creation, refusal or removal is logged by name.
Your data and Syrona
Your data is never shared with third parties or used to train an external model. Syrona's register and control tower provide the traceability the AI Act expects.
Certification and GDPR
ISO 27001 certification in progress. Our data protection officer answers your questions at dpo@socrate.fr. Vulnerabilities are reported to security@socrate.fr, as stated in our security.txt file.
Read the privacy policy →