Trust center
Compliance as a product surface.
Not a slide.
LeCloud runs on Outscale SecNumCloud infrastructure. Every action, plan and approval is signed, archived and exportable as audit evidence.
Wording note: Rectangle is ISO 27001 and HDS certified. LeCloud runs on Outscale SecNumCloud infrastructure. Rectangle does not claim SecNumCloud certification of its own entity.
- Prompt receivedp:0x71…ceops-lead@rectangle · 14:02:11
- Plan signed0x9c41…ab2eai-mode / verified blueprint · 14:02:18
- Human approvalsig:0x4b…9dcompliance.peppol · 14:05:44
- Deployedrev:1.4.0argocd · fr-par-secnumcloud · 14:09:56
- Archivedlta:0xaa…12LTA · NF Z42-013 · 10y · 14:10:02
Verified blueprints & IaC discipline
Infrastructure designed to prove what it does.
Rectangle applies a formal verification discipline to its sovereign blueprints, designed to catch drift, privilege escalation and residency violations before they reach production.
- Blueprints carry machine-checkable invariants
- Residency, identity and network policy validated at plan time
- Failures surface as rejected plans — designed to avoid silent corrections
Human-in-the-loop ops
Designed so changes require explicit human approval.
Every change — manual, GitOps or AI Mode — is designed to pass a human approval gate scoped to the compliance domain it affects. Approver identity is attached to the signed plan and captured as evidence.
- Approval domains: compliance, peppol, identity, runtime
- Approver identity bound to signed plan hash
- Approval evidence captured in LTA
Sub-processors
Outscale (SecNumCloud IaaS). Selected EU sub-processors for trust services. Full list on request.
Evidence export
Signed, queryable evidence — plans, approvals, deploys, drift events — exportable per regulator request, retained per regulatory horizon.
Incident posture
Sovereign incident response with regulator-aligned notification windows aligned to NIS2 and DORA expectations.
Residency & data flows
Where your data lives — visible at plan time.
Residency is a blueprint invariant. Plans surface the target region before approval; ArgoCD reconciles against signed state. Designed to avoid accidental drift into non-EU control planes.
Request the trust pack
Everything procurement, security and audit need — in one signed package.
Sent within one business day under NDA, signed and timestamped, aligned with the current version of each document.
- Security overview — architecture, controls, disclosure policy
- Sub-processors list with roles and jurisdictions
- Residency map — sovereign zones and data flows
- DPA template aligned with GDPR Article 28
- Evidence export sample — signed JSON / PDF / CSV