Trust · Legal · Security · Compliance

Trust as infrastructure.

The RDMC Trust Center centralizes the contractual, operational and regulatory commitments related to our digital services, security, data protection, artificial intelligence and sensitive technologies.

Reference document

Information security policy

Version 2.0 — effective as of 01/04/2026

RDMC applies a risk-based approach to preserve confidentiality, integrity, availability, traceability and resilience.

Principles

Least privilege

Access granted on a need-to-know basis.

Defense in depth

Complementary organizational, network, system and application controls.

Security by design

Requirements embedded from the design stage.

Continuous improvement

Audits, incidents, patches and lessons learned.

Technical and organizational measures

  • identity and entitlement management;
  • strong authentication where required;
  • segmentation and separation of environments;
  • logging and monitoring;
  • vulnerability and patch management;
  • encryption in transit and, depending on the service, at rest;
  • backup, continuity and recovery according to subscribed commitments;
  • securing development pipelines and secrets.

Shared responsibility

The Customer remains responsible for its users, endpoints, passwords, administrator access, configurations, data, third-party applications and its own regulatory obligations.

Incidents

RDMC qualifies incidents within its scope and implements appropriate containment, investigation, remediation and return-to-normal measures. Notifications are made under the Contract and applicable obligations.