Security & trust
Activity-tracking security by design
Phitalys processes presence data: we protect it to the standard an IT department expects, with one guiding principle — minimise what we read, and secure it end to end.
Microsoft 365 data access
- Agentless, no spyware: nothing is installed on devices. Phitalys connects to the Microsoft 365 API after admin consent, read-only.
- Least privilege: only the permissions required for presence and usage analysis — never write, never content access.
- Never the content: metadata and volumes only — no email body, no meeting subject, no file.
Hosting & encryption
- Hosted in the European Union (no transfer outside the EU for day-to-day operations).
- Encryption in transit: TLS on all communications (site and app).
- Encryption at rest and encrypted backups.
- Per-organisation isolation: one client's data is partitioned and never mixed with another's.
Access control & compliance
- Role-based access across 5 roles (admin, HR, manager, DPO, employee) with a named scope restricted per role.
- Logging of named access and administrative actions.
- Aggregation threshold: teams of fewer than five people are masked.
- Sensitive modules opt-in: detection is off by default; enabling it requires informing employees and consulting the works council where applicable.
Processing & GDPR
- Clear roles: the client is the data controller, Phitalys is the processor, under a data-processing agreement (DPA).
- Configurable retention set by the client, with automatic purge (90 days by default).
- Data-subject rights facilitated (access, rectification, erasure) — see the privacy policy.
Roadmap
We build Phitalys along the principles of ISO/IEC 27001 and SOC 2 (least privilege, logging, access management, incident response). A certification effort is on our roadmap; we only claim here what is in place today.
Report a vulnerability
Found a security issue? Email us at contact@phishia.fr — we treat these reports as a priority.