Security & compliance

A web agency that secures your data

A website that brings clients is good. A website, a mailbox and data that can never turn against you is our job. Here is what we answer to, in your words.

Run the free checkTalk to Raphaël

The check reads what anyone can see from the outside. No access, no password, no intrusion.

What we answer to

Each framework below is something the free check measures, or a mission covers. Nothing else.

GDPR

The European regulation on personal data, enforced in France by the CNIL.

A contact form, a booking, a customer file or a newsletter means you process personal data. You must tell people what you do with it, keep only what is useful, know where it is stored, and be able to delete it on request.

What we do: forms with an information notice and separate consent, a privacy policy written for your business, a processing register, retention periods set in the tool, cookies only when allowed.

NIS2

The European cybersecurity directive, transposed in France under the ANSSI.

It targets medium and large companies in eighteen sectors first. A shop is not on the list. But it forces those companies to secure their suppliers: if you work for a clinic, a local authority or a group, you will be asked for proof. That is where it turns to your advantage: whoever can show it keeps the contract.

What we do: an evidence file a client can read (protected e-mail, hosting, backups, access, incident procedure), aligned with the ANSSI hygiene guide, kept current by monitoring.

E-mail

SPF, DKIM and DMARC: the three settings that stop others writing in your name.

Without them anyone can send an e-mail signed with your name, to your clients or accountant, with a fake bank account. It is the most common fraud against small businesses, and needs no hacking.

What we do: the three records set and verified, a strict policy (fakes are rejected, not just flagged), and reports telling you who tries to impersonate you.

Legal notices

The French law that sets what a professional website must display.

Company name, registration number, address, host, publisher, and terms of sale for a shop. Missing notices are punishable, and they scare clients away.

What we do: complete notices written for your legal form, and terms of sale when you sell online.

Hosting and backups

Where your site and data live, and what happens the day something breaks.

Your data must stay in Europe, travel encrypted (HTTPS everywhere, always) and exist in several copies. A site without a restorable backup is not backed up.

What we do: EU hosting, forced HTTPS with modern protection headers, tested automatic backups, and a written recovery plan.

Payments

PCI-DSS, the card standard.

You do not have to carry it yourself, as long as your client's card never goes through your site.

What we do: payments go through Stripe, certified at the highest level; your site never sees or stores a card number.

Accessibility

The French RGAA standard, mandatory for some, good practice for all.

A site readable on every screen, at every age, in every situation: more clients, and what Google rewards too.

What we do: contrast, alt texts, keyboard navigation and clean structure, checked in the report.

How we work

From the lightest to the most complete. We never skip a step, and never enter anywhere without a written invitation.

  1. 01

    The free check

    Thirty seconds, from the outside, like a fraudster or a curious client would: e-mail, certificate, headers, legal notices, trackers, Google listing. Two scores out of 100 and the list of what matters.

  2. 02

    The full audit

    Under written mandate: your tools, access, backups, providers, forms, habits. A report in plain language, ranked by risk, with the cost of each fix.

  3. 03

    Compliance

    We fix, write, configure, and hand you the evidence: a file you can show a client, an insurer or an inspector.

  4. 04

    Monitoring

    Every month everything is measured again: a record that drops, a certificate that expires, a tracker that appears, a leak of your credentials. You are warned before it costs.

What we do not promise

Security is often sold with fear and jargon. We prefer simple rules, written here so you can hold us to them.

  • Never an intrusion test or a probe of your systems without a written authorisation setting scope and dates.
  • No site is unbreakable. We reduce what is exposed, detect fast, and know how to restore.
  • We display no certification we do not hold. Our references are our clients, and the check you can run yourself.
  • Behind RLCore: Raphaël, a graduate engineer specialised in cybersecurity, data and AI. He is the one you will get on the phone.

Start by seeing what a fraudster sees of you.

The check is free, with no commitment, and the full report is e-mailed to you.

Run the free check