Source code and research work
Repositories hosted with a contractor, sometimes on a developer's personal account. Nobody knows who still holds access once a colleague leaves or an engagement ends.
Science park
Sophia Antipolis is not a town: it is a business park spread across several communes of the Alpes-Maritimes, concentrating technology companies, research centres and a constellation of very small firms orbiting them. We work there from Nice on security, software development and artificial intelligence — in English where that is the language of the office, which on this park it often is.
Travelling from 4 rue de Grammont, 06100 Nice · Travel time to the park: within 24 hours in an emergency
The ground
Sophia Antipolis is Europe's oldest and largest science park of its kind: created at the end of the 1960s, it now stretches across several communes around Valbonne and Biot, and concentrates a density of technology companies with no equivalent in the south of France — computing and software, telecommunications, microelectronics, life sciences, energy, alongside public laboratories and higher education institutions.
That density produces a two-tier fabric. On one side, sites belonging to large companies and corporate R&D centres, which have IT teams of their own. On the other — and this is our ground — a large population of small and medium firms: start-ups, software publishers, engineering consultancies, advisory practices, service companies subcontracting to the first group. Some employ five people and handle intangible assets worth far more than their size suggests.
It is also the one place in the department where English is routinely the working language. Many firms here are subsidiaries or spin-outs of foreign groups; others were founded by people who arrived for a job at one of the large sites and stayed. That produces a particular pattern: group IT policy written somewhere else, in English, with nobody locally whose job it is to apply it, and a French-language supplier ecosystem underneath it.
The gap that defines the local need is a different one. Elsewhere in the department, IT risk is first about continuity: a till that stops working, a lost schedule. Here it is also, and mainly, about intellectual property: source code, experimental results, training datasets, product specifications, documents under non-disclosure. A leak cannot be undone, and it can cost a contract or a patent filing.
Second particularity: firms on the park almost all work for clients larger than themselves, and often based abroad. Those clients impose contractual security requirements — supplier questionnaires, confidentiality clauses, audits, sometimes a demand for certification. A company of ten finds itself having to evidence practices no regulation otherwise requires of it. That is frequently the real reason behind a first phone call.
Third, more prosaically: the teams are mobile. Remote working, assignments on client sites, researchers and interns passing through for a few months. What has to be protected is not a building, it is a set of accounts and laptops that move — which changes the shape of the problem entirely.
We work across the whole park, meaning the six communes it is spread over: Valbonne, Biot, Antibes, Mougins, Vallauris and Villeneuve-Loubet. Scoping and the debrief happen on site; the analysis, the development and much of the follow-up are run remotely.
Weak points
These are not client cases but recurring configurations in companies whose staff can write code and therefore assume that security takes care of itself.
Repositories hosted with a contractor, sometimes on a developer's personal account. Nobody knows who still holds access once a colleague leaves or an engagement ends.
A large client or an overseas partner sends a thirty-page questionnaire. Answering it means documenting practices that sometimes exist but have never been written down.
Copies of production databases are used for testing, on machines less protected than the servers they imitate. That is where data leaks, not from the marketing site.
Consultants, interns, partner laboratories: people arrive and leave often. With no procedure, every passage leaves a live account behind it.
What we do
Facing a team that already knows its way around computers, our value is not in doing the work for them: it is in looking at what an internal team has stopped seeing.
Protecting intangible assets, not just workstations.
Extra capacity or an internal tool, with no lock-in created.
Using your data without handing it to just anyone.
How we work
In a technical company the first obstacle is not competence, it is habit: the shortcuts taken at the start have become the norm, and the team that took them no longer sees them. An external review is not there to lecture engineers, but to ask the questions nobody asks internally any more — who still has access to what, what would happen if a given service went down, what you could actually evidence to a client who asks.
We work under a non-disclosure agreement from the first conversation where your activity requires it.
The park is large and companies are often split across several buildings or shared workspaces. Scoping and the debrief happen on site; the bulk of the analysis and development work is run remotely. We travel from Nice.
In an emergency we are on site within 24 hours, travelling from our Nice office.
No reference on the science park is published to date. Confidentiality is the rule on this ground: we will publish an anonymised description approved by the client, or nothing. Our published case studies are here.
Frequently asked
A view that took none of the past decisions. Your developers know how to build; the review covers what surrounds the building: access, secrets, repository backups, test environments, contractor offboarding. In a small team those subjects belong to nobody in particular, and so they stay open.
Yes — it is a frequent reason for engaging us here. The work consists of separating what you already do but have never documented, what is genuinely missing, and what does not apply to an organisation of your size. The free initial audit measures that gap before anyone commits to a response deadline.
By contract and by method: a non-disclosure agreement signed beforehand, access limited to what is strictly necessary, no copies of data taken away, no remote access kept after the engagement. We never name a client without written consent, which is why the references section of this page is still empty.
That is how it is set up. Rights in the code are assigned to you on delivery, the repository is in your name from day one, and hosting accounts are opened under your credentials. The detail is on the software development page.
The initial audit is free and the report is yours, even if you take it no further.