Skip to main content

Glossary

SecNumCloud

SecNumCloud is the qualification that ANSSI, the French cybersecurity agency, grants to cloud service providers after an audit against its own framework. Version 3.2 of that framework adds immunity criteria to non-European legislation, so a qualified offering keeps its data, its administration and its legal control inside the European Union.

How it works

SecNumCloud is a qualification, not a certification. ANSSI publishes the framework, an accredited evaluation centre audits the provider against it, and ANSSI then grants the qualification for three years. The version in force is 3.2, published in March 2022.

That version is the one that changed the conversation. Next to the technical requirements (tenant isolation, key management, logging, vulnerability handling, background checks on operators) it added criteria on immunity to non-European law. The provider's seat, its administration and the data have to sit inside the EU, and the provider must not be exposed to extraterritorial rules such as the US CLOUD Act. Ownership is part of the test, so a shareholding structure that places control outside the EU blocks the qualification.

ANSSI keeps the list of qualified offerings public, and a qualification covers a named offering at a named version, never a company as a whole. The right question to a supplier is therefore not "are you SecNumCloud" but "which offering is qualified, under which version, and until when".

Why it matters for a fleet

An MDM console holds the map of your estate: every device, its user, its OS version, its compliance state, often the list of installed apps. That inventory is a target in itself. Anyone who reads it knows which phones are unpatched and who carries them.

For French public bodies, the cloud doctrine published by the Prime Minister in May 2021 makes SecNumCloud the expected level for sensitive data, and the same line now appears in tenders from hospitals, defence suppliers and operators in scope of NIS2. Outside those sectors a qualified host still answers several supplier questions at once: where the data sits, what law reaches it, which operational practices were audited.

The trade-off is real. Qualified hosting narrows your choice of providers and usually costs more than a hyperscale region. You are buying legal immunity and an audit, not extra features.

How Appaloosa handles it

Appaloosa holds no certification of its own, and the SecNumCloud qualification belongs to the hosting provider rather than to Appaloosa. In practice that means the platform runs on infrastructure located in France, qualified SecNumCloud under version 3.2 of the framework including the immunity criteria, and customer data is not transferred outside the EU.

For you, that removes the transfer chapter from a GDPR record and gives a security questionnaire a documented answer instead of a promise. The rest stays yours: which data you push into mobile device management, how long you keep it, who on your team can read it. Appaloosa supplies the controls (roles, retention, selective wipe) and the hosting, not compliance itself.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

See the full platform Explore Appaloosa

Frequently asked questions

Is SecNumCloud the same as an international security standard?
No. SecNumCloud is a French state qualification granted by ANSSI after an audit against a prescriptive framework, legal immunity criteria included. An international management standard has a scope the organisation defines itself. A qualified provider meets far more specific technical and legal requirements.
Does SecNumCloud hosting make us GDPR compliant?
It settles one part: data location and exposure to non-European law, so the transfer chapter of your record becomes short. Everything else stays with you as controller, including lawful basis, minimisation, retention periods and informing your employees about what the MDM collects.
Do we need SecNumCloud if we are a private company?
It is not mandatory outside regulated uses, but it is increasingly asked for in tenders and supplier reviews, especially for NIS2 entities and health data. If your legal team worries about the US CLOUD Act, a qualified host is the shortest answer available.