Data
Residency, backups, logs, subcontractors, retention periods, and export formats are documented.
We design and manage applications in France with controllable hosting, data, code, and dependencies. Tailored to your requirements: France, Europe, HDS, or SecNumCloud-qualified offerings.
We examine where your data resides, who operates the infrastructure, which dependencies could block a takeover, and how to transfer the system.
Residency, backups, logs, subcontractors, retention periods, and export formats are documented.
The full source code is version-controlled, documented, and transferable to the client.
Providers, regions, accounts, access rights, and recovery procedures are explicitly defined.
Proprietary dependencies and conditions for handover to another team are known.
An application does not require the same setup whether it manages an internal tool, health data, or an essential service. We make the trade-offs explicit.
For a business application that must remain recoverable: transferable Git repository, standard database, inventoried exports and dependencies.
Application, data, backups, and logs hosted in the selected regions; third-party flows mapped.
For healthcare or sensitive data: deployment on the HDS service or the qualified SecNumCloud offering specifically selected for the project.
A certification applies to a precise service and scope, never automatically to the entire application. We verify and document the selected offer for each project.
We can deploy a health data processing application on Scalingo’s PaaS, which is HDS 2.0 certified for all six activities. Final compliance depends on the project’s scope and architecture.
The certification covers the Scalingo service and its scope, not automatically Scroll or the application.
Depending on requirements, we can deploy on a SecNumCloud-qualified OVHcloud offer, such as Private Cloud SecNumCloud or Bare Metal Pod. The exact offer and its scope are specified in the architecture file.
A standard OVHcloud infrastructure is not SecNumCloud by default, and the application is not presented as qualified by inheritance.
Reversibility becomes real when it produces verifiable deliverables, handed over throughout the project rather than on the last day.
History, branches, delivery procedures, and access rights can be taken over by your team or a third party.
Documented schema and exports in standard formats, without relying on a proprietary interface.
Accounts, environments, domains, certificates, secrets, and responsibilities are inventoried.
Every dependency, licence, location, and exit condition is made visible.
Backups, restore tests, and recovery objectives are tailored to the service’s criticality.
Runbooks, architecture, and transfer sessions enable another team to operate the system.
Migration to an open stack, self-hosting, or French AI: these principles have already guided applications delivered by Scroll.
Gradual migration to Next.js and self-hosted Supabase on OVHcloud, with data takeover and service continuity.
Qualification of incoming requests using Mistral, n8n, and Dolibarr, in an architecture where flows and access remain documented.
We start from your actual constraints, not a generic label. Every architectural decision is tied to a risk, a cost, and a recovery plan.
Data, flows, subcontractors, dependencies and obligations are inventoried before selecting an infrastructure.
France, Europe, HDS or SecNumCloud: the level is chosen based on risk, constraints and budget.
We prioritise open standards, replaceable components, tests and verified backups.
Access, exports, operational procedures and recovery plans are provided and kept up to date.
We clarify the scope before any commitment: hosting, transfers, providers and reversibility conditions.
We map your constraints and propose a clear, costed, and reversible architecture.