Security

Upalgo is deployed on the customer’s infrastructure and operates without any external connection. Upalgo Labeling and UpalgoDB run fully offline and are in production on air-gapped networks. This page sets out the security measures of the software and the conditions under which Ezako’s team processes customer data.

Deployment

Upalgo Labeling (Sound, DAS and Timeseries) and UpalgoDB, the server that stores recordings and labels and coordinates the applications, are installed on the customer’s workstations (Windows, Linux, macOS) and servers. No cloud service is required, whether Ezako’s or a third party’s.

  • Fully offline operation, including on air-gapped networks.
  • Recordings and labels remain on the customer’s equipment.

Outbound data

None. Upalgo and UpalgoDB transmit no data, telemetry or usage statistics outside the local network. Updates are distributed by an update server on the local network, under the customer’s control.

Identity and access

Each user has a personal account and a role that defines their permissions. Single sign-on (SSO) integrates with the customer’s identity provider.

Traceability

Every change to a label is recorded as a patch in an operation-based replicated data structure (CmRDT). The full history is auditable (who changed what, and when), can be replayed in both directions, and any previous state can be restored.

Encryption

Communications between workstations and UpalgoDB are encrypted with TLS. Encryption at rest is provided by the storage on which UpalgoDB is deployed, such as full-disk encryption, and remains under the customer’s control.

Software integrity

Each release is signed and published with its checksums and its software bill of materials (SBOM), so that the customer can verify what is installed and what it contains.

Annotation by Ezako

Ezako’s annotation service is performed by Ezako employees in France, biologists and acoustics specialists, all bound by non-disclosure agreements. The data concerned, the place of processing and the handling rules are defined by contract before any work begins; the work is carried out on the customer’s premises or at Ezako. Ezako processes personal data solely as processor, under an agreement compliant with article 28 of the GDPR.

Vulnerability reporting

Security vulnerabilities in Upalgo or on this site can be reported to security@ezako.com. The address is also published in the site’s security.txt file.

Security assessments

For a security questionnaire or a detailed assessment, contact Ezako.