Security Policy
How we protect this site and the personal data of visitors who reach out to us. Version 1, effective 22 September 2026.
1. Scope
This policy applies to tourismeiffel.com, its subdomains, and any personal data processed on its behalf.
2. Technical measures
- Transport encryption: TLS 1.3 with HTTP Strict Transport Security enabled for one year (
Strict-Transport-Security: max-age=31536000). Automatic Let's Encrypt certificate renewal. - Content Security Policy: restricts script and style sources to prevent cross-site injection.
- Security headers:
X-Content-Type-Options: nosniff,Referrer-Policy: strict-origin-when-cross-origin, restrictivePermissions-Policy. - Web Application Firewall: Cloudflare WAF with managed OWASP rules.
- Bot mitigation: Cloudflare Turnstile and rate limits on submit endpoints.
- Server hardening: minimal software footprint, non-root service accounts, automatic security updates.
- Backup and recovery: daily encrypted backups off-site with 30-day retention.
3. Organisational measures
- Access control: role-based access with two-factor authentication for all administrative accounts.
- Least privilege: operational tasks use dedicated service accounts with minimum required permissions.
- Audit logs: all administrative actions on the CMS and hosting layer are logged and retained for 12 months.
- Training: the editorial team follows an annual security-awareness refresher covering phishing, password hygiene and data handling.
- Vendor review: new suppliers undergo a lightweight security review before onboarding.
4. Data-breach handling
If we become aware of a personal-data breach, we assess its scope within 24 hours, contain the issue, and — per GDPR Article 33 — notify the CNIL within 72 hours if the breach poses a risk to individuals. Affected users are informed directly per Article 34 when the risk to their rights is high.
5. Responsible disclosure
We appreciate security researchers who follow responsible-disclosure practices. If you find a vulnerability:
- Report it to [email protected] (PGP key available on request).
- Provide enough detail for us to reproduce the issue.
- Give us reasonable time (at least 30 days) to remediate before public disclosure.
- Do not exploit the vulnerability beyond what is needed to demonstrate it, and do not access data belonging to other users.
We commit to acknowledging your report within three working days, keeping you informed of progress, and — with your consent — crediting you in our security acknowledgements.
6. What is out of scope
- Vulnerabilities in third-party services (report those to the vendor).
- Denial-of-service attacks and volumetric floods.
- Social-engineering attempts against our staff.
- Automated scanner output without a demonstrated vulnerability.
7. Compliance references
GDPR (Regulation (EU) 2016/679), French Loi Informatique et Libertés, ISO/IEC 27001 and 27002 as an inspiration (not certified). We follow the OWASP Top 10 and CIS Critical Security Controls when designing site infrastructure.
8. Version history
Version 1, dated 22 September 2026 — initial publication.