⛏️MineInterop

MineInterop

Sécurité & Confidentialité

Security & Privacy

MineInterop est une couche d'infrastructure neutre pour l'industrie minière. La sécurité, la confidentialité et la conformité réglementaire sont au cœur de sa conception.

🔒

Security & Trust

TLS 1.3 & HSTS

Tout le trafic est chiffré en transit via TLS 1.3, avec HSTS activé pour forcer les connexions sécurisées.

Chiffrement AES-256 au repos

Le stockage temporaire des fichiers uploadés est chiffré en AES-256, puis supprimé immédiatement après traitement.

Authentification API

Les clés mik_live_… sont transmises uniquement via le header X-API-Key — jamais en query string, jamais dans une URL.

Stateless by design

Aucune donnée de bloc-modèle n'est conservée après la réponse de l'API. Le traitement est réalisé en mémoire, sans persistance.

Audit trail & intégrité

Chaque rapport PDF inclut une empreinte SHA-256 et un QR code de vérification d'intégrité.

Infrastructure

Google Cloud Run (europe-west1), Artifact Registry privé et politiques IAM least-privilege.

Enterprise on-premise

Déploiement Docker isolé dans l'infrastructure client — aucun contact réseau vers mineinterop.com lorsque PORTAL_VERIFY_URL est vide (mode air-gapped).

🛡️ GDPR Compliant☁️ GCP europe-west1🏭 Enterprise On-Premise Ready
🛡️

Privacy Policy

Politique de confidentialité — conforme RGPD

Data collected

  • Email, name, API usage counters (number of operations per module).
  • Request logs: timestamp, endpoint, duration — without the content of uploaded files.

Data NOT collected

  • Content of uploaded block-models: processed in memory only, never persisted to disk or database.

Cookies

  • mi_locale : language preference (non-tracking).
  • httpOnly session cookie for authentication.

Third-party sharing

  • No commercial data sharing.
  • Stripe for payments (card data never transits through MineInterop).

Retention

  • API logs: rolling 30 days.
  • Account data: retained until explicit account deletion.

GDPR rights

  • Access, rectification, erasure, portability.
  • Contact: [email protected]
  • DPA (Data Processing Agreement) available on request for Enterprise clients.

Governing law: French law — Tribunal de Commerce de Paris.

Last updated: July 2026.

📄

Data Processing Agreement (GDPR Art. 28)

Our DPA is available for Enterprise clients requiring formal GDPR compliance documentation.

📋

Enterprise NDA Template

Mutual Non-Disclosure Agreement — Template

This template is provided for reference only. Enterprise agreements are executed as separate signed documents. Contact [email protected] to initiate.

Parties: [CLIENT COMPANY] ("Receiving Party") and Solarius DeepTech SAS, a French simplified joint-stock company ("Disclosing Party").

Purpose: Evaluation of the MineInterop API platform, including technical documentation, Enterprise pricing, and exchange of test block-model data.

Confidential Information includes: API architecture & source code, pricing structures, client lists, performance benchmarks, and any test data exchanged between the parties.

Obligations: Each party shall (i) hold Confidential Information in strict confidence, (ii) use it solely for the Purpose, (iii) not disclose it to third parties without prior written consent.

Duration: Confidentiality obligations survive for 3 years from the date of signature.

Exclusions: Information that is (i) already public through no fault of the Receiving Party, (ii) independently developed without reference to the Confidential Information, (iii) required to be disclosed by applicable law or court order (with prior notice to Disclosing Party).

Governing Law: French law — Tribunal de Commerce de Paris.

To execute this agreement: [email protected]