Data security
Withings is committed to maintaining a secure environment that enables you to use our products and services. We protect your personal data through compliance with multiple standards (ISO 27001:2022, ISO 27701:2019 & HDS).
Certifications & Standards
To factor data privacy into our products and services, we strive for the highest standards of personal data protection.
ISO 27001
Withings provides the service of a hosting provider in accordance with the requirements of the International Organization for Standardization 27001 standards.
It includes all systems, people and processes involved in the design, development, operations, validation and support of applications and services hosted by Withings and especially the processing of personal health data.
HDS
Health Data Hosting — version 1.1 final - May 2018 for activities 1 to 6 in accordance with the certification reference system provided by ASIP Santé.
Includes all systems, people and processes involved in the design, development, operations, validation and support of applications and services hosted by Withings which include the processing or disclosure of personal health data.
In accordance with the HDS reference system, you can consult the table of representations of guarantees concerning our activities as a subcontractor via this link.
ISO 27701
Withings demonstrates its capacity to follow the state of the art in terms of Privacy protection worldwide (such as GDPR). In order to do so, internal processes are continuously audited to ensure that Privacy protection is taken into account at each step of activities (internal or external) conducted by Withings.
Services & applications security
We deliver, maintain and manage data protection in our applications, products and services across all stages of their lifecycle.
Framework security controls
Withings relies on modern security control techniques to limit exposure to the top 10 OWASP security risks. These inherent controls reduce our exposure to SQL Injection (SQLi), Cross Site Scripting (XSS), and Cross Site Request Forgery (CSRF), among others.
Agile organization, code review and testing
All development activities are organized using the AGILE method, with the establishment of sprints and prioritization of tasks with the Product Manager team. All sprints are historized. Developers perform unit tests, functional integration tests, and security tests. Features are reviewed by the Security Team and evaluated through peer reviews before deployment.
Software Quality Assurance
The Software Quality Assurance department tests services and applications before going to production (manual and automatic tests).
Environments separations and test data
The development and test environments are logically separated from the production environment. No personal production data is used in our development or test environments.
Infrastructure protection
Since protection of data is part of how we take care of our users, we call upon the best security solutions to protect personal data.
Physical facilities
For B2C activities and B2B activities in Europe, Withings hosts its servers thanks to BSO in data centers located in France. To ensure 24/7 operation and constant availability of services, BSO data centers are equipped with redundant power systems and are subject to environmental controls.
For B2B activities in the US, Withings hosts its servers thanks to GCP in data centers located in the US. To ensure 24/7 operation and constant availability of services, Google data centers are equipped with redundant power systems and are subject to environmental controls.
On site security
BSO and GCP data centers are designed with a multi-layered security model that includes custom-designed electronic access cards, alarms, vehicle access control barriers, security fencing, metal detectors, and biometric technologies. Each data center is also equipped with a laser beam intrusion detection system. The data centers are monitored 24 hours a day, 7 days a week using high-resolution indoor and outdoor cameras that can detect and track intruders.
HR Security
The limited staff that handles data in the Withings Cloud is subject to regular vetting and continuous training on how to mitigate the risks involved in processing personal data.
Background and competency checks
Withings conducts background checks on all new employees in accordance with local laws. These checks are also performed for contractors. Background checks may include technical and general skills, previous employment, and criminal record checks if required.
Confidentiality agreement
All employees must sign non-disclosure and confidentiality agreements. This confidentiality agreement remains valid after the end of the employment contract.
Role and responsibilities definition
Withings ensures that all roles and responsibilities are well defined and understood by the individuals to which they are assigned.
Disciplinary procedure
Withings has put disciplinary procedures in place in the event of a breach of entrusted responsibilities, based on a scale of sanctions defined in the internal regulations.
Continuous improvement
As an innovative IoT company, we make sure that we are always one step ahead of current data protection standards. This is supported by regular internal and external audits.
Internal audit plan
All processes are audited by internal audit teams or by external service providers.
Management review
Management reviews ensure that the management systematically reviews ISMS, assesses opportunities for improvement, and decides on the measures necessary to ensure the relevance, adequacy, and effectiveness of ISMS.