Sovereignty · Privacy · Compliance

Your data stays where your rules require.

Pipeline integrity data describes critical national infrastructure. Axoveris is a France-based company — and PIMARIS is built so operators keep full sovereignty over their data: legally, geographically and technically.

Made in France · EU jurisdiction
Why it matters

Integrity data is infrastructure data

An ILI run is a map of where a pipeline is weakest. In the wrong hands it is a liability; under foreign jurisdiction it is a loss of control. For European operators — and for the regulators who oversee them — where that data lives, and whose law governs it, is not a detail. It is a requirement.

Sovereign hosting

Run PIMARIS on French & EU sovereign infrastructure

PIMARIS can be deployed on SecNumCloud-qualified, EU-jurisdiction cloud — operated under EU law and insulated from extraterritorial non-EU legislation. We work with the recognised French sovereign-cloud providers.

SecNumCloud

S3NS — Thales & Google Cloud

A French sovereign-cloud joint venture between Thales and Google Cloud, building a SecNumCloud-qualified platform operated by a French company under French law.

SecNumCloud

OVHcloud

A French cloud provider with SecNumCloud-qualified infrastructure and European data centres — a long-standing sovereign option.

SecNumCloud

3DS OUTSCALE

The Dassault Systèmes cloud, SecNumCloud-qualified, designed for sensitive and regulated workloads.

EU sovereign

Scaleway & others

Additional SecNumCloud and EU-sovereign options can be matched to your procurement framework on request.

SecNumCloud is the French national cybersecurity agency (ANSSI) qualification for trusted cloud — the most demanding sovereign-cloud benchmark in Europe. Partner availability is confirmed per engagement.

Compliance, by region

Mapped to where you operate

Pipeline operators answer to different rules in different jurisdictions. PIMARIS deployments are matched to the framework that governs you — France first, then the EU, then the United States.

European Union

One market, one set of rules

Across the EU, PIMARIS keeps data in-region and aligns with the directives that govern critical-infrastructure operators.

  • EU data residency, operated under EU law
  • GDPR compliance by design
  • Aligned with the NIS2 cybersecurity directive
  • Insulated from extraterritorial data-access law
United States

Built for US operators too

For operators in the United States, PIMARIS deploys on FedRAMP-aligned infrastructure and supports the federal pipeline-security and reporting regimes.

  • FedRAMP-aligned hosting (e.g. AWS GovCloud)
  • Supports TSA pipeline security directives
  • PHMSA reporting — 49 CFR Parts 192 / 195
  • On-premise option for the strictest requirements
On-premise

Or run it entirely on your own infrastructure

For operators who require it, PIMARIS deploys fully on-premise — inside your own data centre, behind your own firewall, air-gap capable. On an on-premise deployment your integrity data never leaves your network, and never reaches Axoveris.

  • Deployed inside your own environment
  • Air-gap capable — no outbound connection required
  • You own the infrastructure and the keys
  • Hybrid options where only sensitive data stays in-house
Your data centre · Your keys
Privacy

Privacy by design, aligned with the GDPR

PIMARIS is built to the GDPR from the foundation — not retrofitted to it.

Data minimisation

PIMARIS collects what integrity work needs and no more. Personal data is limited to the user accounts that operate the system.

You own your data

Your pipeline, inspection and assessment data belongs to your organisation — exportable, and deletable, on your terms.

Clear processing boundary

Roles, purposes and the processing boundary are defined and contractual — no ambiguity about who touches what.

Security

Security woven through the platform

Security in PIMARIS is built in — and the controls leave a trail.

Encryption in transit & at rest

Data is encrypted on the wire and in storage, so a copy of the disk is not a copy of the data.

Role-based access control

Admin, editor and viewer roles scope every action. People see and change only what their role allows.

Immutable audit trail

Every change is written to a hash-chained audit log — tamper-evident, and built for a regulator to inspect.

Authenticated sessions

Short-lived access tokens and an HttpOnly refresh cookie keep sessions safe without standing credentials in the browser.

Tenant isolation

A tenant boundary is threaded through every record and every query — your data is your data.

Hardened operations

Structured logging, observability and a tested backup & restore runbook keep the deployment dependable.

Discuss a sovereign deployment

Tell us your data-residency and compliance requirements — we will map PIMARIS to them.