
Keeping Vital Business Processes Executable When Primary Systems Fail
Astran is a French enterprise-resilience company founded in 2021 by Yosra Jarraya, Gilles Seghaier and Yahya Jarraya, addressing what happens after a cyberattack or major outage halts core systems. Its AlwaysReady platform serves large organisations — the company names Sanofi, VINCI, Eiffage and Elior among its customers — and is bought jointly by treasury, operations and security leaders. The buying centre is deliberately cross-functional: CFOs and COOs own the vital activities, while the CISO validates the independent execution architecture.
The approach centres on a framework the company calls the Minimum Vital Company: an ExCom-level definition of non-negotiable activities, the step-by-step processes that deliver them, and the datasets those processes need. Data is synced from existing systems over APIs, then split using AONT-RS cryptographic fragmentation and distributed as immutable fragments across independent cloud providers, so no single provider or key can reconstruct it. During a disruption, teams execute guided workflows with role-based access controls on infrastructure that does not depend on the affected estate.
What separates this from backup, disaster recovery and traditional continuity planning is the emphasis on execution rather than documentation: processes run end-to-end during the incident, with every action immutable, versioned and auditable for regulators. Deployment is scoped in weeks, typically starting with treasury and payments before expanding to other vital activities. The patented architecture is reviewed by a scientific committee including cryptographers Nigel Smart and Ludovic Perret, the platform is SOC 2 Type II certified with ISO 27001 in progress, and the company has collected several European cybersecurity innovation awards.



