Information Security Policy.
ISO/IEC 27001 · ISO/IEC 27017 · ISO/IEC 27018
Our company was founded on a clear conviction: our customers’ trust is our most precious asset. Every line of code we write, every service we provide and every piece of data entrusted to us carries an enormous responsibility. This is not just about regulatory compliance: it is about respect, ethics and protecting the people who place their trust in us.
That is why we have adopted an Information Security Management System based on ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018, committing ourselves every day to the principles of transparency, accountability and continual improvement.
Our fundamental commitments
- Protecting data as if it were our own: we safeguard our customers’, partners’ and employees’ data with the utmost care, without compromise.
- Compliance and accountability: we comply with laws, contracts and regulations, but go further, because security is more than a legal obligation: it is a moral duty.
- A risk-based approach: we continually assess threats and adapt our defences to stay one step ahead.
- Transparency: we communicate openly with our stakeholders about how we manage security and protect data.
- A shared culture: security is not an IT department task, but a responsibility we all share.
How we turn these commitments into concrete actions
- We maintain an ISMS compliant with ISO/IEC 27001: we assess risks, define controls, monitor incidents and continually measure the effectiveness of the measures we adopt.
- We apply cloud-specific security controls (ISO/IEC 27017), protecting infrastructure, APIs and data through segmentation, secure access management and ongoing supplier verification.
- We ensure the protection of personal data in the cloud (ISO/IEC 27018), making sure it is processed only for the agreed purposes, securely deleted when no longer needed and never misused.
- In the event of an incident, we are ready to detect, contain and communicate it promptly and transparently, learning from every event to strengthen our protection further.
- We invest in training and awareness: we want everyone in the company to understand their role in security.
Our message to stakeholders
Information security is not a cost or a bureaucratic obligation, but an essential condition for ensuring innovation, continuity and lasting value. We therefore ask everyone — employees, suppliers, partners and customers — to share this responsibility with us, because security only works when everyone shares and applies it.
Continual improvement
This Policy is not a static document: it is reviewed every year or whenever the regulatory, technological or organisational context changes. Our commitment is to continually improve our processes so that security always keeps pace with the challenges of the digital world.