Security and compliance
How we protect our clients' information, which frameworks we work with, and how we answer vendor due diligence.
Much of our work happens in capital markets, banking and asset management, where technology is bought against evidence. Our security management is therefore not a statement of intent: it is a live body of documentation, approved by senior management and tested, which we hand over when a client asks for it.
Reference frameworks
Three management systems, each with its own reference standards.
Information security
Management system built and operated in line with ISO/IEC 27001:2022, supported by the NIST Cybersecurity Framework and CIS Controls v8.
Business continuity
In line with ISO 22301 and ISO 31000, with Business Continuity Institute good practice. Includes business impact analysis and a contingency plan.
Operational risk
In line with ISO 31000 and the regulations of Chile's supervisory bodies, with the Basel III references the financial sector requires.
Management framework and certification
The management framework is built and operated in line with ISO/IEC 27001 and with the continuity standard, with documented policies, plans and procedures, approved by senior management, current and tested. We answer contractually for what we declare in that documentation and hand it over when a due diligence process asks for it. On that basis, ISO/IEC 27001 certification is under way.
The team also holds current professional certifications: Scrum Developer, Scrum Product Owner, Scrum Professional and FinOps Certified Practitioner.
Vendor due diligence
We answer the risk maturity self-assessments that risk and procurement teams send, across their three usual domains: information security and cybersecurity, business continuity and operational risk. Every answer is referenced to the policy, plan or procedure behind it, document by document. We have done this for clients in capital markets and banking.
How we handle your information
Least-privilege access
We work with the client's standards and, where appropriate, inside their own environments, with just the access the work requires and traceability of who does what.
Separate environments
Certification and production are separate environments. Testing runs against the agreed test plan, and the move to production requires the client's formal validation.
Confidentiality agreements
We have our own NDA template and also work with the client's, reviewed by our legal team. The agreement covers the team assigned to the project, not only the company.
Personal data
Personal data handling follows our privacy policy and Chile's Law 21.719, including consent management across digital channels.
Artificial intelligence and data
The standard is the same one already applied to corporate email or any industry cloud service: we use enterprise plans whose terms exclude client content from model training, access is limited to what is needed, and data handling is written into the contract. When data cannot leave the organization, the alternative is to deploy a local model on the client's own infrastructure and orchestrate the solution just as with a cloud model.
Continuity and service levels
The business impact analysis defines recovery objectives per service, and the operation is backed by a contingency site and backups. Support runs on a severity model, with business-hours coverage for general operation and 24x7 for critical incidents. Response and restoration times, committed availability and maintenance windows are set in each contract's service level annex.
Data residency
When data resides outside the client's territory, that circumstance is declared explicitly to the client and, where applicable, to their regulator. For clients whose internal policy requires it, we offer a dedicated instance with independent application, services and database.
Need our documentation for a due diligence process?
Write to us and we will arrange the delivery of the documentation your risk or procurement team needs, under a confidentiality agreement.