Skip to content
Trust

Security and compliance

How we protect our clients' information, which frameworks we work with, and how we answer vendor due diligence.

Much of our work happens in capital markets, banking and asset management, where technology is bought against evidence. Our security management is therefore not a statement of intent: it is a live body of documentation, approved by senior management and tested, which we hand over when a client asks for it.

Reference frameworks

Three management systems, each with its own reference standards.

Information security

Management system built and operated in line with ISO/IEC 27001:2022, supported by the NIST Cybersecurity Framework and CIS Controls v8.

Business continuity

In line with ISO 22301 and ISO 31000, with Business Continuity Institute good practice. Includes business impact analysis and a contingency plan.

Operational risk

In line with ISO 31000 and the regulations of Chile's supervisory bodies, with the Basel III references the financial sector requires.

Management framework and certification

The management framework is built and operated in line with ISO/IEC 27001 and with the continuity standard, with documented policies, plans and procedures, approved by senior management, current and tested. We answer contractually for what we declare in that documentation and hand it over when a due diligence process asks for it. On that basis, ISO/IEC 27001 certification is under way.

The team also holds current professional certifications: Scrum Developer, Scrum Product Owner, Scrum Professional and FinOps Certified Practitioner.

Vendor due diligence

We answer the risk maturity self-assessments that risk and procurement teams send, across their three usual domains: information security and cybersecurity, business continuity and operational risk. Every answer is referenced to the policy, plan or procedure behind it, document by document. We have done this for clients in capital markets and banking.

How we handle your information

Least-privilege access

We work with the client's standards and, where appropriate, inside their own environments, with just the access the work requires and traceability of who does what.

Separate environments

Certification and production are separate environments. Testing runs against the agreed test plan, and the move to production requires the client's formal validation.

Confidentiality agreements

We have our own NDA template and also work with the client's, reviewed by our legal team. The agreement covers the team assigned to the project, not only the company.

Personal data

Personal data handling follows our privacy policy and Chile's Law 21.719, including consent management across digital channels.

Artificial intelligence and data

The standard is the same one already applied to corporate email or any industry cloud service: we use enterprise plans whose terms exclude client content from model training, access is limited to what is needed, and data handling is written into the contract. When data cannot leave the organization, the alternative is to deploy a local model on the client's own infrastructure and orchestrate the solution just as with a cloud model.

Continuity and service levels

The business impact analysis defines recovery objectives per service, and the operation is backed by a contingency site and backups. Support runs on a severity model, with business-hours coverage for general operation and 24x7 for critical incidents. Response and restoration times, committed availability and maintenance windows are set in each contract's service level annex.

Data residency

When data resides outside the client's territory, that circumstance is declared explicitly to the client and, where applicable, to their regulator. For clients whose internal policy requires it, we offer a dedicated instance with independent application, services and database.

More answers on security and contracts

Need our documentation for a due diligence process?

Write to us and we will arrange the delivery of the documentation your risk or procurement team needs, under a confidentiality agreement.