INFORMATION SECURITY POLICY

Valid from: March 1, 2025

 

We consider the complex provision of information security (IS) to be a necessary condition for maintaining data confidentiality and uninterrupted operation of the AppQuantum website and mobile applications (collectively, the "Product").

 

For the effective implementation of information security processes, we have implemented an information security management system that meets the requirements of the international standard ISO/IEC 27001:2022. In matters of personal data protection, we are guided by the principles of international standards and best practices, such as ISO/IEC 27701:2019, GDPR, CCPA. Information security processes are an integral part of information technology management processes and associated operational risks for us and are carried out on the basis of a cyclical model of change management: "Plan-Do-Check-Act".

 

Our main goals in the scope of information security:

 

  • information security risk management, which allows for the smooth execution of business processes and the provision of services;
  • provision of a secure information environment for the functioning and development of internal business processes and services provided;
  • ensuring the integrity, confidentiality and availability of the data processed by the Company, including personal data.

 

The principles that we adhere to when planning, providing and improving information security:

 

  • compliance with the requirements of applicable legislation;
  • adequacy and economic validity of the applied protection measures;
  • minimization of the limiting impact of applied information security measures on business processes;
  • continuity of operation and improvement;
  • personal responsibility;
  • control of fulfillment of requirements in the scope of information security.

 

Tasks that we solve during the planning, provision and improvement of information security:

  • proactive cybersecurity of all aspects related to the Product and development processes;
  • prevention and prompt investigation of information security incidents;
  • personal responsibility of each employee for the performance of the functions and requirements assigned to them within the scope of the information security.

The management of AppQuantum guarantees the provision of conditions and resources for the implementation of the information security policy.