LEGAL
Information Security Policy
Effective date: July 01, 2026
DELIVERA S.R.L. establishes this Information Security Policy as the apex document of its Information Security Management System (ISMS). It formalises Top Management’s commitment to safeguarding the confidentiality, integrity, and availability of all information assets and serves as the authoritative reference against which all personnel align their conduct when handling organisational information.
1. Purpose
This policy articulates the strategic direction for information security across the organisation, enshrining principles that guide the full suite of subordinate policies, procedures, and operational controls — including those protecting the proprietary AI-driven platform, client data processed during investment and M&A workflows, and the cloud infrastructure that underpins service delivery.
2. Field of application
This policy applies to all personnel, collaborators, and external parties who access, process, or manage information assets owned or controlled by DELIVERA S.R.L. It covers the operational office in Milan, all remote work locations, and every cloud-hosted system and service in the organisation’s technology stack. The scope encompasses all information in any format — digital or verbal — regardless of classification level, and extends to personal devices used to access organisational resources.
3. Regulatory references
ISO/IEC 27001:2022
ISO/IEC 27002:2022
GDPR
4. Guiding principles and commitments
The organisation adopts the following guiding principles as the foundation of every security decision and control:
Risk-based approach — identifying, assessing, and treating risks proportionate to their potential impact on business objectives, client data, and service continuity.
Shared responsibility — every individual with access to organisational information bears personal accountability for protecting it.
Defence in depth — layered administrative, technical, and organisational controls so no single point of failure can compromise information assets.
Least privilege and need-to-know — access granted only to the extent required for legitimate duties and reviewed at planned intervals.
Continual improvement — evaluating ISMS effectiveness at regular intervals and incorporating lessons learned.
Legal and contractual compliance — satisfying all applicable obligations relating to information security and data protection.
5. Information security objectives
Top Management establishes that the ISMS pursues the following strategic objectives, measured and reviewed as part of the management review cycle:
Protect client M&A and investment research data from unauthorised disclosure, ensuring it is never exposed to other clients or used beyond the agreed scope.
Maintain the availability and resilience of cloud-hosted services.
Ensure all personnel understand their security responsibilities through awareness, training, and adherence to documented policies.
Adopt and maintain robust cryptographic controls for confidential and limited information at rest and in transit.
Systematically identify and remediate vulnerabilities before they can be exploited.
Preserve compliance with GDPR and contractual data-protection obligations throughout the information lifecycle.
6. Acceptable use of information and assets
Information and associated assets are used exclusively for legitimate business purposes and in a manner consistent with their assigned classification. Personnel access information only in accordance with their authorised role and the principle of least privilege; any access beyond assigned duties requires prior authorisation. Handling follows the classification level:
Public — may be shared without restriction.
Limited — processed only on managed or approved systems, transmitted over encrypted channels, and stored within EU-region cloud services with AES-256 encryption at rest.
Confidential — accessed strictly on a need-to-know basis, processed only within production-tier environments with AES-256 encryption at rest, and transmitted through controlled, monitored channels with mandatory TLS.
7. Clear desk and clear screen
Devices used to access organisational information lock automatically after five minutes of inactivity and require re-authentication; personnel lock their devices manually whenever leaving their workstation. No documents, notes, or removable media containing limited or confidential information are left visible in unattended work areas — whether in the office or at remote locations — and are securely stored or disposed of at the end of each session.
8. Reporting of information security events
All personnel and collaborators report any observed or suspected information security event as soon as practicable — including suspected unauthorised access, unusual system behaviour, data leakage, phishing attempts, and loss or theft of devices. The primary reporting channel is direct notification to the Management System Manager, complemented by automated monitoring tools that detect anomalies in real time. Every individual is empowered — and obliged — to raise concerns without fear of reprisal.
9. Security of off-site assets
Personnel comply with information security requirements when working remotely as though operating within the office. Antivirus software is active on every device with automatic updates and periodic scans; external network connections require an up-to-date software firewall; and remote access relies on company-approved tools configured for multi-factor authentication. Personnel do not modify or disable organisational security controls, change default settings on home Wi-Fi networks, and use encrypted connections for limited or confidential information.
10. Review and continual improvement
This policy is reviewed at planned intervals and whenever significant changes occur in the organisational context, risk landscape, regulatory environment, or technology stack. Inputs include audit results, incident trends, changes in legal or contractual requirements, and performance against the objectives above. It is reviewed at least annually, and any revision is approved by Top Management before publication and communication to all relevant parties.
11. Contact
For questions about this policy, email support@delivera.ai.
