LEGAL

Management System Policy

Effective date: July 01, 2026

DELIVERA S.R.L. establishes this Management System Policy as the apex expression of Top Management’s commitment to information security. It provides the strategic direction and guiding framework within which information security objectives are set, reviewed, and pursued across the organisation.

1. Purpose

This policy articulates the organisation’s intent to protect the confidentiality, integrity, and availability of all information assets — encompassing the proprietary agentic AI platform, client data processed during investment and M&A workflows, and the cloud infrastructure on which service delivery depends. It ensures that the Information Security Management System (ISMS) remains appropriate to DELIVERA S.R.L.’s purpose, context, and business model.


2. Field of application

This policy applies to all personnel, collaborators, and external parties who access, process, or manage information assets owned or controlled by DELIVERA S.R.L. It covers the operational office in Milan, remote work locations, and every cloud-hosted system and service forming part of the organisation’s technology stack. The scope encompasses the design, development, and delivery of a proprietary SaaS platform leveraging AI technologies. Physical data centres, server rooms, and networking hardware are excluded, as the organisation relies entirely on cloud service providers and personal computing devices.

3. Regulatory references

ISO/IEC 27001:2022

Regulation (EU) 2016/679 (GDPR)

D.Lgs. 196/2003

Directive (EU) 2022/2555 (NIS 2)

Regulation (EU) 2024/1689 (AI Act)


4. Organisational context and strategic direction

DELIVERA S.R.L. operates within the investment-technology sector, providing AI agents that automate research, analysis, and document production for investment teams and M&A professionals. As a micro-enterprise, it concentrates decision-making within Top Management and maintains a lean governance structure that facilitates rapid policy implementation. The organisation operates on a fully cloud-native architecture, relying on qualified third-party providers for compute, storage, AI inference, and delivery.

Client expectations regarding data confidentiality are exceptionally high, as the platform processes commercially sensitive deal information, financial statements, and proprietary research. Top Management acknowledges that any weakness in information security directly affects client acquisition and retention, and has committed to a management system that responds proactively to the evolving external and internal context.


5. Information security commitments

Through this policy, Top Management formalises the following commitments, which guide all subordinate policies, procedures, and operational controls within the ISMS:

  • Appropriateness to purpose — maintaining an ISMS proportionate to the nature and sensitivity of the information processed.

  • Satisfaction of applicable requirements — legal, regulatory, and contractual, including data protection, cybersecurity, and AI governance obligations.

  • Risk-based decision-making — a structured, repeatable methodology so resources are allocated where exposure is greatest.

  • Shared responsibility — every individual with access to organisational information bears personal accountability for protecting it.

  • Defence in depth — a layered architecture so no single point of failure can compromise information assets.

  • Data segregation and confidentiality — client M&A data is logically isolated and never exposed to other clients or used beyond the agreed scope.

  • Continual improvement — evaluating the ISMS at regular intervals and incorporating lessons learned from incidents, audits, and technological evolution.


6. Framework for information security objectives

This policy provides the framework within which measurable objectives are established, monitored, and reviewed at relevant functions and levels. At a minimum, objectives address:

  • Protection of client investment and M&A research data from unauthorised disclosure, with strict data segregation across client workspaces.

  • Availability and resilience of cloud-hosted services, minimising interruptions that could impair client decision-making workflows.

  • Competence and awareness of all personnel regarding their security responsibilities.

  • Adoption of robust cryptographic controls to protect confidential and limited information at rest and in transit.

  • Systematic identification and remediation of vulnerabilities before they can be exploited.

  • Preservation of compliance with data protection and contractual obligations throughout the information lifecycle.


7. Communication and availability

This policy is maintained as documented information and classified as public, enabling unrestricted distribution to both internal and external audiences. Internally, it is communicated to all personnel and collaborators. Externally, it is made available to interested parties — including clients, cloud service providers, regulatory authorities, and the certification body — so they can assess the organisation’s commitment to information security.

8. Review and continual improvement

Top Management reviews this policy at planned intervals — and whenever significant changes occur in the organisational context, risk landscape, regulatory environment, or technology stack — to confirm its continued suitability, adequacy, and effectiveness. When a review identifies that the policy no longer reflects the organisation’s context or risk profile, a revision cycle is initiated. It is reviewed at least annually; superseded versions are retained with their original approval and supersession dates preserved.


9. Contact

For questions about this policy, email support@delivera.ai.

Start automating tasks today. Let your team focus on what matters.

Start automating tasks today. Let your team focus on what matters.

Start automating tasks today. Let your team focus on what matters.