1. Purpose
FIVO AI, S.L. has approved this Information Security Policy to set out the principles and guidelines that ensure the security of the information it handles, manages, processes and stores, in terms of confidentiality, authenticity, traceability, integrity, availability and preservation.
Its purpose is to reinforce FIVO AI's commitment to its employees, partners and customers through continuous service improvement, compliance with applicable legislation, improvement of internal processes and protection of information across all stages of its life cycle: generation, distribution, storage, processing, transport, consultation and destruction.
2. Information Security Policy and Objectives
To ensure a comprehensive security framework, FIVO AI adopts measures to prevent, detect, respond to and recover from incidents that may affect the information managed by the platform. The established security objectives are:
- Confidentiality: ensure that sensitive information — including meetings, audio recordings and transcripts — is only accessible to authorized personnel.
- Integrity: protect data and transcripts against unauthorized alteration, modification or destruction, through version control and change logs.
- Availability: ensure systems, networks and data are accessible when authorized users need them, with backups and a continuity plan.
- Regulatory compliance: comply with applicable national and international regulations (GDPR, ISO 27001:2022, LOPDGDD, SOC 2 Type II).
- Threat prevention and response: mature procedures to act on cyberattacks and insider threats.
- Risk management and continuity: minimize operational risks through ongoing assessment and ensure operations continue even during incidents.
- Security culture: foster good data protection practices across all staff, with regular training.
- Personal data protection: comply with the GDPR and LOPDGDD through data minimization, secure deletion and retention controls.
- Secure transmission: encrypt communications (HTTPS, VPN where applicable) and use secure exchange platforms.
- Access control: ensure only authorized people have access, through strong authentication (MFA), identity management and timely access revocation.
- Remote workspace protection: secure work devices with antivirus/EDR, encrypted disks and trusted networks.
- Continuous risk management: identify, assess and treat security risks on an ongoing basis.
- Incident detection and response: log incidents and apply rapid response procedures for unauthorized access, leaks or errors.
These objectives are measurable and reviewable. A few specific commitments:
- 100% of access to critical systems requires multi-factor authentication (MFA).
- Reduce information leakage incidents caused by human error to zero.
- Delete customer data within a maximum of 90 days after service termination.
3. Regulatory Framework
This Policy sits within the legislation and regulations in force regarding information processing and security. It is based on the following reference standards:
- ISO 27001:2022 — Information security management systems (requirements).
- ISO 27002:2022 — Code of practice for information security management.
- ISO 42001 — Artificial intelligence management.
- Regulation (EU) 2016/679 (GDPR) — Protection of natural persons with regard to the processing of personal data.
- Spanish Organic Law 3/2018 (LOPDGDD) — Personal Data Protection and Guarantee of Digital Rights.
FIVO AI aligns its Information Security Management System (ISMS) with ISO 27001:2022 and ISO 27002:2022.
4. Information Security Organization
Information asset security is the responsibility of every department at FIVO AI and of each person who interacts with these assets. Management appoints the positions and individuals who carry out security functions, in particular the Information Security Officer (CISO):
- Sets information security requirements and oversees the proper use and protection of information.
- May designate competent individuals to carry out operational security functions.
- Makes the decisions needed to meet security requirements and verifies that the implemented measures are adequate.
- Promotes periodic reviews, training and awareness across the organization.
5. Information Security Core Principles
FIVO AI grounds its security activities in the following core principles:
- Security as an integral process: encompassing all human, material, technical, legal and organizational elements related to the information assets.
- Security by default and by design: present at every stage of the information systems life cycle.
- Proportionality: measures balanced against risk, criticality and the value of the information and services.
- Legal and contractual compliance: respecting the legal and contractual requirements applicable to information and systems.
- Risk-based management: an ongoing, continuously updated activity that reduces risks to acceptable levels.
- Prevention, detection, response and recovery: measures to reduce the impact of threats and respond promptly and properly.
- Defense in depth: multiple organizational, physical and logical layers, so that the compromise of one layer does not compromise the entire system.
- Continuous monitoring and periodic reassessment: detection of anomalous activity and periodic update of the measures in place.
- Separation of responsibilities: distinguishing the asset owner, the security officer and the system owner.
- Awareness and training: every user and administrator must be trained for the proper use of information systems.
- Professional secrecy: duty of confidentiality, even after activities related to FIVO AI have ended.
6. Minimum Information Security Requirements
FIVO AI commits to meeting the following minimum security requirements:
- Organization of the security process: unambiguous identification of the CISO and System Owner, with clear responsibilities, segregation of duties and communication across the organization.
- Asset control: information assets are inventoried and categorized according to their characteristics and required security level; security measures match this categorization.
- Risk analysis and management: an ongoing process aligned with ISO 27001:2022, repeated at least annually and whenever the information handled changes or a major incident occurs.
- Personnel management: all internal and external personnel receive training and information about their security duties and responsibilities.
- Professionalism: system security is implemented, monitored, reviewed and audited by qualified personnel throughout the system life cycle.
- Access authorization and control: asset access is limited to duly authorized users, processes and devices; access to customer information is segregated.
- Procurement of products and services: products and services are selected with certified security functionality or that meet pre-established quality criteria.
- Least privilege: systems are designed and configured to provide only the essential functionality, with especially strict controls on administration and monitoring.
- Integrity and updating of systems: development and maintenance include security specifications and formal change, configuration and update management processes.
- Protection of stored and in-transit information: measures applied to laptops, mobile devices, peripherals, storage media and communications over open networks.
- Prevention from interconnected systems: interconnections with external systems, especially through public networks, are analyzed and the corresponding risks mitigated.
- Activity logging and malicious code detection: user activity is logged and personal accounts are used wherever possible, to investigate and manage unlawful or risky situations.
- Incident and personal data breach management: comprehensive procedures aligned with ISO 27001:2022 and the GDPR, including notification to CSIRTs, supervisory authorities and affected users when applicable.
- Business continuity: recovery measures and plans are in place to ensure continuity of operations during disruptive events.
- Audit and continuous improvement: information systems undergo regular ordinary audits at least once a year, plus extraordinary audits in case of substantial changes or major incidents.
7. Personal Data Processing
FIVO AI only collects personal data that is adequate, relevant and not excessive in relation to the purposes for which it is obtained, and adopts the technical and organizational measures required to comply with applicable data protection law (GDPR and LOPDGDD).
As Data Controller, FIVO AI documents and keeps up to date the Record of Processing Activities (RoPA) in accordance with article 30 of the GDPR.
8. Personnel Obligations
All personnel and any person with a direct or indirect professional relationship with FIVO AI must comply with this Policy and with the specific regulations that develop it.
The Information Security Officer organizes regular training and awareness sessions to help everyone understand the security measures and the specific rules that develop them.
Manifest non-compliance, whether by internal staff or external collaborators, may trigger the appropriate disciplinary actions and, where applicable, any corresponding legal liability.
9. Third Parties
When FIVO AI provides services to or handles information of other organizations, it shares this Policy with them and sets up channels to coordinate with their respective Information Security Committees, along with incident response procedures.
When FIVO AI uses third-party services or shares information with third parties, it provides them with the internal regulations on supplier security management. The third party is bound by the obligations established and may develop its own procedures to meet them.
Third-party personnel are guaranteed to be properly aware of information security matters, at least at the same level as that established in this Policy.
10. Implementation of the Policy
This Policy is complemented by the Information Security Management System (ISMS) through the policies, regulations and procedures established for that purpose, in line with ISO 27001:2022 best practices. The security regulations are made available to every member of FIVO AI who needs to know them.
11. Policy Review
This Policy is kept up to date over time. It is reviewed on a regular annual basis, and on an extraordinary basis whenever changes occur in strategic objectives or applicable legislation, through a proposal made by FIVO AI's Information Security Committee.
12. Communication and Distribution
Changes to this Policy are communicated to all individuals and interested parties, in line with ISO 27001:2022 and ISO 27002:2022. Each member of the organization is responsible for reading and understanding it, as well as the rest of the regulations that make up the ISMS.
13. Changes to Security Regulations
When FIVO AI determines that changes to its ISMS are needed, those changes are carried out in a planned manner and communicated to interested parties. Changes affecting employees are notified by email by Management or the IT department.
14. Non-Compliance with the Policy
This document is part of the internal regulations of FIVO AI, S.L. No user shall act on requests, instructions or orders contrary to FIVO AI's internal regulations, nor invoke them to justify any non-compliance. Exceptions only apply to duly justified requirements from administrative, inspection or judicial authorities.
Non-compliance may be sanctioned with the suspension of access to the organization's information and IT systems, as well as disciplinary actions in accordance with this Policy, without prejudice to any other legal liability the offender may incur.