Information Security

Information Security Policy

Table of Contents

  1. Purpose
  2. Scope
  3. Normative References
  4. Terms and Definitions
  5. Roles and Responsibilities
  6. Information Security Objectives
  7. Fundamental Information Security Principles
  8. Protection of Off-site Assets
  9. Archiving and Updating
  10. Reference Documents

Purpose

This policy declares and communicates the commitment of DEEPTREE S.r.l.'s Top Management to the protection of the organization's information assets. The document constitutes the framework for establishing, implementing, maintaining, and continually improving the Information Security Management System (ISMS), with the objective of preserving the confidentiality, integrity, and availability of information processed within the scope of designing, developing, and delivering the proprietary SaaS platform.

DEEPTREE S.r.l. recognizes that information security represents a strategic factor for its positioning in the financial intelligence market and for the trust of clients — private equity funds, M&A advisors, and search funds — who entrust sensitive data and critical decision-making processes to the organization. This policy therefore establishes the guiding principles, objectives, and responsibilities that direct all other ISMS policies and procedures, ensuring consistency with corporate strategic directions and the requirements of ISO/IEC 27001:2022.

Scope

This policy applies to all activities, processes, information assets, technological systems, and premises of DEEPTREE S.r.l., including the registered office in Via Sangallo 5, Milan, and the operational office in Piazza Aspromonte 26, Milan. It involves all personnel — employees, contract collaborators, and third parties — who access corporate information or systems, regardless of the working mode (on-site or remote) and geographical location.

The scope specifically includes the cloud infrastructure on Google Cloud Platform, source code repositories, CRM systems, collaboration platforms, email, and any company device assigned to personnel. Physical protected areas (server rooms, reserved physical archives) are excluded from the scope, as the entire IT infrastructure is cloud-based and the organization does not have its own data centers.

Normative References

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • Regulation (EU) 2016/679 (GDPR)

Terms and Definitions

  • Information Security : preservation of confidentiality, integrity, and availability of information.
  • Confidentiality : property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
  • Integrity : property of accuracy and completeness of information. Availability : property of being accessible and usable on demand by an authorized entity.
  • Information Security Management System (ISMS) : part of the overall management system, based on a risk approach, for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving information security.
  • Risk : effect of uncertainty on objectives.
  • Information Security Event : identified occurrence of a system, service, or network state indicating a possible breach of information security policy or a failure of controls, or a previously unknown situation that may be relevant to security.
  • Information Security Incident : one or more unwanted or unexpected information security events that have a significant probability of compromising business operations and threatening information security.
  • Asset : any item that has value to the organization.

Roles and Responsibilities

  • Top Management : approves this policy, ensures the necessary resources for the ISMS, and promotes continuous improvement of information security.
  • Management System Manager : oversees the implementation of the ISMS, coordinates documentation and risk management, performs internal audits, and reports to Top Management on system performance.

Information Security Objectives

DEEPTREE S.r.l. pursues security objectives consistent with its mission to provide reliable financial intelligence tools and with the requirements of interested parties. The objectives, measurable and periodically reviewed during management review, are articulated as follows:

  • Protect the confidentiality of client data and the platform's source code, ensuring that access is limited to authorized personnel based on the principle of least privilege.
  • Ensure the integrity of information extracted and structured by the SaaS platform, so that client decision-making processes rely on accurate and complete data.
  • Ensure the continuous availability of cloud services, minimizing downtime through business continuity and disaster recovery strategies.
  • Reduce the risk of security incidents through the systematic adoption of a risk assessment and treatment approach, with an acceptance threshold defined and reviewed annually.
  • Promote awareness and competence of all personnel regarding information security, through periodic training and awareness programs.
  • Meet applicable legal, regulatory, and contractual requirements, with particular attention to personal data protection and obligations towards institutional clients.

Fundamental Information Security Principles

The organization bases its ISMS on principles that permeate every operational activity, from platform design to daily management of information assets.

Risk-based approach. DEEPTREE S.r.l. systematically identifies, assesses, and treats information security risks, considering the probability and impact of each threat. Risks exceeding the defined acceptability threshold are subject to specific treatment plans; those below the threshold are accepted with the full awareness of Top Management. Risk assessment is reviewed at planned intervals and whenever significant changes occur in the organizational or technological context.

Information classification and handling. All information managed by the organization receives a classification level — Confidential, Restricted, or Public — based on its sensitivity and criticality. Each level corresponds to specific protection requirements for access, transmission, storage, and destruction, as defined in the POL Information classification and labelling policy .

Acceptable use of resources. The organization commits to defining and communicating clear rules for the use of information and associated assets. Every company resource — systems, devices, repositories, collaboration platforms — is formally assigned to personnel through the MOD Asset assignment form and used exclusively for authorized work purposes. Access to information is documented in the Register of users authorized to use the information , which identifies the accessible systems, repositories, and information for each user.

Clean desk and clear screen. The organization adopts measures to ensure that information is not exposed to unauthorized persons. Company devices are configured with automatic screen lock after a period of inactivity and with immediate password request for re-access. Personnel keep the work area free of documents containing classified information when not strictly necessary and securely store removable media. The POL Operational security policy details the specific applicable controls.

Reporting of security events. The organization provides all personnel with a dedicated channel to promptly report observed or suspected information security events. Each report activates the incident management process, which includes event classification, containment, eradication, and recovery, as well as potential notification to competent authorities according to applicable obligations. Incidents are recorded in the MOD Log of information security incidents and subjected to analysis to identify root causes and corrective actions.

Shared responsibility. Information security is not a function delegated to a single role, but rather a responsibility distributed among all personnel. Each member of the organization actively contributes to the protection of information assets through compliance with ISMS policies, procedures, and operating instructions, participation in training programs, and timely reporting of anomalous situations.

Continuous improvement. DEEPTREE S.r.l. is committed to continuously improving the effectiveness of the ISMS, utilizing the results of internal audits, performance indicator monitoring, incident analysis, and recommendations arising from management review. Every identified opportunity for improvement is evaluated, prioritized, and integrated into the organization's action plans.

Protection of Off-site Assets

DEEPTREE S.r.l. recognizes that personnel may operate outside company premises — in smart working, at client sites, or on business trips — and is committed to ensuring that information assets maintain a level of protection equivalent to that provided on-site. The organization considers off-site assets to include notebooks and mobile devices assigned to personnel, any physical media transported, and information processed in remote environments.

Custody and physical protection. Company devices are never left unattended in vehicles, public transport, common areas of hotels, or co-working spaces. During business trips, assigned personnel store them in a locked place or in the host facility's safe. The device screen is not visible to unauthorized persons — family members, flatmates, or colleagues in shared spaces — and physical documents containing classified information are securely stored and destroyed after use.

Remote connection security. To access company resources, personnel use SSH keys belonging to company PCs; the home network is configured with at least WPA2 encryption and personalized credentials, avoiding unprotected public Wi-Fi networks for processing confidential or restricted information. It is forbidden to modify or deactivate security controls on company devices, such as firewalls and antivirus software.

Secure communications. All communications involving information classified as Confidential or Restricted occur exclusively through channels approved by the organization. The use of personal messaging applications or non-company email accounts is prohibited for the transmission of sensitive data. Videoconferences on confidential topics take place in environments that ensure confidentiality and are protected by access credentials.

Reporting of loss, theft, or damage. Personnel immediately notify the Management System Manager of any loss, theft, or damage to off-site company assets. The notification activates procedures for remote device locking, access revocation, and credential changes. The event is recorded as an information security incident according to the PRO Information security incident management procedure .

Return of assets. At the end of the business trip, project, or employment relationship, personnel return company assets to the organization via the MOD Asset assignment form , which documents the taking charge and return of each assigned asset.

Archiving and Updating

This policy is a controlled document, archived and distributed according to the methods defined in the PRO Documented information management procedure . The Management System Manager is responsible for its annual review, or following significant changes in the organization, technology, threat landscape, or applicable regulatory requirements. Each revision is approved by Top Management before publication and communicated to all personnel and relevant interested parties.

Reference Documents

  • POL Operational security policy
  • POL Information classification and labelling policy
  • PRO Information security incident management procedure
  • PRO Documented information management procedure
  • MOD Asset assignment form
  • MOD Log of information security incidents
  • Register of users authorized to use the information

Version: 1 · Date: 07/04/2026 · Author: Claudio Arione · Approved by: Lorenzo Ferretti