Information Security

Management System Policy

Table of Contents

  1. Purpose
  2. Scope
  3. Normative References
  4. Terms and Definitions
  5. Roles and Responsibilities
  6. Management System Commitments and Objectives
  7. Archiving and Updating
  8. Reference Documents

Purpose

DEEPTREE S.r.l. recognizes information security as an essential strategic factor for its business model, which is based on the design, development, and provision of a proprietary AI-powered financial intelligence SaaS platform serving private equity funds, M&A advisors, and search funds. This policy expresses the intentions and direction of Top Management regarding the Information Security Management System (ISMS), establishing the framework within which the organization defines its security objectives, makes commitments to interested parties, and pursues continual improvement of its performance.

Through this document, the organization formalizes its commitment to combining the needs for economic development and value creation — characteristic of a technology startup operating in the private markets software sector — with the systematic protection of the confidentiality, integrity, and availability of information, in compliance with applicable legislation and the legitimate expectations of interested parties.

Scope

This policy applies to all activities, processes, information assets, technological systems, and premises of DEEPTREE S.r.l., including the registered office at Via Sangallo 5, Milan, and the operational office at Piazza Aspromonte 26, Milan. The scope encompasses the entire lifecycle of the SaaS platform — design, development, service delivery, and technical support — as well as the cloud infrastructure on Google Cloud Platform, source code repositories, collaboration platforms, and every company device assigned to personnel. The policy applies to all employees, collaborators, and third parties who access the organization's information or systems, regardless of whether they work on-site or remotely. Dedicated protected physical areas (server rooms and restricted physical archives) are excluded, as the entire IT infrastructure is cloud-based and the organization has no data centers of its own.

Normative References

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • GDPR

Terms and Definitions

  • Information Security Management System (ISMS): a set of policies, processes, procedures, resources, and organizational structures established to manage information security through a systematic, risk-based approach.
  • Information security: preservation of the confidentiality, integrity, and availability of information.
  • Confidentiality: the property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
  • Integrity: the property of accuracy and completeness of information.
  • Availability: the property of being accessible and usable on demand by an authorized entity.
  • Risk: the effect of uncertainty on objectives, expressed as a combination of the probability of an event and its consequences.
  • Policy: the intentions and direction of an organization as formally expressed by Top Management.
  • Top Management: a person or group of people who direct and control an organization at the highest level.
  • Interested party: a person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity.
  • Continual improvement: a recurring activity to enhance management system performance.

Roles and Responsibilities

  • Top Management: establishes and approves this policy, sets information security objectives, and ensures the availability of the resources needed to implement them.
  • Management System Manager: supports Top Management in drafting and updating the policy, coordinates its communication to all personnel and external interested parties, and verifies its consistency with the organizational context.

Management System Commitments and Objectives

DEEPTREE S.r.l. adopts an Information Security Management System compliant with ISO/IEC 27001:2022, appropriate to its nature as a technology startup developing artificial intelligence solutions for the financial sector and consistent with the context in which it operates — a regulated, data-intensive, and rapidly evolving ecosystem. Top Management makes the following commitments and directs the entire organization toward achieving them.

Commitment to Information Security

The organization is committed to protecting the confidentiality of client data and source code through the principle of least privilege, ensuring the integrity of information extracted and structured by the platform so that clients' decisions are based on accurate data, and ensuring the continuous availability of cloud services through business continuity and disaster recovery strategies. This threefold protection is the foundation of the trust that institutional investors, advisors, and private equity funds place in the platform.

DEEPTREE S.r.l. recognizes that information security is a shared responsibility at every level of the organization: all personnel — employees, collaborators, and third parties — actively participate in protecting information assets in accordance with ISMS policies and procedures, promptly reporting any anomalies through dedicated channels.

Risk-based Approach

The organization adopts a systematic approach to identifying, assessing, and treating information security risks. Risks are analyzed according to their likelihood and potential impact; those exceeding the acceptability threshold — reviewed annually by Top Management — are subject to specific treatment plans, while those below the threshold are accepted with management's full awareness. This methodology enables resources to be allocated in proportion to the severity of threats and protective measures to be promptly adapted to the evolving risk landscape.

Meeting Applicable Requirements

DEEPTREE S.r.l. is committed to meeting the legal, regulatory, and contractual requirements applicable to information security, with particular attention to personal data protection and obligations toward institutional clients. The organization promotes a culture of compliance at all levels, encouraging awareness of and adherence to the regulatory principles governing its activities.

Information Classification and Handling

Information managed by the organization is classified according to its sensitivity into three levels — Confidential, Restricted, and Public — each of which has specific protection requirements for access, transmission, retention, and destruction. This system ensures that every item of information receives a level of protection proportionate to its value and the harm that could result from its compromise.

Information Security Objectives

This policy provides the framework for setting information security objectives, which Top Management defines and periodically reviews during management review. These objectives, which are measurable and consistent with corporate strategic directions, cover the following areas:

  • reducing the risk of security incidents through systematic threat assessment and the adoption of risk treatment measures;
  • protecting information assets throughout the platform's lifecycle, from secure software design to service delivery and technical support;
  • promoting personnel awareness and competence in security through periodic training programs;
  • ensuring continuity in the delivery of cloud services to clients through disaster recovery and business continuity strategies;
  • consistently meeting legal, regulatory, and contractual requirements relevant to information security.

Continual Improvement

DEEPTREE S.r.l. pursues continual improvement of the effectiveness of the ISMS by drawing on the results of internal audits, performance indicator monitoring, incident analysis, and recommendations arising from management reviews. Each identified opportunity for improvement is evaluated, prioritized, and integrated into the organization's action plans, in accordance with the Plan-Do-Check-Act cycle that governs all management system processes.

Communication of the Policy

This policy is communicated to all internal personnel through approved company channels — company email, messaging platforms, and training sessions — and is made available to external interested parties (clients, suppliers, and authorities) through the company website, contractual specifications, and communications on request, as governed by the PRO Communication management procedure. Each revision of the document is communicated again so that the entire organization and external stakeholders operate on the basis of the latest version.

Archiving and Updating

This policy is stored digitally in the ISMS document repository, accessible to authorized personnel through company systems. The Management System Manager reviews it at least annually during management review, or whenever changes in the organizational, regulatory, or technological context, or findings from internal or external audits, require an update. Each revision results in a new version, approved by Top Management, and the simultaneous archiving of the previous version in accordance with the methods defined in the PRO Documented information management procedure.

Reference Documents

  • POL Information security policy
  • PRO Management processes
  • PRO Communication management procedure
  • PRO Documented information management procedure

Version: 1 · Date: 07/04/2026 · Author: Claudio Arione · Approved by: Lorenzo Ferretti