Information Security

Public Declaration of the Information Security Policy

Axelia Cybersecurity · Ref.: ORG-1-PSI-PUB · Version 1.0 · Classification: Public

Axelia Cybersecurity regards information security as an essential element of customer trust and of the quality of its ISMShed platform. Management is committed to protecting the confidentiality, integrity, availability, authenticity and traceability of information and services, managing security as a comprehensive, risk-based process built in by design.

Commitments

  • Comply with the National Security Framework (RD 311/2022), and align controls with ISO/IEC 27001 and 27002.

  • Comply with data protection regulations (RGPD and LOPDGDD) and other applicable legislation.

  • Analyse and treat risks periodically and in proportion to the criticality of information and services.

  • Train and raise awareness among staff, and require suppliers and third parties to provide equivalent security guarantees.

  • Manage and report security incidents in accordance with applicable regulations, and improve continuously.

The complete internal policy (PSI) and its regulatory framework apply to all staff and collaborators and are reviewed at least annually and whenever significant changes occur.

Availability

This Declaration is published on Axelia's website and is available to external interested parties upon request. Requests for additional information may be directed to the security contact channel: seguridad@axeliadigital.com. Detailed internal documentation is not disclosed for security reasons.

Approved by the Management of Axelia Cybersecurity — Date: 27/07/2026