Information Security Policy
Version 1.0 — August 1, 2026
Purpose
This Information Security Policy defines the principles, commitments and control objectives through which Futura AI Srl SB protects information assets, digital resources, organizational knowledge and the continuity of its operations.
The policy supports the company's commitment to trust, resilience, confidentiality, integrity and availability of information in relation to its business model, technologies and stakeholder expectations.
Scope
This policy applies to information in any form, including digital, physical, verbal and documentary information, as well as to systems, platforms, services, devices, cloud environments and organizational processes used by or on behalf of Futura AI Srl SB.
It applies to directors, employees, collaborators, consultants, suppliers, partners and any third party who may access company or client information.
Security principles
Futura AI Srl SB adopts the following information security principles:
- protection of confidentiality, integrity and availability of information;
- proportionality between risks, controls and business needs;
- security by design in systems, processes and operational choices;
- access to information on a need-to-know and least-privilege basis;
- traceability, accountability and controlled management of critical activities;
- continuous improvement of security measures according to the evolution of risks and technologies.
Management commitment
Management is committed to promoting and supporting an information security framework that is appropriate to the nature, scale and risk profile of the company.
In particular, management undertakes to:
- assign responsibilities for information protection and security-related activities;
- provide resources, tools and organizational support for effective security measures;
- assess risks and review controls periodically;
- promote awareness and responsible behavior across the organization;
- support incident management, corrective actions and continuous improvement;
- align security practices with applicable legal, contractual and regulatory requirements.
Risk-based approach
The company adopts a risk-based approach to information security. Security decisions are based on the identification of relevant assets, threats, vulnerabilities, potential impacts and appropriate treatment measures.
This approach supports the prioritization of safeguards in relation to business continuity, client trust, data protection obligations and operational resilience.
Access control
Access to systems, applications, repositories and information resources must be authorized, limited to legitimate business purposes and periodically reviewed.
Authentication credentials must be protected with care. Shared accounts, excessive privileges and uncontrolled access paths shall be avoided or strictly governed where technically justified.
Information classification and handling
Information shall be handled according to its sensitivity, business relevance and confidentiality requirements.
The company promotes suitable rules for the creation, storage, transmission, sharing, retention and disposal of information, with particular attention to client data, internal documentation, credentials, technical assets and non-public business information.
Secure use of technology
Technology resources must be used responsibly, securely and in ways consistent with company rules and professional duties.
This includes the secure configuration of systems, appropriate update and patch management, controlled use of software and cloud services, and attention to the risks associated with portable devices, remote work and third-party tools.
Data protection and privacy
Information security and personal data protection are treated as closely connected domains. Futura AI Srl SB is committed to supporting lawful, secure and proportionate processing of personal data.
Security measures are adopted taking into account confidentiality needs, risk exposure, system architecture and the protection of data subjects' rights.
Incident management
Security events, weaknesses and incidents must be reported promptly through the appropriate internal channels so that they can be assessed, contained, investigated and addressed.
The company is committed to ensuring that incidents are managed with seriousness, timeliness and adequate documentation, including the activation of corrective and preventive actions where required.
Business continuity and resilience
The company recognizes the importance of maintaining essential services and preserving critical information in the event of disruption.
For this reason, Futura AI Srl SB promotes appropriate continuity, backup, recovery and resilience measures proportionate to the relevance of the services provided and the supporting infrastructure.
Third parties
Suppliers, partners and external service providers who may affect the security of information or systems are considered within the company's control framework.
Selection, onboarding and oversight of third parties should take into account reliability, security posture, contractual commitments and the potential impact on company and client information.
Awareness and responsibility
Information security depends not only on technical controls but also on behavior, culture and individual responsibility.
All recipients of this policy are expected to contribute to the protection of information assets by following company rules, acting with diligence and reporting relevant risks or anomalies.
Review
This policy is periodically reviewed and updated according to the evolution of the organization, technologies, threats, legal requirements and business context.
Approval
This Information Security Policy is approved by the management of Futura AI Srl SB and constitutes a general reference framework for the protection of information within the organization.
