Information Security Policy
Updated 5 Jul 2026
This policy is the top-level commitment of Sudory to protecting the confidentiality, integrity, and availability of the information we hold: our customers’ compliance data, personal data, and our own business information. It satisfies ISO/IEC 27001:2022 clause 5.2 and frames every other policy in the ISMS.
Purpose
Sudory sells trust: customers connect their systems to us so we can verify their security posture continuously. A security failure at Sudory would harm our customers directly, so information security is a founding requirement of the business, not an afterthought.
Objectives
Protect customer data against unauthorised access, alteration, and loss.
Keep the platform available and recoverable; publish honest status on the trust page.
Meet legal, regulatory, and contractual obligations, including the GDPR, the European Accessibility Act, and ISO/IEC 27001.
Detect and respond to incidents quickly and communicate them transparently.
Improve continuously: findings from monitoring, audits, and incidents feed back into the ISMS.
Principles
Least privilege: people and systems get the minimum access needed for their task.
Security by default: new services start closed, encrypted, and logged.
Single source of truth: security-relevant events are recorded in the platform’s immutable event log.
Automation over ceremony: controls are verified by continuous scans wherever possible, and by documented manual review where not.
Right-sizing: controls match the size and risk profile of the company and are extended as the team grows.
Roles and responsibilities
The founder acts as Security Officer and is accountable for the ISMS, approves policies, accepts residual risks, and reviews security performance. Every person working for Sudory is responsible for following the policies that apply to their work and for reporting security concerns and incidents without delay.
Policy framework
Topic-specific policies elaborate this policy: access management, asset management, secure development, supplier and cloud management, incident management, business continuity, and the other policies published in the Sudory document workspace. Where a topic-specific policy conflicts with this one, this policy prevails.
Compliance and review
Violations are handled through the Human Resources Security Policy and, where relevant, contract terms. The Security Officer reviews this policy at least annually and after significant incidents or organisational change.