Sudory logo

Sudory

Trust Center

Request access

Information Security Policy

Updated 5 Jul 2026

This policy is the top-level commitment of Sudory to protecting the confidentiality, integrity, and availability of the information we hold: our customers’ compliance data, personal data, and our own business information. It satisfies ISO/IEC 27001:2022 clause 5.2 and frames every other policy in the ISMS.

Purpose

Sudory sells trust: customers connect their systems to us so we can verify their security posture continuously. A security failure at Sudory would harm our customers directly, so information security is a founding requirement of the business, not an afterthought.

Objectives

  • Protect customer data against unauthorised access, alteration, and loss.

  • Keep the platform available and recoverable; publish honest status on the trust page.

  • Meet legal, regulatory, and contractual obligations, including the GDPR, the European Accessibility Act, and ISO/IEC 27001.

  • Detect and respond to incidents quickly and communicate them transparently.

  • Improve continuously: findings from monitoring, audits, and incidents feed back into the ISMS.

Principles

  • Least privilege: people and systems get the minimum access needed for their task.

  • Security by default: new services start closed, encrypted, and logged.

  • Single source of truth: security-relevant events are recorded in the platform’s immutable event log.

  • Automation over ceremony: controls are verified by continuous scans wherever possible, and by documented manual review where not.

  • Right-sizing: controls match the size and risk profile of the company and are extended as the team grows.

Roles and responsibilities

The founder acts as Security Officer and is accountable for the ISMS, approves policies, accepts residual risks, and reviews security performance. Every person working for Sudory is responsible for following the policies that apply to their work and for reporting security concerns and incidents without delay.

Policy framework

Topic-specific policies elaborate this policy: access management, asset management, secure development, supplier and cloud management, incident management, business continuity, and the other policies published in the Sudory document workspace. Where a topic-specific policy conflicts with this one, this policy prevails.

Compliance and review

Violations are handled through the Human Resources Security Policy and, where relevant, contract terms. The Security Officer reviews this policy at least annually and after significant incidents or organisational change.