Information Security Policy

This Policy defines the principles and commitments of RedCarbon S.r.l. regarding information security, personal data protection, and cloud service security, in compliance with international standards ISO/IEC 27001:2022, ISO/IEC 27017:2015, and ISO/IEC 27018:2019.

It applies to all business processes, information systems, cloud infrastructures (both as Cloud Service Provider – CSP and Cloud Service Customer – CSC), employees, collaborators, suppliers, and partners who access or process company or customer information.

Scope and Purpose

RedCarbon S.r.l. considers Information Security a primary aspect for the protection of its business and customers. The company's reputation is based on the proper management of physical, information, and personnel assets: to preserve it, a security model is essential that aims to protect processes and information from a wide range of threats and minimize their impact on operational continuity.

Information Security Management System Objectives

The objectives of RedCarbon S.r.l.'s Information Security Management System are to:

These objectives form the foundation for creating, implementing, operating, monitoring, reviewing, maintaining, and continuously improving an effective information security management system, implemented in accordance with ISO/IEC 27001:2022, ISO/IEC 27017:2015, and ISO/IEC 27018:2019 standards.

Policy

The intent of this Policy is to ensure that:

Security Controls for Cloud Services (ISO/IEC 27017)

For Security Controls for Cloud Services (ISO/IEC 27017), RedCarbon, acting as both CSP and CSC, applies the following principles:

Personal Data Protection (ISO/IEC 27018)

For personal data processed as a Data Processor, RedCarbon commits to:

Review and Continuous Improvement

The ISMS is reviewed at least once a year, or upon significant changes (new services, infrastructures, regulations).

The results of internal audits, risk analyses, incidents, and customer reports are used for continuous system improvement.

Availability

This policy is made available to all ISMS stakeholders according to procedures defined by the CEO and CTO.


Last updated: November 2025

RedCarbon S.r.l.

Legal Office

Torino (TO), Corso Lecce 51 - 10145 - Italy

Operations Office

Torino (TO), OGR - Corso Castelfidardo, 22 - 10128 - Italy

Tax Code and VAT Number 13235700013

REA Number TO-1348837

Registered share Capital €367.058,82

RedCarbon S.r.l. 2025 ® - all rights reserved