Information
Security Policy
Information Security Management System (ISMS) compliant with UNI CEI EN ISO/IEC 27001:2024.
The official document is in Italian; this page is a courtesy translation. In case of discrepancy, the Italian PDF prevails.
Owner: Heartwood Labs SRLS unipersonale — Via Costanzo Varolio, 17 – 40133 Bologna, Italy
Code: POLITICA | Category: Public | Author: ISMS Manager
Public document. The signed PDF prevails. Periodically reviewed by Top Management.
Contents
General Premise
Heartwood Labs SRLS is an Italian company active in information technology, digital consulting and custom software development. It designs and delivers innovative digital products for enterprises and organizations, translating business needs into concrete, scalable and integrated technology solutions. The organization operates with specialist teams in strategy, technology and creativity, selecting the most appropriate technologies for each project and covering the full solution lifecycle from discovery to post-release support.
Activities include web and mobile app development, enterprise architectures, systems integration, data governance, semantic search, data analytics, IoT/Industrial IoT, chatbots and virtual assistants, plus technology training.
Information Security Policy
Heartwood Labs considers information security a critical factor for both commercial processes and the delivery of services tailored to client specifications.
The primary objective is to protect data to safeguard corporate know-how, client assets and the personal data of data subjects. Given the nature of its services and the value of information, the security policy is a fundamental strategic priority.
The policy organizes confidentiality, integrity and availability of data and services and covers: identification of primary assets, risk, system and network management, vulnerability and incident identification, access control, privacy and compliance, damage assessment and all other aspects impacting information security.
Through a by-design approach the company maintains its technological, physical, logical and organizational structure and commits to develop and maintain an ISMS to guarantee availability, integrity and confidentiality.
Core principles
- Confidentiality: information accessible only to duly authorized subjects/processes.
- Integrity: protection against unauthorized modification, errors or system failures.
- Availability: authorized users can access information when requested.
- Privacy: protection and control of personal data.
- Authenticity: trustworthy origin and certain identification of users/systems.
Management commitment
- compliance with applicable laws and regulations;
- operational efficiency and reliability of development processes;
- health and safety at work;
- continuity of organizational processes to minimize impact of incidents;
- protection and proper use of provided resources;
- confidentiality, correctness and availability of information and IP protection;
- prevention of process/product/service anomalies.
Top Management defines and periodically reviews security objectives, ensures resources and promotes continual improvement of the ISMS.
Objectives
This Policy is the framework for setting and reviewing objectives. Heartwood Labs commits to:
- protect corporate and client/partner information;
- ensure service continuity;
- prevent unauthorized access;
- reduce risks from cyber threats, human error and vulnerabilities;
- protect intellectual property;
- secure software development processes;
- secure cloud, analytics and AI projects;
- ensure legislative/regulatory/contractual compliance;
- continually improve ISMS effectiveness.
Information Security Management System (ISMS)
To implement the policy, Heartwood Labs has developed and maintains an ISMS compliant with UNI CEI EN ISO/IEC 27001:2024.
- compliance with security levels via ISMS;
- compliance with applicable standards for infrastructure;
- selection of trustworthy partners for security and data protection.
Applies to all internal staff, third parties managing information, and all processes/resources for design, delivery and operation.
- knowledge and criticality assessment of managed information;
- secure access preventing unauthorized processing;
- collaboration with third parties under adequate security procedures;
- training and awareness of all parties;
- timely detection and management of anomalies/incidents;
- physical access restricted to authorized personnel;
- legal and contractual compliance;
- detection of anomalous events and vulnerabilities;
- business continuity and disaster recovery;
- personal data processing as Controller or Processor in line with GDPR (Reg. EU 679/2016).
Reviewed annually and shared via publication on this website.
Risk Management
Heartwood Labs applies a structured process for identification, analysis, evaluation and treatment of information security risks. Decisions are based on risk assessment results, ensuring proportionate controls consistent with the organizational context and stakeholder needs.
Access Policies
All physical and logical access is authorized, controlled and monitored based on:
- need-to-know — only information necessary for the task;
- role-based — only information relevant to the job function;
- premises access restricted to authorized personnel, controlled and monitored.
Personnel Responsibility
All staff and collaborators must:
- comply with applicable mandatory, contractual and voluntary ISMS requirements;
- protect confidentiality, integrity and availability, IP and entrusted assets;
- care for material goods, systems and resources;
- properly manage information within their remit;
- contact Management / ISMS Manager / competent authorities for actual or suspected breaches;
- flag needed changes to security procedures.
Heartwood Labs promotes continuous training and awareness so everyone understands their role in protecting information.
Third-Party Responsibility
- formal commitment to confidentiality and non-disclosure;
- protection of accessible physical and intellectual resources;
- full compliance with ISMS requirements.
Storage, Transfer & Portal Access
Storage
Data are stored via corporate infrastructure and/or qualified suppliers selected for security, reliability and compliance. Third-party processing complies with applicable law and organizational measures.
Transfer
Transfer uses protocols and technologies ensuring confidentiality and integrity in transit.
Management portal access
Protected by robust passwords, MFA and risk-proportionate controls. Access logs are retained with non-modifiability via qualified timestamp per eIDAS. Anomalous attempts are identified, notified by email and attacked accounts may be temporarily locked.
Data Breach & Incidents
Commitment
Heartwood Labs commits to:
- adopt an ISMS compliant with UNI CEI EN ISO/IEC 27001:2024;
- continuously monitor compliance with mandatory/voluntary and contractual requirements;
- provide resources for maintenance and continual improvement, mitigating risks and preventing anomalies/emergencies;
- ensure awareness of obligations and consequences of unauthorized use/modification/destruction of critical information.
This Policy is the reference for security objectives and is periodically reviewed by Top Management for adequacy, effectiveness and alignment with context, strategy and stakeholder needs, pursuing continual improvement for high standards of security, reliability and trust.
Bologna, 15/03/2026 — Top Management