Information Security Policy

Reference framework for information security management at Politeia Soft

Version 2.0 — 21 September 2026
Download PDF

Downloadable public version (PDF)

Organisation

Politeia Soft S.L.

Tax ID (CIF)

B21966023

Registered office

Jerez de la Frontera (Cádiz), Spain

Contact

info@politeiasoft.com

Purpose and scope

This Information Security Policy (PSI) sets the reference framework to protect the confidentiality, integrity, availability, authenticity and traceability of information processed by Politeia Soft S.L. in developing and operating its software products and services.

It applies to internal and external personnel with access to the organisation’s information systems, and to authorised providers.

ENS framework

The organisation commits to compliance with Royal Decree 311/2022 regulating Spain’s National Security Scheme (ENS). The information system under certification is assessed at MEDIUM category.

Confidentiality

Access only by authorised personnel

Integrity

Protection against unauthorised alteration

Availability

Systems and data accessible when required

Authenticity

Verification of identities and origins

Traceability

Logging of relevant actions

Principles

  • Defence in depth
  • Least privilege
  • Secure by default
  • Continuous improvement
  • Segregation of duties (ENS roles not concentrated in a single person)

Security roles

Management assumes responsibility for information, service and system. The Security Officer (RSEG) is designated separately to strengthen independence in security governance. Named appointments are kept in the internal security file (not published in this version).

Management / Information / Service / System

Designated within the organisation

Security Officer (RSEG)

Separately designated (may be external)

Applicable laws and standards

  • Royal Decree 311/2022 (ENS)
  • Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD)
  • E-invoicing / Verifactu rules applicable to billing services
  • Criminal Code provisions on computer-related offences
  • Contracts and processor agreements with providers
  • Supporting CCN-STIC guides (including 803, 807, 808, 811 and 819)

Conflict resolution

  1. Documented attempt at agreement between the parties (e.g. RSEG and technical owners).
  2. If no agreement, escalation to Management.
  3. Final decision by Management, with written record.
  4. In case of doubt, the option that best preserves MEDIUM category and PSI principles prevails.

Compliance

Failure to comply with this policy may lead to disciplinary and legal measures under applicable law and internal rules.

Review

This policy is reviewed at least annually, and after serious incidents or significant infrastructure or regulatory changes.

Contact

For queries about this security policy:

info@politeiasoft.com