01
Our commitment
Ampleshift is committed to providing services with high standards of quality, rigor, reliability, and security, ensuring customer satisfaction, the protection of information, and the continuous improvement of its Integrated Management System.
02
Scope of our activity
We operate in the development and provision of specialized solutions and services, seeking to effectively meet the needs of customers, partners, and other interested parties, ensuring compliance of the services provided, business continuity, and the protection of information handled within the scope of our activity.
03
Information as an essential asset
Ampleshift recognizes information as an essential asset for the organization's continuity, competitiveness, and trust, and it must be adequately protected against applicable risks, threats, and vulnerabilities.
04
A shared responsibility
Information security is the responsibility of all employees and, whenever applicable, of suppliers, service providers, and other interested parties who have access to Ampleshift's information or that of its customers. In its analysis of the external context, the organization determines whether climate change constitutes a relevant issue for the Integrated Management System and for its interested parties.
05
The Integrated Management System
Ampleshift's Integrated Management System, in accordance with the ISO 9001 (Quality Management System) and ISO/IEC 27001 (Information Security Management System) standards, establishes the framework for managing processes, risks and opportunities, objectives, resources, competencies, and the controls necessary for service quality and information security.
06
Our commitments
In this context, Ampleshift commits to:
- ensuring the satisfaction of customers and relevant interested parties, addressing their needs and expectations, and promoting continuous improvement in the quality of services provided;
- complying with legal, regulatory, normative, contractual, and other requirements applicable to its activity;
- ensuring the protection of Ampleshift's information and that of its customers, partners, and other interested parties;
- preserving the Confidentiality, Integrity, and Availability of information, in accordance with identified risks;
- managing risks and opportunities associated with processes, services, and information security;
- applying a risk-based approach to the protection of information assets, defining controls appropriate to the level of risk accepted by the organization;
- preventing information security incidents and ensuring their identification, communication, treatment, analysis, response, and learning;
- promoting the appropriate and secure use of assets, systems, applications, equipment, and information;
- defining, communicating, and, when applicable, contractually incorporating quality, confidentiality, and information security requirements for relevant suppliers and service providers, monitoring their compliance proportionally to the associated risk;
- developing the competencies, awareness, and engagement of employees;
- promoting the continuous improvement of the effectiveness of the Integrated Management System;
- strengthening innovation, operational efficiency, digitalization, and the organization's responsiveness;
- ensuring operational continuity and the resilience of critical processes and systems;
- ensuring the proper handling, storage, transmission, access, and disposal of confidential, sensitive, or proprietary information;
- ensuring the response, recovery, and continuity of activities in the event of an incident, unavailability, or disruptive event that may affect critical information, systems, or services;
- protecting the reputation, credibility, and trust placed in Ampleshift by its customers and interested parties.
07
Objectives and strategic direction
These commitments reflect Ampleshift's strategic direction and establish the framework for defining, reviewing, and monitoring the objectives of the Integrated Management System, which are measurable, periodically monitored, and updated whenever necessary.
08
Resources, communication, and awareness
Management ensures the availability of the resources necessary for the implementation, maintenance, and continuous improvement of the Integrated Management System, ensuring that this Policy is communicated, understood, and applied by all employees and other relevant persons, with records of its dissemination and acknowledgment being maintained where applicable. The Policy is also made available to relevant interested parties whenever appropriate.
09
Review of this Policy
This Policy is reviewed at least annually and whenever significant changes occur in the organization's context, applicable requirements, risks, services, technologies used, or Ampleshift's strategic direction.