Information Security Policy

CELTA TECHNOLOGY SRL is a technology development company specializing in solutions that support public- and private-sector management and help improve productivity.

As part of its commitment to providing competitive services to all its customers, the Company has implemented an Information Security Management System within the organization. Its primary purpose is to support the achievement of business objectives and customer satisfaction by safeguarding information through established processes based on continuous improvement.

The Information Security Management System is intended to ensure the continuity of information systems, minimize the risk of harm, and support the achievement of the objectives established to preserve the confidentiality, integrity, and availability of information at all times.

CELTA TECHNOLOGY SRL is therefore committed to information security in accordance with the requirements of ISO/IEC 27001:2022. To this end, Top Management establishes the following principles:

  • Demonstrate competence and leadership, as well as a firm commitment to the development, implementation, maintenance, and continual improvement of the Information Security Management System.
  • Identify the internal and external interested parties that are relevant to the Information Security Management System and ensure that their applicable requirements are addressed.
  • Understand the context of the organization and identify information security-related risks and opportunities as the basis for planning actions to address, accept, or treat them.
  • Promote customer satisfaction and take into account the expectations of interested parties regarding the Company’s activities, results, and impact on society.
  • Establish objectives and targets focused on evaluating information security performance and continually improving the activities governed by the management system supporting this Policy.
  • Comply with all applicable legal, regulatory, and contractual requirements related to the Company’s activities, including commitments made to customers and other interested parties, as well as internal policies, standards, and operating guidelines adopted by the Company.
  • Protect the confidentiality of the information and data managed by the Company, ensure the availability of information systems, and prevent unauthorized or improper alteration of information, both in customer-facing services and internal operations.
  • Maintain an appropriate response capability for emergency and disruptive situations, restoring critical services within the shortest possible time.
  • Establish and implement appropriate measures to treat the risks identified through the identification and assessment of information assets.
  • Raise awareness and provide appropriate training to all personnel working within the organization, enabling them to perform their duties correctly and act in accordance with the requirements of ISO/IEC 27001:2022, while providing a suitable environment for the operation of organizational processes.
  • Maintain effective and ongoing communication both internally, among the different areas and levels of the Company, and externally with customers and other relevant interested parties.
  • Evaluate and ensure the technical competence of personnel in the performance of their duties and foster their motivation and active participation in the continual improvement of organizational processes.
  • Ensure that facilities and equipment are properly maintained, suitable for their intended purpose, and aligned with the Company’s activities, objectives, and targets.
  • Continually monitor and analyze all relevant processes and implement appropriate improvements based on the results obtained and the objectives established.

These principles are endorsed by Top Management, which undertakes to provide the necessary means and sufficient resources to ensure their implementation and fulfillment.

Through this Information Security Policy, CELTA TECHNOLOGY SRL formally communicates these commitments to its employees, customers, interested parties, and the general public.

Signed: Management Committee

Date: July 31, 2026
Annex I — Edition 01