Scope
This policy applies to all botBrains information assets, the systems that store, process, or transmit them, and everyone who handles them: both team members and any contractor or supplier acting on botBrains’ behalf. It covers our SaaS product, the cloud infrastructure that runs it, our corporate systems, and customer data we process. botBrains operates fully remote with no physical office, so our infrastructure providers handle physical and environmental security under their own certifications. See the Physical Security Policy.Management commitment
botBrains’ management establishes, resources, and continually improves the ISMS. The CISO holds top-level accountability for information security and approves every policy in the framework. Management commits to:- Protect the confidentiality, integrity, and availability of company, customer, and personnel information.
- Meet applicable legal, regulatory, and contractual obligations, including the GDPR in our role as a data processor. See GDPR compliance.
- Provide the people, tooling, and time needed to operate and improve the ISMS.
- Treat information security risk through a defined, repeatable method. See the Risk Management Policy.
- Pursue and maintain ISO/IEC 27001:2022 certification.
Security objectives
The CISO reviews progress against these objectives at least annually and adjusts them as the business changes.
ISMS framework and policy hierarchy
Topic-specific policies implement this policy, each owned by the CISO and reviewed at least annually, tracked in the Employees Only: Document Control register. The ISO 27001 overview lists the full set. Foundational policies include:- Roles and Responsibilities for accountability and the CISO role.
- Risk Management Policy for assessing and treating risk.
- Access Control Policy and Cryptography Policy for protecting data.
- Incident Management Policy for detecting and responding to events.
- Acceptable Use Policy and Code of Conduct for expected behaviour.