1. Purpose and commitment
FMIT Technologies S.L., a company of FMIT Group ("FMIT"), is a software engineering and data services
organisation. Information is one of our principal assets and that of our clients, and protecting it is a
condition of the services we deliver.
Management therefore expresses its commitment to preserving the confidentiality,
integrity and availability of the information assets belonging to FMIT, its clients,
its partners and its employees, throughout their lifecycle and in any medium or format in which they are held.
To that end, FMIT has implemented an Information Security Management System (ISMS) whose objective is to
achieve our business objectives and the satisfaction of our clients while guaranteeing information security
through established processes, sustained by continuous improvement, ensuring the continuity of information
systems, minimising the risk of damage and ensuring compliance with the commitments we have undertaken.
2. Scope
This Policy applies to all FMIT personnel, to all information systems and assets under our responsibility, and
to the services we deliver to our clients. It also applies, through contractual clauses, to suppliers and
subcontractors that access our information or that of our clients.
3. Certification and reference standards
Our Information Security Management System is certified by AENOR under ISO/IEC 27001:2022,
with recognition by IQNET, under certificate SI-0017/2023.
- Certificate: SI-0017/2023, issued by AENOR CONFIA S.A.U., recognised by IQNET
- Standard: ISO/IEC 27001:2022
- Certified scope: The information systems that support the design, development, implementation
and operation of a software system, according to the current statement of applicability (SOA) to the issued
date of the certificate
- Certified site: Alameda Principal 32, 1ª planta, 29005 Málaga, Spain
- First issued: 26 January 2023
- Current issue: 26 January 2026
- Valid until: 26 January 2029
Certification is maintained through periodic external audits. Please note that this Policy applies across FMIT
as described in section 2, which is broader than the certified scope set out above: certification covers the
activities and site stated in the certificate.
FMIT has also undergone a TISAX® (Trusted Information Security Assessment Exchange) assessment
through the ENX Association, in response to the information security requirements of the automotive sector. The
assessment result is available to TISAX participants via the ENX Portal.
Our security measures are additionally aligned with the requirements of Regulation (EU) 2016/679 (GDPR) and
Spanish Organic Law 3/2018 (LOPDGDD).
4. Guiding principles
Management establishes the following principles as the reference for all internal security regulations:
- Leadership and accountability: Management leads the ISMS, assigns responsibilities and provides
the resources necessary for its operation and improvement.
- Risk-based approach: Information assets are identified and valued, and the threats affecting
them are assessed and treated on the basis of their risk, which is accepted, mitigated or transferred through
documented decisions.
- Context and interested parties: We identify the internal and external parties relevant to information
security and take their requirements into account, including those of clients, regulators and suppliers.
- Least privilege and need to know: Access to information is granted only to the extent required
to perform a role, is formally authorised, and is reviewed and revoked when it is no longer needed.
- Confidentiality of client data: Information entrusted to us by clients is protected against undue
disclosure or alteration, both in the services we deliver and in our internal management.
- Integrity of information: Information remains complete, accurate and reliable throughout its
lifecycle, so that decisions are made on sound data and legal, regulatory and contractual requirements are met.
- Resilience and continuity: We maintain the capacity to respond to incidents and emergencies and
to restore critical services within the shortest possible time, and we test that capacity.
- Security in the lifecycle: Security requirements are considered from the design stage of our
systems and of the solutions we build for our clients, not added afterwards.
- Supplier management: Suppliers with access to information are assessed and bound by confidentiality
and security obligations proportionate to the risk they represent.
- Awareness and competence: All personnel receive regular training appropriate to their role, and
their technical competence is evaluated and maintained.
- Legal and contractual compliance: We comply with the legislation applicable to our activity,
with the commitments made to clients and interested parties, and with our own internal rules.
- Continuous improvement: Performance is measured against defined objectives, and processes are
analysed and improved on the basis of the results obtained, audits and incidents.
5. Objectives
Management sets measurable information security objectives, reviews them periodically and communicates
performance against them within the organisation. Those objectives address, as a minimum, the treatment of
identified risks, the effectiveness of security controls, incident response capability, and the level of
awareness among personnel.
6. Responsibilities
Compliance with this Policy is mandatory for all FMIT personnel. Management is accountable for the ISMS and
provides the necessary means. Designated roles within the organisation are responsible for risk assessment,
the operation of controls, incident management and internal audit. Failure to comply with this Policy or with
the regulations that develop it may give rise to disciplinary action in accordance with applicable law.
7. Reporting security concerns and vulnerabilities
We welcome reports of security concerns, suspected incidents and potential vulnerabilities affecting our
systems or services. Please write to info@fmit-solutions.com with the reference "Security", including sufficient technical detail to allow us to
reproduce and assess the issue.
We ask reporters to act in good faith: to avoid accessing, modifying or disclosing data belonging to third
parties, to avoid actions that could degrade the availability of our services, and to give us a reasonable
period to investigate and remediate before disclosing the issue publicly. We will acknowledge receipt of your
report and keep you informed of its handling.
If your report concerns a personal data breach, we will handle it under our incident response procedure and
comply with the notification obligations in Articles 33 and 34 GDPR.
8. Communication and availability
This Policy is communicated to all personnel, is made available to interested parties through this page, and
is available in its full internal version to clients and other interested parties on justified request.
9. Review and updates
This Policy is reviewed at planned intervals, at least annually, and whenever significant changes occur in the
organisation, in the risks we face, in applicable legislation or in the reference standards, in order to
ensure its continued adequacy and effectiveness. It is approved by Management.
Company Information
- FMIT Technologies S.L. (FMIT Group)
- Tax ID (CIF): B93706968
- Registered office: Alameda Principal 32, 1, 29005 Málaga, Spain
- Additional office: Santa Rosalía 49, 1A, 38002 Santa Cruz de Tenerife, Spain
- Contact email: info@fmit-solutions.com
- Phone: +34 952 65 76 03
- Website: https://fmit.io
- Certifications: ISO/IEC 27001:2022, certificate SI-0017/2023 (AENOR, recognised by IQNET); TISAX®
assessment result available via the ENX Portal