Information Security Policy

Version 1.0
Approved by: Daniel Peñaloza, Chief Executive Officer, on behalf of the management of ENTROPY COMPLEX DYNAMIC SYSTEMS, S.L. (Entropy)
Effective date: August 10th, 2026
Classification: Public

1. Purpose

Entropy is an Artificial Intelligence company. Our customers place their contracts, evidence, regulatory records, commercial data and personal data in our care so that we can help them run complex, document-intensive business processes. That trust is the basis of our business.

This policy sets out the intent, direction and commitment of Entropy's Management regarding Information Security. It is the highest-level policy in our Information Security Management System (ISMS) and provides the framework from which all supporting policies, standards, procedures and controls derive.

This is the public version of our Information Security Policy. It is published so that customers, prospective customers, partners, employees, regulators, auditors and other interested parties can understand how Entropy governs Information Security. The complete internal policy set and supporting evidence are available under confidentiality agreement.

2. Scope

This policy applies to Entropy and covers:

  • All information created, received, processed, stored or transmitted by Entropy, in any format and on any medium, including customer information, personal data, intellectual property, commercial information and information entrusted to us by Third Parties.

  • All information systems, applications, cloud environments, networks, devices and corporate systems that Entropy owns or operates, and the services Entropy delivers to its customers.

  • All Entropy employees, officers, directors, contractors, consultants, temporary staff and Third Parties acting on Entropy's behalf, at every location and in every working arrangement, including remote work.

  • All business functions, including engineering, research, operations, customer delivery, professional services, sales, marketing, finance, legal, people operations and corporate administration.

The formal boundaries of the ISMS are defined in our documented ISMS Scope Statement.

3. Policy Statement

Entropy is committed to protecting the confidentiality, integrity and availability of all information within its scope of responsibility.

The management of Entropy commits to:

a) Establishing, implementing, maintaining and continually improving an Information Security Management System structured in accordance with ISO/IEC 27001:2022.

b) Protecting information and information systems against unauthorized access, disclosure, modification, loss, disruption and misuse, whether accidental or deliberate.

c) Satisfying all applicable legal, regulatory, statutory and contractual requirements relating to Information Security and data protection, including the EU General Data Protection Regulation and the EU Artificial Intelligence Act.

d) Managing information security on the basis of assessed risk, using a documented and repeatable risk assessment and risk treatment methodology, with residual risk formally accepted by management.

e) Setting, measuring and reviewing information security objectives, and reviewing the performance of the ISMS at planned intervals through formal management review.

f) Providing the organizational structure, resources, competence, tooling and budget required to operate the ISMS effectively.

g) Ensuring that all personnel understand their Information Security responsibilities and are equipped to meet them.

h) Continually improving the ISMS through internal audit, independent assessment, control testing, incident and near-miss analysis, and feedback from customers and other interested parties.

i) Holding itself accountable for Information Security at the highest level of the organization, and not delegating that accountability.

4. Information Security Objectives

Entropy sets measurable information security objectives annually. They are approved by management, monitored throughout the year and reviewed at management review. Our current objectives address:

  • Protection of customer and personal data against unauthorized access, disclosure, alteration and loss.

  • Timely detection, containment, remediation and communication of information security incidents.

  • Availability, resilience and recoverability of the services we operate for customers.

  • Security assurance in the design, development and delivery of our products and changes to them.

  • Effective governance of suppliers, subprocessors and artificial intelligence model providers.

  • Information security competence and awareness across the whole organisation.

  • Achievement and maintenance of our external certification and assurance objectives.

5. Guiding Principles

The following principles apply across Entropy and are given effect through our supporting policies and controls:

Risk-based decision making. Security effort is directed by assessed risk to the organization, to our customers and to data subjects, and not by assumption or convenience.

Least privilege and need to know. Access to information and systems is granted only to the extent required for a legitimate business purpose, is uniquely attributable to an individual, is protected by strong authentication, and is reviewed and revoked promptly.

Security and privacy by design and by default. Security and data protection requirements are defined at the outset of any new product, feature, system, process or supplier relationship, and are not retrofitted.

Defence in depth. We do not rely on any single control. Preventive, detective and corrective controls operate together across our people, processes and technology.

Data minimization and purpose limitation. We collect, process and retain only the information necessary for a defined purpose, for no longer than necessary, and we delete or return it securely thereafter.

Segregation and isolation. Environments, duties and customer data are separated so that a failure or compromise in one area does not propagate to another.

Transparency and traceability. Actions on information and systems are logged, protected against tampering, and reconstructable, so that we and our customers can establish what happened, when, and by whom.

Human accountability. Automation, including Artificial Intelligence, supports human judgement in consequential decisions; it does not remove human responsibility for them.

Shared responsibility. We are explicit with our customers about which security responsibilities Entropy holds and which they hold, so that neither is assumed by default.

6. Artificial Intelligence

As an Artificial Intelligence company, Entropy accepts obligations that extend beyond conventional information security. Entropy commits that:

  • Customer information, including documents, prompts and outputs, is not used to train, fine-tune or otherwise improve Artificial Intelligence models, whether our own or those of Third-Party model providers. This is a contractual commitment and is flowed down to our model providers.

  • Customer information is logically isolated and is never used to serve, inform or produce results for another customer.

  • The model providers and other subprocessors that may process customer information are disclosed, and material changes are notified in advance in accordance with our Data Processing Agreement.

  • Artificial Intelligence systems that we develop or deploy are subject to documented governance covering risk assessment, model selection, evaluation, reliability of outputs, bias, misuse and human oversight.

  • We assess our role and obligations under the EU Artificial Intelligence Act for each system we place on the market or put into service, and we provide our customers with the documentation, controls and oversight capabilities they require to meet their own obligations.

7. Roles and Responsibilities

Management is accountable for Information Security at Entropy, approves this policy and the ISMS, allocates resources, accepts residual risk and conducts management review.

A designated Information Security function is responsible for the day-to-day operation of the ISMS, including risk management, policy maintenance, monitoring, awareness, incident response and audit coordination. It reports to management and has the authority to escalate, and to require that an activity, change or release be halted where risk is not acceptable.

Information owners are responsible for the classification, protection, appropriate use and lifecycle of the information assets assigned to them.

Every individual within scope is responsible for complying with this policy and its supporting policies, protecting the information they handle, and reporting suspected incidents, weaknesses and policy breaches without delay and without fear of reprisal for good-faith reporting.

8. Legal, Regulatory and Contractual Compliance

Entropy identifies, documents and keeps current the legal, regulatory and contractual requirements applicable to its activities and to the markets it serves, assigns ownership for meeting each of them, and reviews the register as our operations, customer base and the regulatory landscape change. Entropy's principal operations are established within the European Union and are subject to European Union and applicable national law, including the General Data Protection Regulation and the Artificial Intelligence Act. Entropy also serves customers in the United States and in other jurisdictions, and identifies and meets the requirements applicable to the personal data and business information it handles on their behalf. These include the comprehensive state privacy laws of the United States, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the equivalent statutes of other states, together with any sector-specific obligations that apply to a given engagement. Where Entropy processes information on behalf of a customer, it acts as a processor under the General Data Protection Regulation and as a processor or service provider, as applicable, under United States state privacy law, with the customer acting as controller or business. In that capacity, Entropy processes personal information only on the customer's documented instructions and only for the purposes of providing the contracted services. Entropy does not sell or share personal information, does not retain, use or disclose it for any purpose outside the direct business relationship with the customer, and does not combine it with information obtained from other sources except as permitted by law. These commitments, together with the safeguards applied to international transfers, are set out in our Data Processing Agreement, which incorporates the European Commission's Standard Contractual Clauses supported by a documented transfer impact assessment, and the terms required by applicable United States state privacy law. Where Entropy determines the purposes and means of processing, it acts as a controller or business, as described in our Privacy Policy.

9. Third Parties and Supply Chain

Suppliers, subprocessors, service providers and Artificial Intelligence model providers are assessed before engagement against security, data protection and, where relevant, artificial intelligence governance criteria proportionate to the sensitivity of the information involved and their criticality to our operations. Security and confidentiality obligations are imposed contractually, performance is monitored, independent audit reports and certifications are reviewed on an ongoing basis, and relationships are terminated securely.

10. Information Security Incidents

Entropy maintains and exercises a documented incident response process covering detection, reporting, triage, containment, eradication, recovery, communication, and post-incident review with corrective action. Where an incident affects customer information or personal data, Entropy notifies affected customers and, where applicable, supervisory authorities and data subjects, without undue delay and in accordance with applicable law and contractual commitments, and provides the information necessary for customers to meet their own notification obligations.

Suspected vulnerabilities or security concerns may be reported to legal@entropysystems.ai. Entropy does not pursue action against security researchers acting in good faith in accordance with our Policy.

11. Awareness, Training and Competence

All personnel receive Information Security and data protection training on joining Entropy and at least annually thereafter, with additional role-specific training where their duties carry elevated risk. Personnel are subject to confidentiality obligations, to background verification to the extent permitted by applicable law, and to a defined process for the return of assets and revocation of access on change of role or departure.

12. Compliance with this Policy

Compliance with this policy and its supporting policies is mandatory for everyone within scope. Compliance is monitored through internal audit, control testing and management review. Deliberate or negligent breach may result in disciplinary action up to and including termination of employment, termination of contract, and referral to law enforcement or regulatory authorities where required by law. Exceptions to this policy are permitted only where formally requested, risk-assessed, time-limited and approved by the information security function, and are recorded in an exceptions register.

13. Availability, Communication and Review

This policy is issued as documented information, is communicated to all Entropy personnel, is acknowledged by them, and is published on the Entropy website so that it is available to interested parties.

This policy is reviewed by management at least annually, and additionally whenever significant changes occur to Entropy's business, organization, technology, risk profile, regulatory environment or the results of internal audit and management review indicate that change is required. Amendments are approved by management and the revised policy is reissued and republished.

14. Contact

Questions about this policy, requests for supporting documentation, and information security enquiries: legal@entropysystems.ai


Approved and issued by the management of ENTROPY COMPLEX DYNAMIC SYSTEMS, S.L.