TRUST AND SECURITY

Security controls and the ISMS

Qity operates an Information Security Management System aligned to ISO/IEC 27001. This page summarises the controlled policy that governs it, the codes of practice adopted, and the controls a security reviewer usually asks about.

DOC-262Information Security PolicyRELEASED
VERSION
1
CHANGE RECORD
DC-279
EFFECTIVE
6 February 2025
NEXT REVIEW
6 February 2026
OWNER
Miguel Azevedo
DOCUMENT APPROVAL
Miguel AzevedoDimitri CrelotTim VerstraeteYve De Buysscher
QA APPROVALJean-Francois LadryAPPROVED

Purpose and scope

The Information Security Policy establishes the framework, principles, and objectives for the secure operation of Qity's Information Security Management System. It applies to all systems, personnel, and processes within Qity, including board members, directors, employees, suppliers, and third parties with access to Qity systems. It covers the management of all information assets, compliance with legal and contractual obligations, and the implementation of both physical and digital security controls.

The policy commits Qity to the confidentiality, integrity, and availability of organisational information through clear governance structures, risk management practice, and adherence to statutory, regulatory, and contractual requirements. It covers access to sensitive data, a formal incident management approach, personal data protection, continuous improvement of security controls, and regular training.

WHY THIS MATTERS FOR A QMS BUYER

Qity sells quality management systems to regulated manufacturers. The same discipline is applied internally: this policy is a controlled document under Qity's own QMS, with a version, a change record, named approvers, an effective date, and a scheduled review. It is not a marketing page written once and forgotten.

Standards and codes of practice

Reference controls in Annex A of ISO/IEC 27001 are adopted where appropriate, reviewed regularly against the outcome of risk assessments and in line with information security risk treatment plans. Which Annex A controls are implemented and which are excluded is recorded in the Statement of Applicability, available on request.

Three further codes of practice are adopted and implemented where appropriate. Together they extend the baseline to cloud services and to the protection of personal data in public clouds, which is the operating model that matters for an Atlassian Marketplace vendor.

StandardWhat it adds
ISO/IEC 27001The management system itself: governance, risk assessment, objectives, Statement of Applicability, internal audit, management review, and continual improvement.
ISO/IEC 27002Code of practice for information security controls, used to implement the Annex A reference set.
ISO/IEC 27017Code of practice for information security controls for cloud services, applied because Qity apps run on Atlassian Cloud infrastructure.
ISO/IEC 27018Code of practice for the protection of personally identifiable information in public clouds acting as PII processors, applied to Qity's processor role.

Qity's stated ISMS objective includes achieving ISO/IEC 27001 certification and maintaining it on an ongoing basis. Qity is not certified today, and this page does not claim otherwise. What exists today is the management system, the policy set, the continuous scanning evidence, and the audit report linked from the trust overview.

Objectives and continual improvement

Information security objectives are set on a regular cycle that coincides with the budget planning cycle, so improvement activity is funded rather than aspirational. Objectives are documented for an agreed period together with how they will be achieved, then evaluated and monitored at management review. Amendments run through the change management process.

The policy commits Qity to make security processes and controls measurable, to review metrics annually against collected historical data, and to gather improvement ideas from employees, customers, suppliers, IT staff, risk assessments, and service reports. Ideas are recorded and evaluated as part of management review.

The policy set

The Information Security Policy is the overarching document. Beneath it sit 28 subject policies, each defined and agreed by one or more people competent in the relevant area, formally approved, and communicated to its audience. All 28 are listed below with their scope and audience. Any of them can be requested from security@qity.be; customers and prospective customers under an NDA receive the full text, and the request link on each card pre-fills the subject line.

GOVERNANCE AND PEOPLE

How the organisation behaves, and what happens when it does not.

Acceptable Use Policy

Sets out what every employee commits to when using Qity systems and information: permitted use, prohibited use, and the expectation that organisational security policies are followed rather than acknowledged. It is the policy that makes the rest enforceable.

AUDIENCEAll personnel
Request this policy

HR Security Policy

Covers the security dimension of the employment lifecycle: recruitment screening, security terms in employment contracts, ongoing policy compliance, the disciplinary process where policy is breached, and the removal of access and return of assets on termination.

AUDIENCEAll personnel
Request this policy

Information Labelling Policy

Defines the classification scheme and instructs personnel how to classify and label information so that handling rules follow the label. Without it, every other control has to guess at sensitivity.

AUDIENCEAll personnel
Request this policy

IP and Copyright Compliance Policy

Protection of Qity and customer intellectual property, the legal position, the penalties for infringement, and software licence compliance across the estate.

AUDIENCEAll personnel
Request this policy

Information Security Whistleblowing Policy

How anyone can raise an information security concern inside the organisation, including where the concern involves management. Provides a route that does not depend on the reporter's line manager.

AUDIENCEAll personnel and other interested parties
Request this policy

Social Media Policy

How social media is used when representing Qity and when discussing matters relevant to Qity, including what must not be disclosed about customers, products, or security posture.

AUDIENCEAll personnel
Request this policy

ACCESS AND IDENTITY

Who can reach what, and how that is proven.

Access Control Policy

User registration and deregistration, provision and revocation of access rights, external and third-party access, periodic access reviews, password policy, user responsibilities, and system and application access control. The joiner, mover, and leaver process sits here.

AUDIENCEPersonnel who set up and manage access control
Request this policy

User Password Policy

Allowed password composition, how to construct a strong one, and the use of multifactor authentication. Applies to every account, not only administrative ones.

AUDIENCEAll personnel
Request this policy

User Mobile Device Policy

Rules for company-provided mobile devices, including enrolment, configuration, permitted use, and what happens when a device is lost or replaced.

AUDIENCEUsers of company-provided mobile devices
Request this policy

BYOD Policy

The conditions under which personnel may use their own devices to access corporate information, the restrictions that apply to that access, and the separation expected between personal and business data.

AUDIENCEPersonnel setting up personal devices for restricted business use
Request this policy

INFRASTRUCTURE AND CONFIGURATION

The technical baseline the services are built on.

Infrastructure Policy

The Qity infrastructure security principles: how environments are structured, isolated, provisioned, and decommissioned, and the security properties each must hold.

AUDIENCEPersonnel responsible for IT
Request this policy

Network Security Policy

Network security design, including segregation, perimeter security, wireless networks and remote access, and network security management, covering roles and responsibilities, logging and monitoring, and change.

AUDIENCEPersonnel who design, implement, and manage networks
Request this policy

Configuration Management Policy

Secure configuration of hardware, software, services, and networks, including hardened baselines and the control of drift away from them.

AUDIENCEPersonnel who design systems and manage service delivery
Request this policy

Asset Management Policy

How assets are identified, owned, classified, handled, and disposed of from an information security perspective, across their whole life.

AUDIENCEAll personnel
Request this policy

DATA AND RECORDS

How information is handled, retained, and protected.

Privacy and Personal Data Protection Policy

Applicable data protection legislation, the definitions that follow from it, and the requirements placed on systems and personnel that process personal data. This is the internal counterpart to the published privacy policy and the data processing agreement.

AUDIENCEPersonnel who design and manage systems using personal data
Request this policy

Records Retention and Protection Policy

Retention periods by record type, the use of cryptography, media selection, record retrieval, secure destruction, and periodic review. Determines how long anything survives and in what form.

AUDIENCEPersonnel who create and manage records
Request this policy

External Data Management Policy

The management of data pertaining to entities external to Qity, including customer and supplier information, and the handling expectations attached to it.

AUDIENCEAll personnel
Request this policy

Clear Desk and Clear Screen Policy

Security of information displayed on screens, printed out, and held on removable media, in offices and in remote working locations alike.

AUDIENCEAll personnel
Request this policy

THREAT, VULNERABILITY, AND RESPONSE

Finding problems, and dealing with them.

Technical Vulnerability Management Policy

Vulnerability definition, sources of vulnerability information, patches and updates, vulnerability assessment, system hardening, awareness training, and vulnerability disclosure. The public summary is at Vulnerability management.

AUDIENCEPersonnel responsible for protecting the infrastructure
Request this policy

Threat Intelligence Policy

The collection and use of threat intelligence at strategic, tactical, and operational levels, and how it feeds risk assessment and control selection rather than sitting in a feed nobody reads.

AUDIENCEPersonnel responsible for protecting the infrastructure from attacks
Request this policy

Incident Management Policy

Defines the approach to incident management, which is then implemented through the associated plans and procedures, principally SOP DOC-836. The public summary is at How Qity handles security incidents.

AUDIENCEAll personnel and other interested parties
Request this policy

Business Continuity and Disaster Recovery Policy

The policy and the plan that determine how business continuity is handled in the face of disruptive events, including recovery objectives and the conditions under which the plan is invoked and tested.

AUDIENCEAll personnel
Request this policy

WORKING PRACTICES

Security where the work actually happens.

Remote Working Policy

Information security considerations in establishing and running a remote working site and arrangement, including physical security, insurance, and equipment. Relevant because Qity works remotely by default.

AUDIENCEManagement and personnel setting up and maintaining a remote working site
Request this policy

Physical Security Policy

Secure areas, paper and equipment security, and equipment lifecycle management, covering the physical controls that digital controls assume are present.

AUDIENCEAll personnel
Request this policy

Online Collaboration Policy

Use of collaboration tools for communication, sharing, and video conferencing, including what may be shared through them and how external participants are handled.

AUDIENCEUsers of online collaboration tools
Request this policy

Electronic Messaging Policy

Sending and receiving electronic messages, monitoring of electronic messaging facilities, and the use of email, including the handling of attachments and links.

AUDIENCEUsers of electronic messaging facilities
Request this policy

SUPPLIERS AND EMERGING TECHNOLOGY

The parts of the estate Qity does not directly control.

Information Security for Supplier Relationships Policy

Due diligence before engagement, supplier agreements, monitoring and review of services, handling of changes, dispute resolution, and end of contract. This is the control behind the sub-processor list.

AUDIENCEPersonnel who set up and manage supplier relationships
Request this policy

AI Security Policy

A framework for the ethical and secure use of AI technologies while safeguarding sensitive information, with particular attention to privacy and intellectual property. Governs what may be sent to which model, and on what basis.

AUDIENCEPersonnel who design systems and manage service delivery
Request this policy

Application and enforcement

The policy statements in DOC-262 and in the supporting set have been reviewed and approved by Qity top management and must be complied with. Failure by an employee to comply may result in disciplinary action under the Employee Disciplinary Process. Questions about any Qity policy are addressed in the first instance to the employee's line manager.

Requesting the documents

The security whitepaper, the Statement of Applicability, individual policies, and the full text of the procedures summarised across these pages are available on request. Security reviewers and procurement teams should write to security@qity.be. Data protection questions go to dpo@qity.be.

For the reasoning behind how Qity structures privacy accountability as controlled records rather than a shelf of documents, see the open-access paper A systematic approach for the protection of personal data and privacy.

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA