Purpose and scope
The Information Security Policy establishes the framework, principles, and objectives for the secure operation of Qity's Information Security Management System. It applies to all systems, personnel, and processes within Qity, including board members, directors, employees, suppliers, and third parties with access to Qity systems. It covers the management of all information assets, compliance with legal and contractual obligations, and the implementation of both physical and digital security controls.
The policy commits Qity to the confidentiality, integrity, and availability of organisational information through clear governance structures, risk management practice, and adherence to statutory, regulatory, and contractual requirements. It covers access to sensitive data, a formal incident management approach, personal data protection, continuous improvement of security controls, and regular training.
WHY THIS MATTERS FOR A QMS BUYERQity sells quality management systems to regulated manufacturers. The same discipline is applied internally: this policy is a controlled document under Qity's own QMS, with a version, a change record, named approvers, an effective date, and a scheduled review. It is not a marketing page written once and forgotten.
Standards and codes of practice
Reference controls in Annex A of ISO/IEC 27001 are adopted where appropriate, reviewed regularly against the outcome of risk assessments and in line with information security risk treatment plans. Which Annex A controls are implemented and which are excluded is recorded in the Statement of Applicability, available on request.
Three further codes of practice are adopted and implemented where appropriate. Together they extend the baseline to cloud services and to the protection of personal data in public clouds, which is the operating model that matters for an Atlassian Marketplace vendor.
| Standard | What it adds |
| ISO/IEC 27001 | The management system itself: governance, risk assessment, objectives, Statement of Applicability, internal audit, management review, and continual improvement. |
| ISO/IEC 27002 | Code of practice for information security controls, used to implement the Annex A reference set. |
| ISO/IEC 27017 | Code of practice for information security controls for cloud services, applied because Qity apps run on Atlassian Cloud infrastructure. |
| ISO/IEC 27018 | Code of practice for the protection of personally identifiable information in public clouds acting as PII processors, applied to Qity's processor role. |
Qity's stated ISMS objective includes achieving ISO/IEC 27001 certification and maintaining it on an ongoing basis. Qity is not certified today, and this page does not claim otherwise. What exists today is the management system, the policy set, the continuous scanning evidence, and the audit report linked from the trust overview.
Objectives and continual improvement
Information security objectives are set on a regular cycle that coincides with the budget planning cycle, so improvement activity is funded rather than aspirational. Objectives are documented for an agreed period together with how they will be achieved, then evaluated and monitored at management review. Amendments run through the change management process.
The policy commits Qity to make security processes and controls measurable, to review metrics annually against collected historical data, and to gather improvement ideas from employees, customers, suppliers, IT staff, risk assessments, and service reports. Ideas are recorded and evaluated as part of management review.
The policy set
The Information Security Policy is the overarching document. Beneath it sit 28 subject policies, each defined and agreed by one or more people competent in the relevant area, formally approved, and communicated to its audience. All 28 are listed below with their scope and audience. Any of them can be requested from security@qity.be; customers and prospective customers under an NDA receive the full text, and the request link on each card pre-fills the subject line.
GOVERNANCE AND PEOPLE
How the organisation behaves, and what happens when it does not.
Acceptable Use Policy
Sets out what every employee commits to when using Qity systems and information: permitted use, prohibited use, and the expectation that organisational security policies are followed rather than acknowledged. It is the policy that makes the rest enforceable.
AUDIENCEAll personnel
Request this policyHR Security Policy
Covers the security dimension of the employment lifecycle: recruitment screening, security terms in employment contracts, ongoing policy compliance, the disciplinary process where policy is breached, and the removal of access and return of assets on termination.
AUDIENCEAll personnel
Request this policyInformation Labelling Policy
Defines the classification scheme and instructs personnel how to classify and label information so that handling rules follow the label. Without it, every other control has to guess at sensitivity.
AUDIENCEAll personnel
Request this policyIP and Copyright Compliance Policy
Protection of Qity and customer intellectual property, the legal position, the penalties for infringement, and software licence compliance across the estate.
AUDIENCEAll personnel
Request this policyInformation Security Whistleblowing Policy
How anyone can raise an information security concern inside the organisation, including where the concern involves management. Provides a route that does not depend on the reporter's line manager.
AUDIENCEAll personnel and other interested parties
Request this policySocial Media Policy
How social media is used when representing Qity and when discussing matters relevant to Qity, including what must not be disclosed about customers, products, or security posture.
AUDIENCEAll personnel
Request this policy
ACCESS AND IDENTITY
Who can reach what, and how that is proven.
Access Control Policy
User registration and deregistration, provision and revocation of access rights, external and third-party access, periodic access reviews, password policy, user responsibilities, and system and application access control. The joiner, mover, and leaver process sits here.
AUDIENCEPersonnel who set up and manage access control
Request this policyUser Password Policy
Allowed password composition, how to construct a strong one, and the use of multifactor authentication. Applies to every account, not only administrative ones.
AUDIENCEAll personnel
Request this policyUser Mobile Device Policy
Rules for company-provided mobile devices, including enrolment, configuration, permitted use, and what happens when a device is lost or replaced.
AUDIENCEUsers of company-provided mobile devices
Request this policyBYOD Policy
The conditions under which personnel may use their own devices to access corporate information, the restrictions that apply to that access, and the separation expected between personal and business data.
AUDIENCEPersonnel setting up personal devices for restricted business use
Request this policy
INFRASTRUCTURE AND CONFIGURATION
The technical baseline the services are built on.
Infrastructure Policy
The Qity infrastructure security principles: how environments are structured, isolated, provisioned, and decommissioned, and the security properties each must hold.
AUDIENCEPersonnel responsible for IT
Request this policyNetwork Security Policy
Network security design, including segregation, perimeter security, wireless networks and remote access, and network security management, covering roles and responsibilities, logging and monitoring, and change.
AUDIENCEPersonnel who design, implement, and manage networks
Request this policyConfiguration Management Policy
Secure configuration of hardware, software, services, and networks, including hardened baselines and the control of drift away from them.
AUDIENCEPersonnel who design systems and manage service delivery
Request this policyAsset Management Policy
How assets are identified, owned, classified, handled, and disposed of from an information security perspective, across their whole life.
AUDIENCEAll personnel
Request this policy
DATA AND RECORDS
How information is handled, retained, and protected.
Privacy and Personal Data Protection Policy
Applicable data protection legislation, the definitions that follow from it, and the requirements placed on systems and personnel that process personal data. This is the internal counterpart to the published privacy policy and the data processing agreement.
AUDIENCEPersonnel who design and manage systems using personal data
Request this policyRecords Retention and Protection Policy
Retention periods by record type, the use of cryptography, media selection, record retrieval, secure destruction, and periodic review. Determines how long anything survives and in what form.
AUDIENCEPersonnel who create and manage records
Request this policyExternal Data Management Policy
The management of data pertaining to entities external to Qity, including customer and supplier information, and the handling expectations attached to it.
AUDIENCEAll personnel
Request this policyClear Desk and Clear Screen Policy
Security of information displayed on screens, printed out, and held on removable media, in offices and in remote working locations alike.
AUDIENCEAll personnel
Request this policy
THREAT, VULNERABILITY, AND RESPONSE
Finding problems, and dealing with them.
Technical Vulnerability Management Policy
Vulnerability definition, sources of vulnerability information, patches and updates, vulnerability assessment, system hardening, awareness training, and vulnerability disclosure. The public summary is at Vulnerability management.
AUDIENCEPersonnel responsible for protecting the infrastructure
Request this policyThreat Intelligence Policy
The collection and use of threat intelligence at strategic, tactical, and operational levels, and how it feeds risk assessment and control selection rather than sitting in a feed nobody reads.
AUDIENCEPersonnel responsible for protecting the infrastructure from attacks
Request this policyIncident Management Policy
Defines the approach to incident management, which is then implemented through the associated plans and procedures, principally SOP DOC-836. The public summary is at How Qity handles security incidents.
AUDIENCEAll personnel and other interested parties
Request this policyBusiness Continuity and Disaster Recovery Policy
The policy and the plan that determine how business continuity is handled in the face of disruptive events, including recovery objectives and the conditions under which the plan is invoked and tested.
AUDIENCEAll personnel
Request this policy
WORKING PRACTICES
Security where the work actually happens.
Remote Working Policy
Information security considerations in establishing and running a remote working site and arrangement, including physical security, insurance, and equipment. Relevant because Qity works remotely by default.
AUDIENCEManagement and personnel setting up and maintaining a remote working site
Request this policyPhysical Security Policy
Secure areas, paper and equipment security, and equipment lifecycle management, covering the physical controls that digital controls assume are present.
AUDIENCEAll personnel
Request this policyOnline Collaboration Policy
Use of collaboration tools for communication, sharing, and video conferencing, including what may be shared through them and how external participants are handled.
AUDIENCEUsers of online collaboration tools
Request this policyElectronic Messaging Policy
Sending and receiving electronic messages, monitoring of electronic messaging facilities, and the use of email, including the handling of attachments and links.
AUDIENCEUsers of electronic messaging facilities
Request this policy
SUPPLIERS AND EMERGING TECHNOLOGY
The parts of the estate Qity does not directly control.
Information Security for Supplier Relationships Policy
Due diligence before engagement, supplier agreements, monitoring and review of services, handling of changes, dispute resolution, and end of contract. This is the control behind the sub-processor list.
AUDIENCEPersonnel who set up and manage supplier relationships
Request this policyAI Security Policy
A framework for the ethical and secure use of AI technologies while safeguarding sensitive information, with particular attention to privacy and intellectual property. Governs what may be sent to which model, and on what basis.
AUDIENCEPersonnel who design systems and manage service delivery
Request this policy
Application and enforcement
The policy statements in DOC-262 and in the supporting set have been reviewed and approved by Qity top management and must be complied with. Failure by an employee to comply may result in disciplinary action under the Employee Disciplinary Process. Questions about any Qity policy are addressed in the first instance to the employee's line manager.
Requesting the documents
The security whitepaper, the Statement of Applicability, individual policies, and the full text of the procedures summarised across these pages are available on request. Security reviewers and procurement teams should write to security@qity.be. Data protection questions go to dpo@qity.be.
For the reasoning behind how Qity structures privacy accountability as controlled records rather than a shelf of documents, see the open-access paper A systematic approach for the protection of personal data and privacy.