All legal & policiesInformation Security
VitaeForge legalBSHQ-LGL-015

Information Security Policy

The principles and controls established to protect BioStackHQ information systems, data and digital infrastructure.

Version
1.0
Status
Published
Effective
24 July 2026
Authority
Board of Directors
01

Security Objective

BioStackHQ is committed to protecting information assets against unauthorised access, misuse, disruption or loss.

This Policy applies to BioStack HQ information systems, devices, accounts, networks, applications, records and facilities, as well as to personnel and third parties with authorised access to them.

Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.

Security controls are selected according to risk and may include identity management, least-privilege access, encryption, secure development, backup, logging, monitoring, supplier assurance and incident response. No control eliminates all risk; suspected incidents must be reported promptly through designated channels.

02

Security Controls

Appropriate administrative, technical and organisational safeguards are implemented based on the nature and sensitivity of information.

This Policy applies to BioStack HQ information systems, devices, accounts, networks, applications, records and facilities, as well as to personnel and third parties with authorised access to them.

Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.

Security controls are selected according to risk and may include identity management, least-privilege access, encryption, secure development, backup, logging, monitoring, supplier assurance and incident response. No control eliminates all risk; suspected incidents must be reported promptly through designated channels.

03

Continuous Improvement

Security practices are reviewed periodically to address evolving technology risks and operational requirements.

This Policy applies to BioStack HQ information systems, devices, accounts, networks, applications, records and facilities, as well as to personnel and third parties with authorised access to them.

The responsible owner shall maintain proportionate procedures, records and review arrangements to give effect to this provision. Any exception requires appropriate authority, documentation and, where the risk warrants it, consultation with the Office of Legal & Governance or another competent control function.

Security controls are selected according to risk and may include identity management, least-privilege access, encryption, secure development, backup, logging, monitoring, supplier assurance and incident response. No control eliminates all risk; suspected incidents must be reported promptly through designated channels.