Information Security Policy

LAST UPDATE — 15/09/2026

INBRAIN considers it essential to ensure the security of information according to ISO
27001 in all its dimensions, confidentiality, integrity, availability, as well as the security of
the processes, infrastructures, personnel, and other resources involved in the provision of
the company’s services.

With the objective of being a benchmark organization within its sector, INBRAIN is
committed to managing corporate security appropriately by protecting these elements
against potential threats, minimizing associated risks, and ensuring the continuity of its
business processes.

In the current environment, the protection of corporate information and the assets that
process it is of particular importance. These assets are critical to the organization and must
be reasonably safeguarded against any threat that may pose a risk to them. Information
security shall be ensured at all times in accordance with applicable legal, regulatory,
organizational, and technical requirements.

Accordingly, protecting information and maintaining its security constitutes a shared
responsibility and a strategic objective for the entire organization. All personnel must be
aware of and comply with this Information Security Policy, as well as the related
procedures, standards, rules, and guidelines that support its implementation.
To this end, INBRAIN establishes the following fundamental principles:

Compliance with legal and contractual requirements
INBRAIN shall comply with all applicable legal, regulatory, and contractual
requirements related to its activities, particularly those concerning the protection
of personal data, corporate information, and business continuity.

Appropriate use of information and systems
The use of information and information systems owned or managed by INBRAIN
shall be restricted to activities necessary for the proper performance of assigned
job responsibilities. The use of corporate assets for personal benefit is strictly
prohibited.
Confidentiality and non-disclosure
All personnel must maintain confidentiality regarding company information and
shall not disclose it to unauthorized third parties. Information may only be shared
when strictly necessary for legitimate business purposes and under appropriate
security controls.
Implementation of an Information Security Management System (ISMS)
INBRAIN shall establish, implement, maintain, and continually improve an
Information Security Management System (ISMS) in accordance with ISO/IEC 27001. The ISMS shall include the policies, procedures, standards, and controls
necessary to manage information security risks and to protect INBRAIN’s
information and assets.

INBRAIN’s Executive Management is committed to:
• Ensuring the implementation, maintenance, and continual improvement of the
ISMS.
• Providing the necessary resources to achieve information security objectives.
• Ensuring compliance with applicable information security requirements.
• Communicating this Information Security Policy within the organization and
making it available to relevant interested parties.

Failure to comply with this Policy, its associated directives, or applicable legal
requirements, may result in disciplinary or legal actions in accordance with internal
regulations and applicable legislation.