Legal Document

Information Security Policy

Risk-based information security policy for bi.expert services, systems, and operational governance.

Last revised: May 26, 2026. This policy applies to all interactions with bi.expert unless a stricter written agreement applies.

1. Security governance and policy objective

bi.expert applies a risk-based information security model to protect confidentiality, integrity and availability of business information, client assets, personal data and operational systems. Security controls are selected proportionately to business impact, threat exposure and legal obligations, including relevant EU and Dutch requirements for digital resilience and data protection.

Management is accountable for defining security priorities, assigning ownership and ensuring corrective actions are tracked. Personnel and contractors must follow least-privilege principles, secure handling procedures and incident reporting duties.

2. Core control domains

Our control framework covers identity and access management, secure configuration, patch and vulnerability management, backup governance, logging and monitoring, change control, supplier governance, endpoint protection and secure collaboration practices for project delivery.

Client-facing analytics outputs are handled with attention to data minimization, role-based access and traceability of critical definitions. High-sensitivity processing may trigger additional contractual controls, including project-specific security requirements, processing restrictions and verification steps.

  • Authentication controls: unique credentials, MFA where feasible, and periodic access review.
  • Data protection controls: classification, encryption in transit, and restricted access pathways.
  • Operational controls: controlled deployments, rollback planning and incident-ready logging.
  • People controls: confidentiality commitments and role-appropriate security awareness.

3. Incident response, reporting and continuous improvement

Security events are triaged according to severity and potential impact. We apply containment, investigation, remediation and post-incident review steps, with documented evidence and accountability. Where personal data may be affected, privacy assessment is coordinated with data-protection governance and notification duties under GDPR are evaluated without undue delay.

Reports of vulnerabilities or security incidents can be sent to [email protected]. We continuously improve controls based on threat intelligence, lessons learned, client requirements and legal/regulatory developments. Correspondence address: Keurenplein 41, UNIT A6260, 1069 CD, Amsterdam, The Netherlands.