Information Security Policy

Version 3.0 — Issue date: 7 September 2026 — Classification: Public

Reporting a security issue

Found a vulnerability in a Prowide product or in one of our open source libraries? Email [email protected].

Please do not report it through a public channel such as a GitHub issue or discussion. For our open source libraries, see the security policy on GitHub: https://github.com/prowide/.github/blob/main/SECURITY.md

This notice is not part of the Information Security Policy below.

Document owner
Information Security Management System (ISMS) Lead
Accountable
Chief Technology Officer
Version
3.0
Issue date
7 September 2026
Next review date
7 September 2027, or sooner following a major change
Classification
Public

1. Purpose and Commitment

Prowide International S.A., which provides SWIFT messaging software for banks, vendors and developers, is committed to preserving the confidentiality, integrity and availability of all assets, including personally identifiable information, within the scope of its information security management system (ISMS), in order to compete in the marketplace and to maintain its legal, regulatory and contractual compliance and its commercial standing.

Prowide International S.A. is committed to ensuring compliance with all applicable legislative, regulatory and contractual requirements, including all applicable legislation on the protection of personally identifiable information.

To achieve this, Prowide International S.A. has implemented an ISMS in accordance with the international standard ISO/IEC 27001:2022. The ISMS is subject to continual, systematic review and improvement. This Policy is established by top management, is appropriate to the purpose of the organisation, and provides the framework within which the information security objectives set out in 10-ISMS Information Security Objectives and Measurement Plan are established and measured.

Where Prowide International S.A. uses artificial intelligence systems, their use is governed within the ISMS: only systems that Prowide International S.A. has approved may be used with its information, and the risks arising from their use are assessed and managed in the same way as any other information security risk.

2. Scope

This Policy applies to every person working under the control of Prowide International S.A., including Employees/Staff, contractors and consultants, and to all information and information processing facilities within the scope of the ISMS as defined in 01-ISMS Scope of the ISMS.

3. Policy Objectives

Prowide International S.A. sets the following objectives for its ISMS:

  • information is made available to all authorised parties with minimal disruption to the business processes;
  • information security and privacy risks are managed;
  • the integrity of information is maintained;
  • the confidentiality of information is preserved;
  • regulatory, legislative and other applicable requirements related to information security are met;
  • appropriate information security and privacy objectives are defined and measured;
  • appropriate business continuity arrangements are in place to counteract interruptions to business activities, and these take account of information security;
  • appropriate information security and privacy education, awareness and training is available to Employees/Staff and to relevant others, such as suppliers, working on behalf of Prowide International S.A.;
  • breaches of information security or privacy, and security incidents, whether actual or suspected, are reported and investigated through appropriate processes;
  • appropriate access control is maintained and information is protected against unauthorised access;
  • continual improvement of the ISMS is made as and when appropriate; and
  • compliance with all applicable legislation on personally identifiable information, including the contractual terms agreed between Prowide International S.A. and its clients, is achieved, supported and managed.

4. Roles and Responsibilities

Role Responsibility
Chief Technology Officer Is accountable for this Policy and for the outcomes of the ISMS. Is accountable for the management and maintenance of the risk treatment plan. Approves an exception to this Policy. Chairs the ISMS Governance Council.
ISMS Governance Council Supports the framework of the ISMS and is consulted on a request for an exception to this Policy.
ISMS Lead Owns this Policy, reviews it and keeps it up to date.
Line Managers Require the people they manage to apply information security in accordance with this Policy and the topic-specific policies beneath it.
Employees/Staff, contractors and consultants Comply with this Policy and with the ISMS that implements it, and report an information security event or weakness without delay.

Where additional risk assessments are necessary to determine appropriate controls for a specific risk, they are carried out.

5. The Policy Framework

This Policy is the highest-level statement of Prowide International S.A.'s approach to information security. The topic-specific policies below sit beneath it, carry the detailed requirements, and are read as part of it. Each person is responsible for reading and complying with those relevant to their role.

Policy Purpose
Acceptable Use of Assets Policy To identify assets and the responsibility for protecting them, and to set out their acceptable use.
Access Control Policy and Procedure To limit access to information, information processing systems, networks and facilities to authorised parties.
Business Continuity and Disaster Recovery Plan To prepare for extended service outages and to restore services in a minimum time frame.
Cryptography Policy To ensure the proper and effective use of cryptography and the protection of cryptographic keys.
Human Resource Security Policy To ensure that Employees/Staff and contractors meet security requirements and understand their responsibilities.
Incident Response Plan To manage information security incidents and events, and to guide those who respond to them.
Information Classification, Labelling and Handling Policy To ensure that information is classified, protected, retained and securely disposed of according to its importance.
Operating Procedures for IT Management To ensure the correct and secure operation of information processing systems and facilities.
Physical Security Policy To prevent unauthorised physical access to, or damage to, information and information processing facilities.
Risk Management Policy To define the method for assessing and managing information security risks.
Secure Development Policy To ensure that information security is designed into the development lifecycle for applications and information systems.
Supplier Management Policy To protect data and assets shared with, accessible to or managed by suppliers, and to maintain an agreed level of security and service delivery.

The complete set of documents that make up the ISMS, and their current versions, is recorded in the 00-ISMS Master List of Documents.

6. Compliance, Exceptions and Enforcement

Prowide International S.A. measures and verifies compliance with this Policy through ongoing monitoring, internal audit and external audit.

A request for an exception to this Policy is submitted to the Chief Technology Officer for approval. The ISMS Governance Council is consulted, and the exception is recorded with its justification and the period for which it applies.

A known violation is reported to the ISMS Lead. A violation may result in the immediate withdrawal or suspension of system and network privileges and, for an Employee/Staff member, in disciplinary action under the Employee Disciplinary Process. For a contractor or a consultant, it may result in action under their contract, including its termination.

7. Review

The ISMS Lead reviews this Policy at least annually, and sooner where a significant change to the organisation, its risks, its technology or the legal and regulatory requirements that apply to it makes a review necessary. The approved version is published in Vanta and on the Prowide International S.A. website.

Annex A — ISO/IEC 27001:2022 Coverage

Clause or control Title Addressed in
5.1 Leadership and commitment Sections 1 and 4
5.2 Policy The whole of this Policy
5.3 Organisational roles, responsibilities and authorities Section 4
7.3 Awareness Sections 3 and 5
A.5.1 Policies for information security Sections 5 and 7
A.5.4 Management responsibilities Section 4

The topic-specific requirements are addressed in the policies listed in Section 5, each of which records the controls it covers. Acceptable use, remote working, clear desk and clear screen, user endpoint devices, off-premises assets, return of assets, protection against malware and intellectual property rights are addressed in the Acceptable Use of Assets Policy and the Physical Security Policy; authentication information and access control in the Access Control Policy and Procedure; terms of employment, competence, awareness and the disciplinary process in the Human Resource Security Policy and the Employee Disciplinary Process; the reporting of an information security event in the Incident Response Plan; installation of software on operational systems in the Operating Procedures for IT Management; and the use of cloud services in the Supplier Management Policy.