Information Security Policy
Reporting a security issue
Found a vulnerability in a Prowide product or in one of our open source libraries? Email [email protected].
Please do not report it through a public channel such as a GitHub issue or discussion. For our open source libraries, see the security policy on GitHub: https://github.com/prowide/.github/blob/main/SECURITY.md
This notice is not part of the Information Security Policy below.
- Document owner
- Information Security Management System (ISMS) Lead
- Accountable
- Chief Technology Officer
- Version
- 3.0
- Issue date
- 7 September 2026
- Next review date
- 7 September 2027, or sooner following a major change
- Classification
- Public
1. Purpose and Commitment
Prowide International S.A., which provides SWIFT messaging software for banks, vendors and developers, is committed to preserving the confidentiality, integrity and availability of all assets, including personally identifiable information, within the scope of its information security management system (ISMS), in order to compete in the marketplace and to maintain its legal, regulatory and contractual compliance and its commercial standing.
Prowide International S.A. is committed to ensuring compliance with all applicable legislative, regulatory and contractual requirements, including all applicable legislation on the protection of personally identifiable information.
To achieve this, Prowide International S.A. has implemented an ISMS in accordance with the international standard ISO/IEC 27001:2022. The ISMS is subject to continual, systematic review and improvement. This Policy is established by top management, is appropriate to the purpose of the organisation, and provides the framework within which the information security objectives set out in 10-ISMS Information Security Objectives and Measurement Plan are established and measured.
Where Prowide International S.A. uses artificial intelligence systems, their use is governed within the ISMS: only systems that Prowide International S.A. has approved may be used with its information, and the risks arising from their use are assessed and managed in the same way as any other information security risk.
2. Scope
This Policy applies to every person working under the control of Prowide International S.A., including Employees/Staff, contractors and consultants, and to all information and information processing facilities within the scope of the ISMS as defined in 01-ISMS Scope of the ISMS.
3. Policy Objectives
Prowide International S.A. sets the following objectives for its ISMS:
- information is made available to all authorised parties with minimal disruption to the business processes;
- information security and privacy risks are managed;
- the integrity of information is maintained;
- the confidentiality of information is preserved;
- regulatory, legislative and other applicable requirements related to information security are met;
- appropriate information security and privacy objectives are defined and measured;
- appropriate business continuity arrangements are in place to counteract interruptions to business activities, and these take account of information security;
- appropriate information security and privacy education, awareness and training is available to Employees/Staff and to relevant others, such as suppliers, working on behalf of Prowide International S.A.;
- breaches of information security or privacy, and security incidents, whether actual or suspected, are reported and investigated through appropriate processes;
- appropriate access control is maintained and information is protected against unauthorised access;
- continual improvement of the ISMS is made as and when appropriate; and
- compliance with all applicable legislation on personally identifiable information, including the contractual terms agreed between Prowide International S.A. and its clients, is achieved, supported and managed.
4. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Chief Technology Officer | Is accountable for this Policy and for the outcomes of the ISMS. Is accountable for the management and maintenance of the risk treatment plan. Approves an exception to this Policy. Chairs the ISMS Governance Council. |
| ISMS Governance Council | Supports the framework of the ISMS and is consulted on a request for an exception to this Policy. |
| ISMS Lead | Owns this Policy, reviews it and keeps it up to date. |
| Line Managers | Require the people they manage to apply information security in accordance with this Policy and the topic-specific policies beneath it. |
| Employees/Staff, contractors and consultants | Comply with this Policy and with the ISMS that implements it, and report an information security event or weakness without delay. |
Where additional risk assessments are necessary to determine appropriate controls for a specific risk, they are carried out.
5. The Policy Framework
This Policy is the highest-level statement of Prowide International S.A.'s approach to information security. The topic-specific policies below sit beneath it, carry the detailed requirements, and are read as part of it. Each person is responsible for reading and complying with those relevant to their role.
| Policy | Purpose |
|---|---|
| Acceptable Use of Assets Policy | To identify assets and the responsibility for protecting them, and to set out their acceptable use. |
| Access Control Policy and Procedure | To limit access to information, information processing systems, networks and facilities to authorised parties. |
| Business Continuity and Disaster Recovery Plan | To prepare for extended service outages and to restore services in a minimum time frame. |
| Cryptography Policy | To ensure the proper and effective use of cryptography and the protection of cryptographic keys. |
| Human Resource Security Policy | To ensure that Employees/Staff and contractors meet security requirements and understand their responsibilities. |
| Incident Response Plan | To manage information security incidents and events, and to guide those who respond to them. |
| Information Classification, Labelling and Handling Policy | To ensure that information is classified, protected, retained and securely disposed of according to its importance. |
| Operating Procedures for IT Management | To ensure the correct and secure operation of information processing systems and facilities. |
| Physical Security Policy | To prevent unauthorised physical access to, or damage to, information and information processing facilities. |
| Risk Management Policy | To define the method for assessing and managing information security risks. |
| Secure Development Policy | To ensure that information security is designed into the development lifecycle for applications and information systems. |
| Supplier Management Policy | To protect data and assets shared with, accessible to or managed by suppliers, and to maintain an agreed level of security and service delivery. |
The complete set of documents that make up the ISMS, and their current versions, is recorded in the 00-ISMS Master List of Documents.
6. Compliance, Exceptions and Enforcement
Prowide International S.A. measures and verifies compliance with this Policy through ongoing monitoring, internal audit and external audit.
A request for an exception to this Policy is submitted to the Chief Technology Officer for approval. The ISMS Governance Council is consulted, and the exception is recorded with its justification and the period for which it applies.
A known violation is reported to the ISMS Lead. A violation may result in the immediate withdrawal or suspension of system and network privileges and, for an Employee/Staff member, in disciplinary action under the Employee Disciplinary Process. For a contractor or a consultant, it may result in action under their contract, including its termination.
7. Review
The ISMS Lead reviews this Policy at least annually, and sooner where a significant change to the organisation, its risks, its technology or the legal and regulatory requirements that apply to it makes a review necessary. The approved version is published in Vanta and on the Prowide International S.A. website.
Annex A — ISO/IEC 27001:2022 Coverage
| Clause or control | Title | Addressed in |
|---|---|---|
| 5.1 | Leadership and commitment | Sections 1 and 4 |
| 5.2 | Policy | The whole of this Policy |
| 5.3 | Organisational roles, responsibilities and authorities | Section 4 |
| 7.3 | Awareness | Sections 3 and 5 |
| A.5.1 | Policies for information security | Sections 5 and 7 |
| A.5.4 | Management responsibilities | Section 4 |
The topic-specific requirements are addressed in the policies listed in Section 5, each of which records the controls it covers. Acceptable use, remote working, clear desk and clear screen, user endpoint devices, off-premises assets, return of assets, protection against malware and intellectual property rights are addressed in the Acceptable Use of Assets Policy and the Physical Security Policy; authentication information and access control in the Access Control Policy and Procedure; terms of employment, competence, awareness and the disciplinary process in the Human Resource Security Policy and the Employee Disciplinary Process; the reporting of an information security event in the Incident Response Plan; installation of software on operational systems in the Operating Procedures for IT Management; and the use of cloud services in the Supplier Management Policy.