Skip to content
FeaturesFeesSecurityFAQDownload app
Policy

Information Security Policy

1. Purpose and Commitment

Mondo Gate AG's core business objectives are to deliver secure fintech services, protect customer data, and maintain regulatory compliance. This policy establishes management's commitment to information security and provides the framework for the Information Security Management System (ISMS), operated in accordance with ISO/IEC 27001:2022, that supports those objectives.

Mondo Gate AG is committed to protecting the confidentiality, integrity, and availability of its information assets on an ongoing basis.

2. Scope

This policy applies to all Mondo Gate AG employees, contractors, and consultants, and to all information assets, systems, and third-party service providers operating on behalf of Mondo Gate AG.

3. Security Objectives

Mondo Gate AG pursues the following information security objectives:

  • Confidentiality: Information is accessible only to those authorised to access it.
  • Integrity: Information and systems are accurate and protected from unauthorised modification.
  • Availability: Information and systems are available to authorised users when required.
  • Privacy: Personal data is processed lawfully and in accordance with applicable data protection law.

4. Compliance Commitments

Mondo Gate AG is committed to:

  • Complying with applicable legal and regulatory requirements, including the EU General Data Protection Regulation (GDPR) and ISO/IEC 27001:2022.
  • Satisfying applicable information security requirements of customers, partners, and regulators.
  • Continuously improving the effectiveness of its ISMS.

5. Supporting Documents

This policy sits at the top of Mondo Gate AG's ISMS documentation hierarchy and is implemented through the following supporting documents.

5.1 Topic-specific policies

The following list is an excerpt.

  • Acceptable Use Policy
  • Data Protection Policy
  • Cryptography Policy
  • Password Policy
  • Remote Working Policy
  • Mobile Device Policy
  • Supplier Security Policy
  • AI Use Policy

5.2 Control set and procedures

Detailed control implementation — including access control, physical and environmental security, operations and network security, incident management, and business continuity — is defined in the Statement of Applicability (ISO27001-SOA-001) and the Annex A control documents (A.5 Organizational, A.6 People, A.7 Physical, A.8 Technological), supported by the ISMS operational procedures (including incident management, business continuity, internal audit, and document change control).

6. Review

This policy is reviewed annually and following any significant change to the organisation, its operations, or the risk environment. All material changes require approval by the CEO and CTO.