Information Security Policy
Last updated: August 14, 2026 · Version 2.0.0
1. Objective and scope
This policy defines the principles and controls with which Sinapsis SpA protects the confidentiality, integrity and availability of its own information and that of its clients and users, across all the services it operates: sinapsis.in, the HumanOS platform (humanos.eco, empresa.eco, estudiante.humanos.eco), the QueBot assistant and consulting projects. We take the ISO/IEC 27001 standard and Chilean Law No. 21.663 (the Cybersecurity Framework Law) as design criteria; this reference does not imply formal certification unless expressly stated (see the Compliance Notice).
2. Principles
- Least privilege: every person and system accesses only the information needed for their role.
- Security by design: controls are defined when designing the solution, not after building it.
- Defense in depth: multiple layers of control across infrastructure, application and data.
- Traceability: relevant accesses and changes are logged.
- Continuous improvement: controls are reviewed and adjusted periodically.
3. Main controls
Technical and organizational measures currently in place:
- TLS/HTTPS encryption on all communications and encryption at rest in the database.
- Additional AES-256-GCM field-level encryption for sensitive health data (Chilean ID, diagnoses, allergies, clinical notes).
- Tamper-evident clinical audit logging for every access to health records.
- Role-based access control, least privilege and per-user, per-organization isolation (multi-tenant).
- Google OAuth 2.0 authentication; credentials, tokens and secrets managed in secure stores, with a ban on secrets in source code.
- Parameterized queries (ORM) against injection; security headers and CSP.
- Separation of development, testing and production environments.
- Periodic backups of essential information and restoration tests.
- Software components kept updated and patched.
4. Incident management
We maintain a security incident management procedure taking ISO/IEC 27035 as reference:
- Detection and reporting: any suspicious event can be reported to admin@sinapsis.in.
- Assessment and containment: we classify the incident, limit its scope and preserve the evidence.
- Notification: if the incident affects personal data and creates risk for data subjects, we notify the Chilean Personal Data Protection Agency and those affected without undue delay, in accordance with the Privacy Policy.
- Recovery and lessons learned: we restore the service and adjust controls.
5. Business continuity
We identify critical processes and maintain contingency and recovery plans, taking ISO 22301 as reference. We design solutions for resilience and fast recovery.
6. Suppliers
We assess the security of suppliers that process information on our behalf and require contractual commitments of confidentiality, security and use limited to our instructions. The current list of processors is in the Privacy Policy, section 11.
7. Responsible disclosure
If you discover a vulnerability in our services, please report it responsibly to admin@sinapsis.in before disclosing it publicly. We commit to responding and to taking no action against good-faith research.
8. Continuous improvement
We maintain a phased improvement plan, including two-factor authentication (2FA), data export in portable formats, SOC 2 readiness and external penetration testing. We align our management system with ISO/IEC 27001 and ISO/IEC 27701 as reference frameworks; formal adoption of certifications will be announced publicly.
9. Review
This policy is reviewed at least once a year, or upon significant changes in the services or in regulation. Each version is published frozen and verifiable through a SHA-256 fingerprint, like the rest of our legal documents.
10. Contact
- Security reports: admin@sinapsis.in
- Company: Sinapsis SpA (RUT 78.327.684-4), San Martín 924, Office 213, Temuco, Chile