Information Security Policy

Last updated: August 14, 2026 · Version 2.0.0

1. Objective and scope

This policy defines the principles and controls with which Sinapsis SpA protects the confidentiality, integrity and availability of its own information and that of its clients and users, across all the services it operates: sinapsis.in, the HumanOS platform (humanos.eco, empresa.eco, estudiante.humanos.eco), the QueBot assistant and consulting projects. We take the ISO/IEC 27001 standard and Chilean Law No. 21.663 (the Cybersecurity Framework Law) as design criteria; this reference does not imply formal certification unless expressly stated (see the Compliance Notice).

2. Principles

3. Main controls

Technical and organizational measures currently in place:

4. Incident management

We maintain a security incident management procedure taking ISO/IEC 27035 as reference:

  1. Detection and reporting: any suspicious event can be reported to admin@sinapsis.in.
  2. Assessment and containment: we classify the incident, limit its scope and preserve the evidence.
  3. Notification: if the incident affects personal data and creates risk for data subjects, we notify the Chilean Personal Data Protection Agency and those affected without undue delay, in accordance with the Privacy Policy.
  4. Recovery and lessons learned: we restore the service and adjust controls.

5. Business continuity

We identify critical processes and maintain contingency and recovery plans, taking ISO 22301 as reference. We design solutions for resilience and fast recovery.

6. Suppliers

We assess the security of suppliers that process information on our behalf and require contractual commitments of confidentiality, security and use limited to our instructions. The current list of processors is in the Privacy Policy, section 11.

7. Responsible disclosure

If you discover a vulnerability in our services, please report it responsibly to admin@sinapsis.in before disclosing it publicly. We commit to responding and to taking no action against good-faith research.

8. Continuous improvement

We maintain a phased improvement plan, including two-factor authentication (2FA), data export in portable formats, SOC 2 readiness and external penetration testing. We align our management system with ISO/IEC 27001 and ISO/IEC 27701 as reference frameworks; formal adoption of certifications will be announced publicly.

9. Review

This policy is reviewed at least once a year, or upon significant changes in the services or in regulation. Each version is published frozen and verifiable through a SHA-256 fingerprint, like the rest of our legal documents.

10. Contact