CustomsGo
Home Legal notice Privacy Terms
ES EN FR
Information security

Security policy

Principles, commitments and general guidelines governing the protection of information at VM2 Innovate Soft, S.L., owner of CustomsGo.

This is a courtesy translation. The legally binding version is the Spanish original; in the event of any discrepancy, the Spanish text prevails.

CustomsGo

ISMS and ISO/IEC 27001:2022

A common framework for preserving the confidentiality, integrity, availability, authenticity and traceability of information.

Back to home
Legal notice Privacy policy Terms of service

This Information Security Policy sets out the principles, commitments and general guidelines governing the protection of information at VM2 INNOVATE SOFT, S.L., owner of and responsible for the SaaS service CustomsGo.

Its purpose is to provide a common framework for preserving the confidentiality, integrity, availability, authenticity and traceability of information and of the assets that support it, and to strengthen the confidence of clients, employees, suppliers and other interested parties.

VM2 INNOVATE SOFT, S.L. establishes, implements, maintains and continually improves an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001:2022 standard.

VM2 INNOVATE SOFT, S.L. adopts the following general security principles:

Security by design and by default

Security must be built in from the earliest stages of the design, development, deployment, operation and evolution of CustomsGo. Default configurations must prioritise the protection of information and the minimisation of exposure.

Risk-based management

Security decisions will be based on the systematic, consistent and documented identification, analysis, evaluation and treatment of risks. The organisation will maintain risk criteria, a treatment plan and a Statement of Applicability consistent with its ISMS.

Shared responsibility

Information security is the responsibility of the whole organisation. Management provides leadership, resources and a framework for action, but every individual is responsible for protecting information and acting in accordance with this policy and the applicable procedures.

Compliance and proportionality

Security controls must be proportionate to the risk, to the type of information processed, to legal, regulatory and contractual requirements, and to the operational needs of the service.

Continual improvement

The ISMS will be continually reviewed and improved through the monitoring of indicators, risk assessment, incident handling, audits, corrective actions and management review.

Management commitments

The Management of VM2 INNOVATE SOFT undertakes to:

  • Establish and maintain this policy as documented information.
  • Ensure that the policy is appropriate to the purpose of the organisation and consistent with the business strategy.
  • Provide sufficient resources for the establishment, implementation, maintenance and improvement of the ISMS.
  • Define information security objectives and monitor their achievement.
  • Integrate information security into business, development, operations and support processes.
  • Assign roles, responsibilities and authorities relating to information security.
  • Promote a culture of security and awareness throughout the organisation.
  • Periodically review the effectiveness of the ISMS and support its continual improvement.

These commitments derive directly from clause 5 of the ISO/IEC 27001 standard.

VM2 INNOVATE SOFT, S.L. sets the following general security objectives:

  • Protect information assets against unauthorised access, alteration, loss, leakage or unavailability.
  • Ensure reasonable continuity of the CustomsGo service and the ability to recover from incidents.
  • Comply with the applicable legal, regulatory and contractual obligations.
  • Maintain effective information security risk management.
  • Strengthen staff training and awareness.
  • Continually improve the effectiveness of the ISMS and of the controls in place.

Information classification and handling

Information must be classified according to its sensitivity and criticality and handled in line with its required level of protection. Rules for access, use, storage, transmission and disposal will be defined in accordance with that classification.

Access and identity control

Access to information and systems will be granted in accordance with the principles of least privilege, need to know and individual identity. The organisation will manage, in a controlled manner, the life cycle of users, privileged accounts, authentication and remote access.

Secure development

The development and maintenance of CustomsGo will follow secure development practices, code review, change control, protection of test data and priority response to vulnerabilities in production.

Network, encryption and endpoint security

The organisation will apply appropriate measures for network protection, segmentation, encryption, hardening, system patching, screen locking, anti-malware protection and control over the use of devices and removable media.

Management of operations, changes and logs

Changes to systems and environments, backups, resource capacity, maintenance, the generation and retention of logs, and the traceability of security-relevant activity will all be controlled.

Incidents, vulnerabilities and continuity

The organisation will define and maintain procedures for the reporting, classification, response, analysis of and learning from security incidents, as well as for vulnerability management, business continuity and disaster recovery.

Third parties and the supply chain

Suppliers and third parties with access to VM2 information or assets must meet security requirements proportionate to their criticality. The organisation will control third-party relationships, confidentiality agreements, subcontracting and supply chain risks.

Training and awareness

All staff must receive initial and periodic information security training and awareness, according to their role.

Management will assign and communicate the roles and responsibilities relevant to information security. As a minimum, the following must be defined:

  • The authority responsible for the ISMS.
  • Those responsible for technical matters and operations.
  • Asset or information owners, where applicable.
  • The support, incident, document management, risk and review functions.

VM2 INNOVATE SOFT, S.L. undertakes to comply with the laws, regulations and contractual obligations applicable to information security, including the protection of personal data. Failure to comply with this policy may give rise to disciplinary, contractual or legal measures, depending on the severity and the applicable framework.

This policy will be communicated to all staff and made available to the relevant interested parties. Those who access the organisation’s systems or information will be required to read and accept it, as appropriate.

The policy will be reviewed at planned intervals and whenever significant changes occur in the context of the organisation, in risks, in applicable regulations, in the CustomsGo service or in the expectations of interested parties. That review will consider, where relevant, the impact of climate change on the context of the organisation and on the requirements of interested parties.

This Information Security Policy takes effect on the date of its approval by Management and is binding from that moment on all persons and entities within its scope.

Signed in Madrid, on 3 September 2026.

Mario García CEO - VM2 Innovate Soft, S.L.
CustomsGo

CustomsGo simplifies customs declaration management and helps companies work with clearer, better connected and more efficient processes.

Contact

  • +34 91 197 21 86
  • inbound@customsgo.com
  • Madrid · Barcelona

Legal

  • Privacy policy
  • Security policy
  • Legal notice
  • Terms of service
© CustomsGo. All rights reserved. Designed by IDEOS IT Solutions
↑