SECURITY STATEMENT · YARIPO

Security Statement

Yaripo SpA integrates information security as a strategic capability across its consulting services, analytical solutions, digital products, training platforms and cloud environments. This statement summarises the protection, control, resilience and continuous improvement approach that Yaripo applies or seeks to apply in the context of an enterprise-ready operation.

Executive summary

Security as a business capability

Yaripo conceives information security not merely as a technical requirement, but as an enabling capability for trust, resilience, compliance and commercial scalability. This approach is especially relevant in services linked to data, artificial intelligence, automation, advanced analytics and cloud environments.

Positioning. This statement is designed to support conversations with enterprise clients, procurement, compliance, technology, security and risk management teams, without implying any current formal certification or promises that exceed Yaripo's real operational maturity.
Maturity approach

Aligned, but not certified

Yaripo can structure its security practices with reference to internationally recognised frameworks, particularly those used in corporate and regulatory environments. Notwithstanding this, this statement should not be interpreted as evidence of formal ISO certification or a completed external audit.

Correct reading. When Yaripo states it is “aligned with”, “inspired by” or “designed to support” a standard, this should be understood as a design and governance reference, not formal accreditation, unless an express certification or verification exists.
01

General security approach

Security as a strategic function

Information security at Yaripo is approached through a risk management logic, protection of critical assets, access control, operational resilience and continuous improvement. This approach seeks to reduce exposure to incidents, reinforce client trust and protect sensitive information in the context of consulting, digital products, training and artificial intelligence solutions.

Security is integrated by design where reasonably practicable, taking into account the nature of the service, the client context, the type of data involved and the level of operational criticality.

02

Scope of this statement

Services, platforms and covered environments

This statement covers, as applicable, the operation and evolution of:

03

Reference frameworks and standards

Alignment with international standards

Yaripo may draw on recognised security and privacy frameworks, particularly those useful for B2B and enterprise environments, including best practices associated with:

Interpretation. Reference to these frameworks expresses an intention of methodological alignment and progressive maturity, not current formal certification.
04

Guiding principles

Confidentiality, integrity and availability

Yaripo's security architecture is organised around classic and extended principles of information protection:

05

Applicable security controls

Access, encryption, monitoring and more

Depending on the type of service, environment or deployment, Yaripo may apply controls such as the following:

Technical note. The term hardening refers to the strengthening or reinforcement of configurations to reduce attack surface, disable unnecessary components and improve the security posture of systems and services.
06

Protection of sensitive and critical data

Personal, commercial and technical information

Yaripo may process or interact with information requiring enhanced protection, including personal data, confidential commercial information, technical documentation, enterprise datasets, prompts, inputs, outputs and configurations associated with AI or advanced analytics solutions.

Protection of this information is addressed in accordance with its criticality, purpose, sensitivity and applicable contractual or regulatory requirements.

07

Cloud architecture and multicloud approach

Open and evolving infrastructure

Yaripo may operate on cloud infrastructure, including single-cloud or multicloud architectures, depending on the nature of the service and client requirements. Although certain environments may initially be implemented on specific providers, the design stance remains open and non-exclusive.

The strategy considers secure configurations, logical segmentation, prudent use of managed services, permissions review, credential protection and adoption of provider-native best practices where relevant.

08

Security incident management

Response, containment and notification

Yaripo may maintain processes for the identification, analysis, containment, mitigation and learning from information security incidents, in proportion to the nature and criticality of the affected service or environment.

Where applicable, notification to clients, counterparties or authorities will be carried out prudently and in accordance with applicable legal, regulatory or contractual obligations, avoiding over-commitment on absolute timelines not expressly agreed.

Contractual prudence. Specific commitments regarding notification, escalation or response times should be understood as primarily defined by contract, security annexes or individual agreements with each client.
09

Third-party and vendor management

Dependency assessment and control

Yaripo may rely on third parties for infrastructure, analytics, communications, cloud, automation, observability, collaboration or training. In this context, a reasonable vendor assessment is sought based on criticality, access, sensitivity of the information processed and associated risks.

Where relevant, Yaripo may require or review commitments on confidentiality, security, privacy, access segregation or processing in accordance with service requirements.

10

Resilience, continuity and recovery

Backup and operational continuity

Operational continuity is addressed through measures proportionate to the service context, including backups, restoration, configuration recovery, reasonable redundancy where applicable and review of critical dependency points.

In services where continuity or recovery is materially relevant to the client, specific commitments must be defined by commercial or contractual agreement.

11

Relationship with enterprise clients

Shared and contractual responsibility

Yaripo understands that in enterprise environments, security is to a large extent a shared responsibility between vendor, client, platform, cloud provider and internal operations. Effective security therefore also depends on the service scope, approved configuration, integration flows, information classification and the client's own operational discipline.

Due diligence. This statement may serve as a general security posture framework, but does not replace due diligence questionnaires, security annexes, DPAs, control matrices, RACI charts or specific contractual clauses.
12

Maturity, evolution and future certification

Strengthening roadmap

Yaripo projects a progressive evolution of its security posture, including documentary formalisation, strengthening of controls, governance maturity and eventual preparation for certification or audit processes when the business, scale and commercial demand justify it.

In particular, standards such as ISO/IEC 27001 or ISO/IEC 27701 may constitute reasonable future maturity milestones, especially as Yaripo expands its enterprise operations, client base and exposure to procurement and compliance requirements.

Correct commercial reading. Yaripo can demonstrate technical expertise and operational experience in security prior to holding formal certification. Future certification would strengthen that position, but does not exhaust the real capacity to design, operate or advise with solid judgement in this area.