Important:
This document is a professional draft, not legal advice. It must be reviewed against elyXion’s final legal entity details, implemented controls, suppliers, customer contracts, and actual operating practices before publication.
1. Purpose
This policy defines elyXion’s public information-security principles for protecting company, customer and service information.
2. Principles
elyXion seeks to preserve confidentiality, integrity and availability through risk-based controls including security by design, least privilege, strong authentication, tenant isolation, defence in depth, secure configuration, controlled change, encryption where appropriate, logging, vulnerability management, resilience, incident response and supplier assurance.
3. Responsibilities
Security is a shared responsibility. elyXion operates controls within its contracted service boundary; customers remain responsible for controls and decisions allocated to them.
4. Risk and assurance
Material risks should have an owner and traceable treatment. elyXion intends to align its control environment with relevant recognised European and international standards, but alignment must not be represented as certification unless actually achieved and valid.
5. Review
The policy is reviewed periodically and after material security, regulatory, architectural or operational change.
| Owner: | elyXion |
| Version: | 1.0 |
| Last updated: | 11 Aug 2026 |
| Status: | Draft for legal and operational review |
