Information Security Policy

Important:

This document is a professional draft, not legal advice. It must be reviewed against elyXion’s final legal entity details, implemented controls, suppliers, customer contracts, and actual operating practices before publication.

1. Purpose

This policy defines elyXion’s public information-security principles for protecting company, customer and service information.

2. Principles

elyXion seeks to preserve confidentiality, integrity and availability through risk-based controls including security by design, least privilege, strong authentication, tenant isolation, defence in depth, secure configuration, controlled change, encryption where appropriate, logging, vulnerability management, resilience, incident response and supplier assurance.

3. Responsibilities

Security is a shared responsibility. elyXion operates controls within its contracted service boundary; customers remain responsible for controls and decisions allocated to them.

4. Risk and assurance

Material risks should have an owner and traceable treatment. elyXion intends to align its control environment with relevant recognised European and international standards, but alignment must not be represented as certification unless actually achieved and valid.

5. Review

The policy is reviewed periodically and after material security, regulatory, architectural or operational change.

Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review