Information Security Policy
Purpose
The purpose of this Information Security Policy is to provide and protect the information and
property of Indivi from all threats, whether internal or external, incidental or intentional. It
establishes the overarching framework for the Information Security Management System
(ISMS) to ensure the continued Confidentiality, Integrity, and Availability (CIA) of all information
assets, maintaining alignment with ISO/IEC 27001:2022, ISO 13485:2016, Good Clinical Practice
(GCP), and applicable data privacy regulations.
Scope
This policy applies to all individuals, entities, or processes that interact with any Indivi
information resource. The scope encompasses the information systems and supporting
processes involved in the development, deployment, and operation of software and platforms
for digital biomarkers, including the clinical web platform and mobile applications (both
provisioned and BYOD), as well as the ingestion, processing, and analysis of clinical data.
Information Security Principles and Directives
Indivi respects and enforces the core principles of preserving Confidentiality, Integrity, and
Availability. To achieve our strategic security objectives, the following directives are mandated
across the organisation:
Identity and Access Management (IAM): Access to Indivi information resources shall be
strictly governed by the Principle of Least Privilege (PoLP) and the "need-to-know" basis.
Multi-Factor Authentication (MFA) is mandatory for access to all corporate and clinical
services.Endpoint and Device Security: All end-user devices — whether corporate-owned or
personal devices used under the BYOD framework — must comply with Indivi's approved
cybersecurity baselines prior to accessing corporate networks or data.Data Governance and Classification: All information and data handled by Indivi must be
formally classified according to its sensitivity, criticality, and legal obligations. Appropriate
cryptographic and access controls shall be applied proportionally to the data's classification
level.Continuous Monitoring and Auditing: Critical information systems and cloud infrastructures
must be subject to continuous security monitoring. Audit trails and system logs shall be
centrally collected and evaluated to support incident response and regulatory compliance.Regulatory and Legal Compliance: Indivi shall comply with all applicable regulatory and legal
requirements, including but not limited to GDPR, the Swiss Federal Act on Data Protection
(FADP), HIPAA, and contractual agreements with clinical sponsors.Information Security in Project Management (Security by Design): Information security
and privacy principles shall be formally integrated into project management across the
business for projects of all kinds. This ensures a "Secure and Private by Design and by
Default" approach is embedded throughout the entire project lifecycle.
Responsibilities
Executive Management (Leadership Team): Responsible for ensuring that an appropriate
risk-based Information Security Program is implemented and for providing adequate
resources to secure the organisation's mission.Information Security Officer (ISO) / ISMS Representative: Responsible for leading the
Security Team, assessing risks, managing compliance with statutory requirements, and
reporting annually to Executive Management on the effectiveness of the ISMS.All Employees, Contractors, and Third Parties: Must understand their responsibilities,
complete mandatory awareness training, and use Indivi Information Resources in strict
compliance with all Information Security Policies.
References
ISO/IEC 27001:2022
ISO 13485:2016
ICH E6(R3) – Good Clinical Practices
Contact Information
For questions or concerns about this policy, please contact our Information Security Team at security@indivi.io.
History
This policy is reviewed regularly to adapt to evolving risks and organizational needs.
Revision history:
August 2021: Initial version 1.1
September 2022: version 2.0
March 2024: version 13.0
December 2024: version 17.0
June 2025: version 21.0
July 2026: version 1.0 under SC DMS