Skip to content

Governance

Compliance

How we manage our legal, regulatory, and contractual compliance obligations as part of our security program.

Last reviewed: July 2026

We operate our information security program with compliance in mind. This page describes how we manage the legal, regulatory, and contractual obligations that apply to our business.

Our approach

We maintain guidelines for managing the regulatory, legal, and contractual compliance requirements that apply to our systems, in line with applicable security standards and good practice. Our information security program is established and operated with due consideration for statutory, regulatory, and contractual obligations, as well as any specific security requirements.

Identifying applicable requirements

We define and document the relevant statutory, regulatory, and contractual requirements that apply to our operations and information systems, and our policies and procedures are designed to adhere to the applicable laws.

Intellectual property rights

We comply with the terms, conditions, and license requirements of copyrighted software, customer intellectual property, and any other proprietary information used within the organization.

Protecting records

We protect our records related to information security from loss, destruction, and falsification, in accordance with statutory, regulatory, contractual, and business requirements.

Data protection and privacy

We ensure data protection and privacy as required by applicable data protection and privacy legislation and regulations, and by the contractual clauses we agree with our customers.

Appropriate use of information processing facilities

Our information processing facilities are used in accordance with this and our related policies, including our Acceptable Use Policy and Code of Business Conduct.

Compliance with security policies and standards

Our functional leads ensure that the security procedures within their area of responsibility are carried out correctly, so that we achieve compliance with our security policies and standards.

Independent audits

We conduct periodic audits by competent, independent parties to check compliance with our information security policies, procedures, standards, and guidelines. We plan and agree audit activities carefully to minimize the risk of disrupting business processes, follow formal procedures for planning, reporting, and remediating findings, and protect access to audit tools to prevent misuse or compromise.

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]