Security Policy

Introduction

At Prometeo, we recognize the critical importance of leading the region's financial infrastructure landscape in information security and personal data protection. We constantly focus on maintaining and strengthening this privileged position by implementing state-of-the-art security practices.

By prioritizing security, we not only protect our valuable assets and data, but also inspire confidence among our stakeholders, reinforcing our reputation as a trusted and reliable partner in the industry.

Objective

The main objective of the General Information Security Policy is to safeguard the integrity, confidentiality, and availability of Prometeo's critical information assets. This policy seeks to establish a solid framework that ensures protection against internal and external threats, as well as the mitigation of risks associated with information management.

Scope

This policy applies to all employees, suppliers, and third parties that interact with the company's information systems. It covers all information assets, including but not limited to data, systems, networks, and processes related to business operations.

Information Security Principles

Under the premise of the continuous improvement of our Information Security Management System (ISMS), we are committed to ensuring a secure environment for our operations, aligned with all applicable Information Security requirements. To achieve this objective, we rely on the following principles:


Objective Setting

Establish annual Information Security objectives, and develop and update the action plan to achieve these objectives.

Risk Assessment and Treatment

Develop a security risk assessment and treatment process, and implement the appropriate corrective and preventive actions based on its results.
Access and Identity Control

Ensure that access to Prometeo's information and systems is strictly controlled. All access to technological and information resources will be granted based exclusively on the principles of "Least Privilege", "Need-to-Know", and segregation of duties. The use of robust authentication mechanisms, including multi-factor authentication (MFA), is mandatory for accessing critical systems, production environments, and sensitive data. Every digital identity must be unique, personal, and non-transferable.

Information Classification and Protection

Classify and label information according to current regulations and based on its value and importance to Prometeo. Generate, store, and transfer information, both internally and externally, always keeping the principles of confidentiality and integrity in mind, keeping information protected in transit, in processing, and at rest. Implement appropriate cryptographic mechanisms according to the information's classification to mitigate the risks associated with data handling.

Secure Software Development

Integrate security into all phases of the Secure Software Development Life Cycle (SSDLC), adopting a "security by design" approach. Prometeo's products and APIs must undergo rigorous and periodic code reviews and security testing (including vulnerability scanning and penetration testing) before and during their deployment to production, thereby guaranteeing resilient platforms against cyberattacks.

Threat and Vulnerability Management

Manage the vulnerabilities of our products and services through the release of appropriate updates, patches, and recommendations. Furthermore, extend this management to security threats and vulnerabilities throughout our entire environment, including our internal systems.

Third-Party and Vendor Management

Maintain a continuous process for third-party and vendor management. These parties must adhere to the principles of this policy and its derived procedures in order to protect the organization's information.

Guaranteeing Operational Continuity

Establish the necessary means to guarantee the continuity of critical operations and processes by developing business continuity and disaster recovery plans that align with our disruption tolerance in the event of adverse incidents.

Organizational Security Culture

Promote an organizational culture oriented towards information security. Involve and engage management in the dissemination, consolidation, and compliance of the policy.

Legal and Contractual Compliance

Comply with service, legal, or regulatory requirements and contractual security obligations.

Security Incident Management

Establish and maintain a robust framework for information security incident response and management, aligned with international standards and best practices. This framework must cover preparation, detection, analysis, containment, eradication, and recovery in the face of any adverse event. Furthermore, it is established that the entire Prometeo team, vendors, and third parties have the unavoidable responsibility to immediately report any security event, vulnerability, or breach, whether confirmed or suspected, strictly following the channels and procedures established by the organization.

Policy Communication

We will communicate our Security Policy to all stakeholders. It is key that it is integrated into our organizational culture through its dissemination via our security training and awareness plan. Additionally, this policy will be publicly available to all stakeholders.

Continuous Improvement and Audit

We intend to focus our efforts on the continuous improvement of our Information Security Management System (ISMS), implementing a cycle that includes the periodic review of our processes, the identification of areas for improvement, and the execution of corrective and preventive actions. Through this approach, we are committed to maintaining our leadership in the development of financial infrastructure, prioritizing information security and personal data protection. We will continue to elevate our customers' experience, ensuring compliance with relevant legal requirements and regulations, while innovating our products and services without compromising stability, security, or user experience. Under this premise, we will continue to build an open, secure, and connected financial ecosystem.

Consequences of Non-Compliance

Compliance with this policy is mandatory for all individuals associated with Prometeo. Any alleged violation will be formally investigated according to the guidelines of our Security Violation Policy. Confirmed violations will result in disciplinary actions proportional to their severity, intentionality, and impact. Additionally, in cases that cause damage to Prometeo, clients, or third parties, the organization may initiate the appropriate civil and/or criminal legal actions.

2026 Prometeo