Last updated: October 25, 2025
At Ingealimite Technology S.A.S we consider cybersecurity a fundamental pillar of our technology operations. We are committed to ensuring the confidentiality, integrity, availability and traceability of our clients', users' and strategic partners' information, protecting their data against unauthorized access, improper manipulation, loss or destruction.
We recognize that we operate in a highly interconnected digital environment where cyber risks constantly evolve. We implement preventive, corrective and continuous monitoring measures backed by international standards and a security culture throughout the organization.
1. Principles of our cybersecurity policy
Our security strategy is based on the following principles:
-
Confidentiality: only authorized individuals may access sensitive or critical information.
-
Integrity: we ensure that data remains complete, accurate and protected against unauthorized changes.
-
Availability: systems, services and platforms will be available to legitimate users when needed.
-
Authenticity: we ensure that all communication and information exchanges come from verified sources.
-
Traceability: all relevant system activities are logged, monitored and audited.
2. Scope of this policy
This policy applies to all areas, projects and products developed by Ingealimite Technology S.A.S, including:
-
Solutions core banking and financial middleware.
-
Mobile applications and web platforms.
-
Multichannel transactional bots and AI for fraud prevention.
-
Predictive educational systems and enterprise ERPs.
-
Cloud infrastructure, internal networks and support systems.
3. Security controls implemented
To protect information assets and services, Ingealimite Technology S.A.S implements cybersecurity controls and measures such as:
-
Encryption of data in transit and at rest using AES-256 and TLS 1.3 standards.
-
Multifactor authentication (MFA) for administrative access and critical systems.
-
Identity management and least privilege, preventing unnecessary access.
-
Network segmentation and role-based access control (RBAC).
-
Encrypted backups with disaster recovery plans (DRP).
-
24/7 monitoring of security events and anomaly detection using SIEM.
-
Penetration tests and regular audits following methodologies from OWASP y MITRE ATT&CK.
-
Vulnerability management with continuous assessments and automatic updates.
-
Malware and ransomware protection through EDR and sandboxing solutions.
4. Security incident management
We have a Incident Response Plan (IRP) that enables us to detect, contain, mitigate and document any event affecting information security.
Incidents are classified by severity and addressed through coordination between technical, legal and communications teams.
If an event affects personal or financial data, the measures taken will be communicated promptly and competent authorities will be informed in accordance with applicable law.
5. Organizational culture and training
At Ingealimite Technology S.A.S, we believe cybersecurity is a human issue as well as a technical one.
We therefore provide ongoing staff training in digital security, data protection, ethical information handling, social engineering, phishing and cyber hygiene.
Each team member is responsible for following internal policies and immediately reporting suspicious activity or potential breaches.
6. Regulatory compliance and audits
Our infrastructure and processes are aligned with leading international security standards, including:
-
ISO/IEC 27001: Information Security Management.
-
ISO/IEC 22301: Business continuity.
-
PCI DSS: Payment card data protection.
-
NIST Cybersecurity Framework: Identify, protect, detect, respond and recover.
We also conduct internal and external audits regularly to ensure compliance, identify emerging risks and strengthen digital defenses.
7. Shared responsibility
Maintaining security is a shared responsibility between Ingealimite Technology S.A.S and users who interact with our platforms.
We recommend that all users:
-
Maintain strong passwords and do not share credentials.
-
Regularly update their devices and browsers.
-
Do not enter confidential information on public or unsecured networks.
-
Report suspicious activity to: seguridad@ingealimite.com
8. Continuous improvement and commitment
Cybersecurity is a dynamic process. We therefore review and update our policies, technologies and defense protocols regularly to anticipate new threats.
Our goal is to maintain a digital environment that is secure, reliable and resilient, protecting the trust of clients who rely on us to operate their businesses and financial systems.
Ingealimite Technology S.A.S reaffirms its commitment to digital security, fraud prevention, technological innovation and cyber resilience as essential pillars for driving the digital transformation of Latin America's financial and business sectors.