Information Security Policy
Our Commitment to Data Protection and Privacy
SapphireOne is dedicated to enhancing its information security performance in alignment with our risk appetite. As a provider of software, implementation, and help desk services, we have access to our clients’ information and recognise the importance of safeguarding it at all times. Protecting sensitive data and maintaining strong security practices is fundamental to the trust placed in SapphireOne by our clients and partners.
We also need to secure our own information to ensure the effective operation of our business. By maintaining robust information security practices, SapphireOne aims to protect its internal systems, intellectual property, and operational data while continuing to deliver reliable and secure services to our clients.
Information Security Management System (ISMS)
To support our information security performance, SapphireOne is committed to implementing, maintaining, and continually improving our Information Security Management System (ISMS). We aim to achieve compliance with and certification to ISO 27001:2022. The ISMS and this policy are designed to provide a structured framework for managing security risks and protecting sensitive information across the organisation.
The ISMS and this policy are designed to achieve the following objectives:
- Confidentiality – Ensure that information is not disclosed to unauthorised individuals, entities, or processes.
- Integrity – Maintain the consistency, accuracy, and trustworthiness of information throughout its lifecycle.
- Availability – Guarantee that information is accessible and usable on demand by authorised parties.
Compliance and Legal Requirements
SapphireOne is committed to ensuring that our ISMS meets the requirements of our stakeholders, clients, and legal obligations for information security. Maintaining compliance with recognised standards helps ensure that our information security practices remain robust, transparent, and aligned with industry expectations.
To accomplish this, we are dedicated to engaging and equipping our staff with the necessary skills, training, and awareness to deliver information security outcomes that align with our risk appetite and organisational responsibilities.
Last reviewed date: 17/07/2025
John William Adams | CEO