Information Security Policy
1. Purpose
SEPIA Innovations recognises that information is a critical asset for our customers and for our own operations. This policy sets out how we protect the confidentiality, integrity and availability of that information.
2. Scope
This policy applies to all officers and employees of SEPIA Innovations, to all contractors and partners acting on our behalf, and to all information systems we operate — including those we administer for customers.
3. Management structure
A designated officer is responsible for information security. Responsibilities, review cycles and escalation paths are defined and reviewed at management level.
4. Legal compliance
We comply with the laws, regulations, standards and contractual obligations that apply in each jurisdiction where we operate — Japan, India and the United States.
5. Education
All employees receive information security education on joining and at regular intervals thereafter. Education is adapted to the systems each role touches.
6. Continuous improvement
We review this policy and our security controls regularly, and revise them in response to changes in threat, technology, regulation and our own operations.