> For the complete documentation index, see [llms.txt](https://legal.delos-banking.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://legal.delos-banking.com/security/whitepaper.md).

# Whitepaper

## Delos Security Whitepaper

## Security at Delos

### Building Trust Through Security

At Delos, security is not treated as a standalone function or\
compliance exercise. It is a fundamental business capability that\
supports the trust placed in us by our customers, partners, and\
stakeholders.

We recognize that safeguarding information, maintaining\
operational resilience, and protecting the integrity of our services\
are essential responsibilities. Security considerations are embedded\
throughout our governance, operational processes, technology\
lifecycle, and decision-making practices.

Our objective is to maintain a security program that is\
proportionate to the risks we manage, aligned with recognized\
international standards, and continuously evolving to address\
emerging threats and changing business requirements.

### Security Governance

Delos maintains a structured information security program\
supported by executive leadership and integrated into organizational\
governance processes.

The program is designed to provide oversight of information\
security risks, support informed decision-making, promote\
accountability, and ensure that security objectives remain aligned\
with business priorities.

Security responsibilities are formally assigned, and governance\
activities include risk management, policy oversight, control\
effectiveness reviews, incident management, third-party risk\
management, and continuous improvement initiatives.

### Risk-Based Security Approach

Delos applies a risk-based methodology to the design,\
implementation, and operation of security controls.

Security, operational, technology, vendor, and business risks are\
regularly identified, assessed, evaluated, and managed through\
established governance processes. Risk management activities support\
the prioritization of security initiatives and the ongoing\
improvement of the control environment.

This approach enables Delos to maintain a balanced and sustainable\
security posture while supporting business growth and innovation.

### Security Program

The Delos security program incorporates administrative, technical,\
and organizational measures intended to protect the confidentiality,\
integrity, and availability of information and services.

The program includes areas such as:

* Information security governance
* Identity and access management
* Vulnerability management
* Security monitoring and response
* Secure development practices
* Third-party risk management
* Business continuity and resilience
* Security awareness and training
* Data protection and privacy controls
* Continuous assessment and improvement

Security activities are periodically reviewed to ensure continued\
effectiveness and alignment with evolving risks and business needs.

### Secure Operations

Delos maintains operational processes designed to support the\
secure and reliable delivery of services.

Security considerations are incorporated into the management of\
systems, applications, changes, vendors, and operational activities.\
Processes are established to support the identification, evaluation,\
escalation, and remediation of security-related issues when\
appropriate.

Operational resilience and service reliability remain important\
considerations across all stages of service delivery.

### Product and Development Security

Security is considered throughout the lifecycle of products and\
technology services.

Development, deployment, and change management activities are\
supported by security practices intended to reduce risk, promote\
consistency, and strengthen the overall security posture of the\
organization.

Security requirements are incorporated into relevant stages of\
planning, implementation, testing, and operational management.

### Security Monitoring and Incident Management

Delos maintains capabilities intended to support the\
identification, assessment, investigation, and management of security\
events and incidents.

Established processes guide incident handling activities,\
including assessment, escalation, containment, recovery,\
communication, and post-incident review where applicable.

Lessons learned from operational events are used to strengthen\
processes, controls, and organizational resilience.

### Business Continuity and Operational Resilience

Maintaining the continuity of critical business operations is an\
important element of the Delos security program.

Business continuity and recovery capabilities are designed to\
support operational resilience and help ensure that services can\
continue to be delivered or restored following disruptive events.

These capabilities are reviewed periodically as part of the\
organization's ongoing risk management and resilience efforts.

### Third-Party Risk Management

Delos recognizes the importance of managing risks associated with\
external service providers and business partners.

Third-party relationships are evaluated using a risk-based\
approach that considers factors such as security, operational\
resilience, regulatory obligations, and business impact.

Appropriate oversight activities are performed throughout the\
lifecycle of applicable vendor relationships.

### Security Awareness and Culture

Security is a shared responsibility across the organization.

Personnel are expected to understand and fulfill their security\
responsibilities through adherence to established policies,\
procedures, and standards. Security awareness initiatives support a\
culture of accountability, risk awareness, and responsible handling\
of information and technology resources.

### Continuous Improvement

Delos views security as an ongoing process rather than a fixed\
state.

Our security program is regularly reviewed and enhanced through\
governance activities, risk assessments, operational experience,\
industry developments, and evolving business requirements.

This commitment to continuous improvement helps ensure that\
security remains effective, relevant, and aligned with organizational\
objectives.

### Alignment with Recognized Standards

The Delos security program is informed by recognized international\
security frameworks, standards, and industry best practices.

These include principles and control domains commonly associated\
with:

* ISO/IEC 27001:2022
* SOC 2 Trust Services Criteria
* NIST Cybersecurity Framework
* OWASP Security Practices

Delos continues to invest in the maturity and effectiveness of its\
security and compliance capabilities as part of its long-term\
operational strategy.

### Contact

For security, compliance, privacy, or third-party risk management\
inquiries, please contact:

[**security@delos.financial**](mailto:security@delos.financial)
