For the complete documentation index, see llms.txt. This page is also available as Markdown.

Whitepaper

Delos Security Whitepaper

Security at Delos

Building Trust Through Security

At Delos, security is not treated as a standalone function or compliance exercise. It is a fundamental business capability that supports the trust placed in us by our customers, partners, and stakeholders.

We recognize that safeguarding information, maintaining operational resilience, and protecting the integrity of our services are essential responsibilities. Security considerations are embedded throughout our governance, operational processes, technology lifecycle, and decision-making practices.

Our objective is to maintain a security program that is proportionate to the risks we manage, aligned with recognized international standards, and continuously evolving to address emerging threats and changing business requirements.

Security Governance

Delos maintains a structured information security program supported by executive leadership and integrated into organizational governance processes.

The program is designed to provide oversight of information security risks, support informed decision-making, promote accountability, and ensure that security objectives remain aligned with business priorities.

Security responsibilities are formally assigned, and governance activities include risk management, policy oversight, control effectiveness reviews, incident management, third-party risk management, and continuous improvement initiatives.

Risk-Based Security Approach

Delos applies a risk-based methodology to the design, implementation, and operation of security controls.

Security, operational, technology, vendor, and business risks are regularly identified, assessed, evaluated, and managed through established governance processes. Risk management activities support the prioritization of security initiatives and the ongoing improvement of the control environment.

This approach enables Delos to maintain a balanced and sustainable security posture while supporting business growth and innovation.

Security Program

The Delos security program incorporates administrative, technical, and organizational measures intended to protect the confidentiality, integrity, and availability of information and services.

The program includes areas such as:

  • Information security governance

  • Identity and access management

  • Vulnerability management

  • Security monitoring and response

  • Secure development practices

  • Third-party risk management

  • Business continuity and resilience

  • Security awareness and training

  • Data protection and privacy controls

  • Continuous assessment and improvement

Security activities are periodically reviewed to ensure continued effectiveness and alignment with evolving risks and business needs.

Secure Operations

Delos maintains operational processes designed to support the secure and reliable delivery of services.

Security considerations are incorporated into the management of systems, applications, changes, vendors, and operational activities. Processes are established to support the identification, evaluation, escalation, and remediation of security-related issues when appropriate.

Operational resilience and service reliability remain important considerations across all stages of service delivery.

Product and Development Security

Security is considered throughout the lifecycle of products and technology services.

Development, deployment, and change management activities are supported by security practices intended to reduce risk, promote consistency, and strengthen the overall security posture of the organization.

Security requirements are incorporated into relevant stages of planning, implementation, testing, and operational management.

Security Monitoring and Incident Management

Delos maintains capabilities intended to support the identification, assessment, investigation, and management of security events and incidents.

Established processes guide incident handling activities, including assessment, escalation, containment, recovery, communication, and post-incident review where applicable.

Lessons learned from operational events are used to strengthen processes, controls, and organizational resilience.

Business Continuity and Operational Resilience

Maintaining the continuity of critical business operations is an important element of the Delos security program.

Business continuity and recovery capabilities are designed to support operational resilience and help ensure that services can continue to be delivered or restored following disruptive events.

These capabilities are reviewed periodically as part of the organization's ongoing risk management and resilience efforts.

Third-Party Risk Management

Delos recognizes the importance of managing risks associated with external service providers and business partners.

Third-party relationships are evaluated using a risk-based approach that considers factors such as security, operational resilience, regulatory obligations, and business impact.

Appropriate oversight activities are performed throughout the lifecycle of applicable vendor relationships.

Security Awareness and Culture

Security is a shared responsibility across the organization.

Personnel are expected to understand and fulfill their security responsibilities through adherence to established policies, procedures, and standards. Security awareness initiatives support a culture of accountability, risk awareness, and responsible handling of information and technology resources.

Continuous Improvement

Delos views security as an ongoing process rather than a fixed state.

Our security program is regularly reviewed and enhanced through governance activities, risk assessments, operational experience, industry developments, and evolving business requirements.

This commitment to continuous improvement helps ensure that security remains effective, relevant, and aligned with organizational objectives.

Alignment with Recognized Standards

The Delos security program is informed by recognized international security frameworks, standards, and industry best practices.

These include principles and control domains commonly associated with:

  • ISO/IEC 27001:2022

  • SOC 2 Trust Services Criteria

  • NIST Cybersecurity Framework

  • OWASP Security Practices

Delos continues to invest in the maturity and effectiveness of its security and compliance capabilities as part of its long-term operational strategy.

Contact

For security, compliance, privacy, or third-party risk management inquiries, please contact:

security@delos.financial

Last updated