Information Security Policy

This is Available's top-level information security policy. It is approved by the CEO, reviewed at least annually, and published openly because we believe transparency about how we protect information builds justified trust.

Our commitment

Available builds and operates services that our clients trust with their information. Protecting the confidentiality, integrity, and availability of that information — and of our own — is a core business objective, owned by top management.

We operate an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022 and are pursuing certification. Our approach is risk-based: we identify what could realistically harm our clients or our business, and we invest in controls proportionate to those risks.

Principles

  • Risk-driven. Controls follow from an explicit, regularly reviewed risk assessment — not from checklists alone.
  • Least privilege. People and systems get the access they need, no more, reviewed regularly.
  • Secure by default. Multi-factor authentication, encryption in transit and at rest, and peer review of every change are baseline, not exceptions.
  • Privacy built in. We apply GDPR principles — data minimisation, purpose limitation, and clear supplier agreements — as part of security, not beside it.
  • Prepared, not surprised. We maintain tested backup and incident response processes, and we notify affected clients and authorities as our legal and contractual obligations require.
  • Everyone's job. Every employee and contractor receives security training and is required to report security events immediately. Reporting in good faith is always the right move and is never punished.
  • Continual improvement. Incidents, audits, and metrics feed a documented improvement cycle.

Scope and governance

This policy applies to all of Available: all employees, contractors, information, systems, and locations. It is supported by internal topic-specific policies (acceptable use, access control, information classification, secure development, supplier security, backup and recovery) and by documented procedures. Responsibility for the ISMS rests with our Security Lead; accountability rests with the CEO.

Failure to comply with this policy framework is handled through our normal management and, where necessary, disciplinary processes.

Questions

Clients and partners can read more on our trust site or contact us at security@available.dk (TODO: confirm address) — including to report a suspected vulnerability or security issue.

Version 0.1 · Last reviewed 2026-08-26