At Novahiring, a company dedicated to the design, development, operation, maintenance and support of the Nova Hiring platform for automating recruitment processes through artificial intelligence, including the management of the cloud infrastructure, customer and candidate data, third-party integrations and the associated support processes, we are aware of the importance that information security has today for the day-to-day conduct of our business and for the proper management of our organization's information and assets.
To ensure this management, Novahiring has implemented an Information Security Management System in accordance with the requirements of the ISO/IEC 27001:2022 standard, in order to guarantee the continuity of our information systems, minimize risks and ensure that the objectives set are met.
To guarantee the effectiveness and application of the Information Security Management System, an Information Security Committee is established, responsible for the approval, dissemination and enforcement of this Security Policy, as well as for the supervision, implementation, development and maintenance of the Management System.
The purpose of this Security Policy is to set the framework needed to protect information resources against threats, internal or external, deliberate or accidental, in order to ensure the confidentiality, integrity and availability of information. To this end, we make the following commitments:
- Comply with current legislation on information security.
- Ensure the privacy of the data managed by Novahiring on behalf of customers, employees, suppliers and third parties.
- Guarantee the confidentiality, availability and integrity of our organization's own information assets.
- Identify and reduce the information security risks relevant to our organization.
- Ensure the capacity to respond to emergencies, restoring critical services in the shortest possible time.
- Protect information assets according to their value or importance.
- Promote information security awareness and training.
- Establish a frame of reference for meeting information security objectives and targets, and for continual improvement of our activities and processes.
Every person whose activity may, directly or indirectly, be affected by the requirements of the Information Security Management System is obliged to strictly comply with this Security Policy.
Signed by: Guim Gorgues, CTO
Date: 18/06/2026