Appfront B.V. designs, builds and manages custom software for clients in sectors including finance, healthcare, industry, mobility and the (semi-)public sector. Much of the information we process on behalf of clients is sensitive: personal data, trade secrets, source data from business processes and integrations with core systems. Information security is therefore not an optional layer, but a prerequisite for our services.
This information security policy describes the principles we apply, the normative framework within which we work, the technical and organisational measures we take, how we handle client data and incidents, and what you can expect from us as a client, partner or reporter. The policy applies to all employees, freelancers, interns and contractors working on behalf of Appfront, and to all systems in which we process data: our own infrastructure, development environments, and client environments we manage, to the extent contractually agreed.
The policy is a living document. We update it whenever legislation, standards or our operations require it, with a fixed annual review as a minimum. Changes are published on this page, stating the version date. For clients and auditors who wish to cite this policy in vendor onboarding or a risk assessment, the version on this page at the time of consultation applies. Questions about how this policy applies to a specific engagement or audit can be sent to security@appfront.nl.