Company Policy

1. Objective and Scope

Getik establishes a unified operational framework designed to guarantee the consistent delivery of high-quality software products and services while maintaining the highest standards of confidentiality, integrity and availability for all information assets.
The physical and digital boundaries of this Integrated Management System (IMS) encompass all business processes, engineering workflows and corporate operations executed across our office locations, alongside our entire underlying hybrid infrastructure. This operational perimeter ensures a secure and efficient environment for both the delivery of services and the storage of critical data.
The IMS explicitly covers all on-premises resources, including office network infrastructure, secure physical IT infrastructure, version control systems, automated delivery platforms and centralized storage solutions. Furthermore, the scope extends to cloud-native ecosystems, encompassing collaborative suites, document management environments and all authorized cloud-based services utilized for business operations.
The IMS, which incorporates both our Information Security Management System and Quality Management System, specifically covers the development and delivery of financial software solutions. Systems, infrastructure and data operated by banking clients on their own premises fall outside the scope of this IMS, as the organization does not store or process end-customer data.
We maintain and continually improve this system in accordance with the internationally recognized standards of ISO/IEC 27001 and ISO 9001. By aligning corporate quality goals with rigorous security parameters, we fulfill our strategic commitment to customer satisfaction, continuous improvement and sustainable business growth. This comprehensive approach ensures that all operations strictly adhere to relevant statutory and regulatory requirements, providing a robust foundation for excellence in software development and information security.

2. Management Commitment and Funding

Management Commitment

Top management formally assumes full responsibility for the effectiveness, maintenance and continual improvement of the IMS, ensuring ongoing conformity with quality and security standards. This leadership commitment involves actively promoting a robust information security and quality culture across the entire organization, ensuring that security is integrated into the core of all business operations.
Leadership directly oversees the approval of all core IMS policies and remains actively informed regarding any significant security or quality events, ensuring that our strategic direction remains resilient against evolving operational and digital threats.

Resource Allocation

To ensure the long-term success of our quality and security initiatives, management guarantees the allocation of the necessary budget, human resources and logistical support. This commitment encompasses the acquisition of appropriate security tools, the continuous professional development of our teams through specialized training and the maintenance of our underlying infrastructure. By prioritizing these resources, leadership ensures that Getik maintains the technical and intellectual capacity to uphold its security and quality benchmarks.

Management Reviews

Accountability is demonstrated through a mandatory management review process conducted at planned intervals. These evaluations, involving top management and key functional representatives, provide a formal forum for analyzing system performance, review outcomes and risk assessments. The objective of these reviews is to identify specific opportunities for improvement and establish new security and quality measures that align with the company's long-term business goals.

3. Operational Planning and Control

Operational planning and control of integrated quality and information security activities is implemented through dedicated internal procedures.
These frameworks cover change management, incident management, vulnerability management, corrective actions and security monitoring.
These procedures define the criteria for high-quality software development and secure operation, establish controls to keep processes aligned with planned arrangements and ensure that outsourced processes are identified, monitored and controlled.

4. Continual Improvement

We continually improve the suitability, adequacy and effectiveness of the Integrated Management System. Opportunities for improvement are systematically identified through internal audits, management reviews, corrective actions, post-event incident reviews and periodic risk and opportunity assessments.
All improvement actions are tracked in a centralized platform with assigned owners and deadlines to ensure a cycle of continuous enhancement that aligns with our organizational quality and security objectives.

5. Compliance, Enforcement and Disciplinary Actions

All personnel and stakeholders are expected to operate in full accordance with the legal and regulatory mandates governing our activities, ensuring the highest level of corporate integrity. This includes compliance with the General Data Protection Regulation (GDPR) to protect the privacy of personal data and the Digital Operational Resilience Act (DORA) to maintain the robustness of digital infrastructures against cyber threats. Additionally, we integrate applicable environmental legislation into our operational workflows to fulfill our commitments regarding sustainability and resource management.
Failure to comply with the mandates outlined in this policy or any associated security and quality procedures will result in immediate investigation and subsequent enforcement actions. Disciplinary measures are applied consistently and fairly, following the provisions of the applicable Labor Code and contractual terms, up to and including termination of the employment or contractual relationship. The organization reserves the right to pursue legal action for serious breaches that compromise intellectual property, client confidentiality or institutional security.

6. Green Computing and Cloud Optimization

The organization integrates environmental sustainability into its operational framework by implementing strategic measures to reduce its carbon footprint and ensure the efficient utilization of IT resources.
A core component of this optimization involves enforcing strict automation rules for managing non-production environments. Specifically, non-production test and staging instances, whether hosted locally or in the cloud, are programmed for automatic shutdown outside of regular working hours and throughout weekends. This proactive approach significantly reduces energy consumption and minimizes the environmental impact associated with maintaining idle computing power.
Furthermore, we maintain a rigorous standard for the disposal of decommissioned hardware through a formal e-waste management process.
Before any physical asset is retired, it undergoes a secure data erasure procedure to protect information security. Once sanitized, all decommissioned hardware is transferred to authorized recycling centers specializing in Waste Electrical and Electronic Equipment (WEEE) to contribute to a sustainable circular economy.

7. Climate Change Resilience

We systematically identify and assess how climate change and shifting environmental conditions may affect our business operations and infrastructure.
To safeguard against these risks, climate resilience is integrated into our broader business continuity and risk management strategies. This includes preparing for potential power shortages or grid instabilities that may arise from extreme weather, as well as establishing robust protocols to ensure the continued safety and productivity of our remote workforce during severe meteorological phenomena.

8. Single Source of Truth and Document Control

We maintain a centralized, secure repository for all security and quality documentation, establishing a definitive single source of truth. Access to these repositories is strictly controlled and restricted to authorized personnel, ensuring that the integrity and confidentiality of our governing documentation remain intact.
All formal documentation follows a standardized revision protocol. Each document undergoes a comprehensive lifecycle that includes creation, formal review and official approval before being released. Obsolete versions are systematically archived to prevent accidental use in operational environments.

9. IMS KPIs

The effectiveness of the Integrated Management System is monitored through regular performance evaluations using objective, system-generated data extracted from centralized workflow and version control platforms.

  • Quality KPIs: Focused on software delivery excellence, quality of deliverables, and client satisfaction metrics.
  • Security KPIs: Focused on the frequency and severity of security events, vulnerability remediation timelines and adherence to secure engineering workflows.

The consolidated results are analyzed during management reviews to ensure that technical and individual performance directly supports our broader quality and security objectives.

10. Integrated Governance and Collaboration

To maintain a cohesive and efficient system, key organizational functions and roles work in close coordination:

  • Strategic Leadership: Sets the overall direction of the IMS, approves policies, allocates critical resources and conducts management reviews.
  • Security & Infrastructure Oversight: Directs technical security controls, monitors vulnerabilities and manages incident response operations.
  • Quality & Delivery Management: Ensures engineering workflows and development processes adhere strictly to quality standards and client expectations.
  • Engineering & Product Teams: Comply with secure coding practices, quality-by-design principles and participate in security training.
  • Operations & Support Functions: Manage physical security, secure personnel lifecycles (such as onboarding and offboarding compliance) and continuous security awareness initiatives.

Segregation of duties must be implemented for all identified critical roles and activities, ensuring that responsibilities are assigned to different individuals within the organization.
These functions collaborate dynamically to ensure that Getik continuously meets all statutory, regulatory and contractual obligations. While standard quality and security benchmarks are integrated into our core delivery model, we accommodate specific client contractual arrangements and service level agreements (SLAs) through tailored, project-specific execution frameworks.