Trust Center

Transparency, security and compliance to build trust.

A space to explain how we work, how we protect information and how we structure trust with customers and third parties.

How we work

Six verifiable commitments.

Security by design

Security headers, protected storage, access control and activity traceability.

Privacy and GDPR

Consent, record of processing activities, minimisation and limited retention of commercial data.

Data location

Ready to operate with local storage or controlled infrastructure, depending on scope.

AI governance

Inventory, risks, evidence and ISO/IEC 42001 and AI Act maturity assessment.

Responsible disclosure

Reporting channel for vulnerabilities and responsible handling of evidence.

Continuity

Continuity plans, backup, recovery and review of critical capabilities.

This website

Security and privacy applied to our own site.

We apply to bomontec.net the same principles we recommend to our clients.

  • Security headers: CSP with a per-request nonce, HSTS, X-Frame-Options, Referrer-Policy and Permissions-Policy.
  • Form with CSRF protection, honeypots, submission limits, server-side validation and an in-house captcha with no third-party services.
  • Requests stored on our own infrastructure with restricted access and purging under a retention policy.
  • No third-party cookies by default: analytics are only enabled with explicit consent.
  • Fonts and assets served from our own domain, with no external CDNs.
  • Responsible vulnerability disclosure channel.

Frameworks and standards

The frameworks that structure our work.

We do not present them as our own certifications unless contractually applicable; they are reference frameworks for designing, implementing, reviewing and evidencing.

ISO 27001ISO 22301ENSNIS2DORANIST CSFISO/IEC 42001CRAAI ActGDPRCIS ControlsPCI DSSOWASPMITRE ATT&CK

AI governance

Artificial intelligence with control and evidence.

Inventory, risks, evidence and ISO/IEC 42001 and AI Act maturity assessment, both for our clients and for the group's internal use of AI.

AI inventory

Which systems are used, with what data and for what purpose.

Risk assessment

Classification under the AI Act and impact analysis.

ISO/IEC 42001 evidence

AI governance records ready for audit.

Maturity

Ongoing assessment and adaptation plan.

Let's talk

Ready to take the first step?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.