Security and Compliance as a Public Commitment


 


TRUST CENTER

Assertiva operates under the highest information security standards. This page centralizes our regulatory compliance statement, applied frameworks, and current policies, available to clients, vendors, and all stakeholders.​

 Estado operativo: Conforme |Última revisión: Julio 2026

ISO/IEC 27001:2022

SGSI · Certificado ·

01 153 2632206 

Law 21,719

Personal Data Protection · Chile

 Framework Law 21,663

Cybersecurity · Declared VIO

Active Transparency

 Public and Auditable Policies

Current Documents

Security Policies


Our policies are approved by General Management and are publicly available to all stakeholders interacting with Assertiva.

​Active  

POL-0234 · Version 1.0 · 04/21/2026

General Information Security Policy

Establishes the general guidelines to protect Assertiva's information assets within the ISMS framework aligned with ISO/IEC 27001:2022.

 ISO 27001 CIA SGCI Continuous Improvement​


View Policy

Active 

POL-0506 · Version 1.0 · 05/21/2026

 Vendor Management and Information Security Policy

Defines the security requirements for vendors and strategic partners, including risk assessment, access control, and contract lifecycle management.

 A.5.19 A.5.23 Third-party​ Risk


View Policy

REGULATORY COMPLIANCE

Legal Frameworks and Applied Standards

 Assertiva formally declares its alignment with current Chilean and international regulations regarding security, cybersecurity, and personal data protection.

Information Security Management System (ISMS)


Standard international reference · In formal certification process


Assertiva implements and maintains an Information Security Management System (ISMS) aligned with the requirements of the ISO/IEC 27001:2022 standard. This framework governs risk identification and treatment, control selection, periodic system reviews, and the continuous improvement of all security processes.

93+ Controls

Documented and aligned with Annex A of the standard.

Total Scope

Employees, vendors, and authorized third parties.

Continuous Improvement

PDCA cycle applied to all ISMS processes.

Internal Audit

Periodic compliance and risk reviews. 


Law

21,719


Chile - Data

Personal Data Protection


Chile’s new data protection law - Active alignment with its principles


Assertiva recognizes Law 21,719 as the current regulatory framework for personal data protection in Chile and is committed to respecting its principles when processing the data of clients, employees, and third parties.

Personal data is processed based on the principles of lawfulness, purpose, proportionality, and security. Technical and organizational measures aligned with ISO 27001 ISMS controls are implemented to protect data against unauthorized access, loss, or unlawful processing.

Security Principle

Active technical and organizational controls.

Proportionality

Minimum data required for each processing activity.

Purpose Limitation Principle

Data processed solely for declared legitimate purposes.

Data Subject Rights

Enabled procedures to exercise rights.


VIO

​Law 21,663

Vital Importance Organization — Cybersecurity Framework Law

Law 21,663 · Chile’s Framework Law on Cybersecurity and Digital Infrastructure


 

Chile’s Framework Law on Cybersecurity and Digital Infrastructure (Law 21,663) establishes the institutional framework for national risk management and incident response, creating the National Cybersecurity Agency (ANCI) and defining the category of Vital Importance Organizations (VIO).

VIO CATEGORY APPLICABLE TO ASSERTIVA

"Institutions engaged in digital infrastructure activities, digital services, and information technology services managed by third parties."

Assertiva declares its alignment with the duties established for VIOs under Law 21,663, by virtue of the nature of its advisory services in risk, cybersecurity, and managed digital infrastructure. This alignment is underpinned by the implemented ISMS under ISO/IEC 27001:2022, which constitutes the formal mechanism for risk management, control implementation, and incident response required by law.

Assertiva’s ISO 27001 framework covers the areas required for VIOs: continuous cybersecurity risk management, measures to prevent and mitigate incidents, timely incident reporting to ANCI, and the adoption of recognized international standards as a reference to protect its services and those of its clients.


Continuous cybersecurity risk managementd


 Active prevention and response measures


 Timely incident reporting to ANCI

Assertiva Risk Advisory · Trust Center

Inquiries regarding compliance and security: ciberseguridad@assertiva.biz

Public statement approved by the General Management of Assertiva. May 2026.

 ISO 27001:2022

 Law 21,719

 Law 21,719