Integrated Management Policy

The AIRCURY Group is a business group dedicated to the design, development, deployment, operation and maintenance of software solutions and digital services, supported by cloud infrastructure and a predominantly remote working model, providing services to national and international clients.

AIRCURY Group Management recognises that service quality, environmental protection, effective management of information technology services, and information security are strategic elements for sustainability, client trust, regulatory compliance and business continuity.

To this end, AIRCURY establishes and maintains an Integrated Management System, in accordance with ISO 9001, ISO 14001, ISO/IEC 20000-1, ISO/IEC 27001 and the requirements of the National Security Framework (RD 311/2022), committing to its implementation, maintenance and continuous improvement.

Management

AIRCURY Group Management commits to:

  • Providing the necessary resources for the proper functioning of the Integrated Management System.
  • Ensuring leadership, accountability and involvement at all levels of the organisation.
  • Integrating the principles of quality, environmental management, service management and information security into the strategy and business processes.
  • Fostering a preventive culture focused on continuous improvement, risk management and operational excellence.

Quality

AIRCURY, with regard to quality, commits to:

  • Providing software services and solutions that meet applicable client, legal and contractual requirements.
  • Ensuring the planning, control and improvement of the processes that support service delivery.
  • Measuring and analysing process performance and client satisfaction as a basis for continuous improvement.
  • Managing risks and opportunities that may affect the quality of the services provided.

Environment

AIRCURY acknowledges its responsibility for environmental protection and commits to:

  • Complying with applicable environmental legislation and other requirements subscribed to by the organisation.
  • Preventing pollution and minimising the environmental impacts arising from its activities, particularly those associated with the use of technological and energy resources.
  • Promoting the efficient use of resources, reduction of consumption and proper waste management.
  • Integrating the environmental perspective into decision-making and the continuous improvement of the management system.

IT Services

AIRCURY, with regard to IT services, commits to:

  • Planning, designing, delivering, operating and improving information technology services in a controlled manner, consistent with the needs of the business and clients.
  • Defining and maintaining service level agreements, support processes and performance monitoring mechanisms.
  • Adequately managing incidents, problems, changes and service continuity.
  • Ensuring alignment between IT service management and the strategic objectives of the organisation.

Information Security

AIRCURY recognises that information and the systems that support it are critical assets and commits to:

  • Protecting the confidentiality, integrity, availability, authenticity and traceability of information.
  • Complying with the requirements of ISO/IEC 27001:2022 and the National Security Framework, in accordance with the defined scope and categorisation level.
  • Applying a risk-based approach to identify, assess and address threats that may affect information and services.
  • Implementing appropriate technical, organisational and procedural controls to prevent security incidents and respond to them effectively.
  • Ensuring the continuity of services and the resilience of information systems.

Our People

AIRCURY Group and its people commit to:

  • Ensuring staff competence and training in relation to quality, the environment, service management and information security.
  • Fostering individual awareness and responsibility in compliance with established policies, rules and procedures.
  • Promoting the active participation of staff in the improvement of the Integrated Management System.

Compliance

AIRCURY's compliance management commits to:

  • Identifying and complying with the legal, regulatory and contractual requirements applicable to its activities.
  • Periodically evaluating the performance of the Integrated Management System through monitoring, measurement, internal audits and management reviews.
  • Applying corrective and improvement actions to increase the effectiveness, efficiency and maturity of the system.
  • Maintaining this Policy as a reference framework for setting objectives and improvement plans.

This Integrated Management Policy is communicated to all staff and relevant interested parties, and is available for consultation.

The Policy will be reviewed periodically, and whenever significant changes occur in the organisation, its activities, context or applicable requirements.

Approved by: AIRCURY Group Management

Date of issue: 12 January 2026