Legal

Policy on Information Security

Last modified January 25, 2024

This document is the Information Security Policy of SQUAKE.earth GmbH (SQUAKE), Brunnenstraße 19-21, 10119 Berlin.

It represents binding rules for us, the employees of SQUAKE, with regards to:

  • the context in which we operate with our company and to what extent information security plays a role in this;
  • what information security policy we are pursuing together;
  • which interested parties have which requirements for the information security we provide;
  • which information security targets we therefore define as binding for us;
  • the scope of our information security management system (ISMS) – i.e., where and in which activities we comply with all information security regulations in a binding manner;
  • what roles and responsibilities we have for information security;
  • which regulations we have established to achieve our information security goals and meet the requirements of ISO 27001.

Context of the organization

The mission statement of SQUAKE is:

Striving toward sustainability and bringing down carbon emissions has become a priority on many levels in recent times. At SQUAKE, we support companies to reach their goals on the way toward operating in a CO2-reduced way. Our focus is to decarbonize the travel & transport sector and foster sustainably operating businesses in travel and transport. Founded in the heart of Berlin, we are on the way of becoming the go-to tech solution for businesses who want to act in an impactful way today. We are trusted by clients, partners, and venture capital.

From our mission statement, we have the following external and internal context to consider:

  • External context: Our clients are mainly active in the sectors Travel and Logistics. Our value proposition is comprised of two elements: Carbon emission calculations (fostering visibility to drive awareness around emissions), and emission compensations (reducing net CO2 emissions today). Services are made accessible through the SQUAKE API. Processing of business information is a key part of our business. It is therefore our duty to protect data and information assets (customer-facing & supplier-facing, entrusted to us & self-generated) in relation to confidentiality, integrity and availability, in order to underline our right to play and earn the trust that is put into us.
  • Internal context: We develop, host and operate the SQUAKE API as well as adjacent services with our team of employees and trustful service providers. Our own claim is that the SQUAKE API meets highest industry standards in terms of performance, availability and security. Internally, we focus on adding most value to our clients, designing processes in a scalable manner by default, as well as accruing data treasuries for future actions. The Code Base encapsulates the technological essence of the product and represents our intellectual property. The services are hosted and executed on our Infrastructure. Processing and storage of all business activities takes place in our Database.

Information Security Policy

We consider information security to be an essential value that we want to offer. Much depends on the information security (confidentiality, integrity and availability) of information processed by our solutions. The market is strictly regulated, security and trust are highest good. As a tech organization, IS is a strategic component, we need to provide big players that are our clients.

We express this through the following voluntary commitment:

  • We are committed to complying with all legal information security regulations and those contractually stipulated by clients and partners, and to using information provided by authorities and other organizations to continuously improve information security.
  • We train all employees who perform activities in the scope of information security in such a way that they can act safely and consciously in terms of information security.
  • We create the necessary technical and organizational conditions that enable us to live information security.
  • We want to achieve that information security is not understood by all of us as "annoying extra work", but as important and essential for clients, strategy and ultimately success. We must turn on our heads and not rely on the fact that following the established rules is sufficient in every situation. If we are faced with the choice of making something really secure or following a rule, we prefer to make it really secure – and adjust the rule if necessary.
  • We want to get better and better in our information security!

We provide resources and an information security management system according to the international norm ISO/IEC 27001:2022 for the above.

Improving our information security

We improve our information security using an overall approach which works as follows:

  • We plan improvements by means of identifying and managing risks, corrective and preventive actions and identifying in a planned manner to incidents and events.
  • We do improve by implementing what we planned in step 1.
  • We check if our improvements do what they are supposed to do by effectiveness checks on what we implemented, internal audits and measurements of our information security objective KPIs.
  • We act on the results of the checks and based on this, continue with step 1.

Interested parties

Based on our context, we have the following parties interested in information security:

Interested PartyConfidentialityIntegrityAvailabilityRelevant Requirements
Clients who use SQUAKE's services (external)Data provided by clients reg. emissions as well as API usage statistics may, if not protected, lead to insights into company secrets. It is an imperative that this shall not happen.Part of our offering (such as company emission data) is used as steering measures for top management; other information informs invoices. It is necessary that all data is always 100% correct. This means, it shall not be corrupted by unauthorized access and be changed in order to compromise it.In many cases, our API is built into our clients' online services. If our service fails due to unavailable content, the client cannot provide its service properly either. Furthermore, clients need to retrieve company emissions data and usage statistics for management reviews or ad hoc questions.GTC that cover i.a. confidentiality aspects & integrity, SLA agreement, DPA if required by client.
Customers of our clients, especially end-customers (external)End-customers interact directly with us a merchant of record; protection of the highly sensitive data used for identification and/or payments must clearly be ensured.End-customers will see information on compensation projects as well as prices for these compensations. Self-evidently, this information needs to be accurate and correspond to the customer's request. Confirmations sent to end-customers need to match actual purchases. This means, it shall not be corrupted by unauthorized access and be changed in order to compromise it.A customer journey should not be disrupted nor noticeably decelerated by our services; minimal latency and consistent uptime is required.GDPR compliance, special care regarding PCI data in case it is processed.
Shareholders (external & internal)In our own interest and that of our shareholders, assets that constitute competitive advantages must be kept secret.Shareholders and potential investors want to see performance KPIs. These should reflect the real performance of the company. This means, it shall not be corrupted by unauthorized access and be changed in order to compromise it.Shareholders and potential investors want to see performance KPIs from time to time.Awareness to protect IP engrained in team.
Management (internal)Our software solution will only be accepted in the market if it does not inadvertently or through targeted hacking reveal information that would be better left confidential.Our software solution will only be accepted on the market if it is not possible to unintentionally or through targeted hacking change information that should better be secured against it.Our software solution will only be accepted on the market if all the information constituting our service as well as information processed in it is constantly available to our clients.Security standards brought to live by effective management procedures; ISO 27001 certifications as per its marketing effect.
Employees (internal), applicants, former employeesIt is harmful to the company's business, and therefore to job security, if our software unintentionally or through targeted hacking exposes information that would be better left confidential. Employee data may under no circumstances be leaked, as publicity around that would negatively impact willingness to apply for jobs at SQUAKE.Performance KPIs need to be accurate to enable steering the business on strategic, tactical and operational levels. This means, it shall not be corrupted by unauthorized access and be changed in order to compromise it.Performance KPIs need to be available on ad hoc basis on all management levels.GDPR compliance regarding personnel data. Effective IP clauses in employee contracts.
Contractors and service providers such as Traction Engineering (external & internal)*Copyrights must be preserved in both directions according to contracts.To prevent unnecessary work, the right version of the code should be worked on.Tools used for collaboration must be retrievable for effective service provision.Effective IP clauses in agency contracts.
Suppliers (external)Suppliers regularly share prices and inventory information with us, which under no circumstances should be viewed by competitors (potentially also partners of us).Suppliers use our digital platform as a sales channel. Information provided by us will inform business steering and thus needs to be secured against unintentional or hacked changes.Suppliers have an economical interest that our digital services keep on being available, as we represent one sales channel for them.Confidentiality established either via GTC or NDA.
Other partners, e.g. data merchants, rating agencies, business intelligence, landlord (external)In case we partner with vendors with whom we have agreed on NDA, disclosed information categorized as confidential needs to be kept confidential.License agreements, clear requirements from SQUAKE towards them, NDAs in some cases.
Certifiers, verifiers, auditors, advisers (external)-Information architecture shall enable checks of veritable information logged, to undertake certification, e.g. TN-CC 020. This means, it shall not be corrupted by unauthorized access and be changed in order to compromise it.Information architecture shall enable regular checks, mostly announced, to undertake certification, e.g. TN-CC 020.Clauses around acceptable use of assets towards the service provided.
Legislator, Judiciary, Executive forceCompliance with all applicable data protection and copyright laws.Compliance with all applicable data protection laws.Compliance with all applicable data protection laws.All applicable laws.
Cyber criminalCyber criminals may want to hack our systems and attack confidentiality in a harmful way by leaking information. (This means, we need to equip our systems against it.)Cyber criminals may want to hack our systems and attack data integrity in a harmful way by changing it. (This means, we need to equip our systems against it.)Cyber criminals may want to hack our systems and impact system availability in a harmful way. (This means, we need to equip our systems against it.)Effective protection established by SQUAKE.

* Upon building and expanding our services, we closely work together with external contractors and service providers. Internally set rules need to be applied by them, in order for us to credibly vouch for it. The table highlights the expectations from them to us. SQUAKE takes all needs and expectations seriously and addresses them.

Information Security Objectives

Derived from stakeholder interests, we have the following information security goals:

  • Confidentiality: We strive to ensure that all information considered to constitute our offering, provided by others to use our offering, as well as derived from using our services is not disclosed to any unauthorized person. We will measure this by counting how many incidents we suffer with effect on any stakeholder in which information has been improperly kept confidential and how many cases we discover ourselves during our internal acceptance tests before delivery. We aim for: less than 2 per year.
  • Integrity: We strive to ensure that all information processed through our software solution is secured against unauthorized and accidental modification/falsification during processing. We will measure this by how many incidents get reported where information has been or could be changed without authorization and how many cases we discover ourselves after roll-out. We aim for: less than 2 per year.
  • Availability: In the development, operation and hosting of the services constituting our digital platform, we strive to ensure that the application is available at all times. We will measure this by whether we manage to achieve an API uptime of 99.9%.

Scope

Derived from the information security objectives defined above, the scope of our information security management system is:

Development, hosting and operation of sustainability applications and adjacent services.

Adjacent services are constantly extended and enhanced over time. They can be static or dynamic. For now, they include (but are not limited to):

  • Information material for the compensation projects we sell which can be used by clients for marketing and communication purposes
  • API code snippets to facilitate implementation
  • The tracking of according API activities via the client dashboard
  • A trust page to track the forthgoing of the project a client has invested in
  • Send-out of confirmation documents to clients that substantiate the transaction
  • The settlement of any service transaction on client side
  • The settlement of any service transaction on supply side

Roles, responsibilities, and communication

Essential roles in the scope of our information security management system are:

RoleName(s)Responsibility & Authority
Managing DirectorsPhilipp von Lamezan (CEO), Dan Kreibich (CPO)Communicate externally on all information security matters. Overall responsibility for information security; responsible for and owner of all information security risks.
Chief Information Security Officer (CISO)Antonia AdamikImplementation and maintenance of the information security management system, competence development in the field of information security, support and first point of contact on all information security issues.
Internal AuditorExternal providerExecution of internal audits.
Lead Software DeveloperLudwig ReinmiedlInformation secure software development, operation and hosting as well as risk management in this area.
Product ManagerNicolai BrunnerContinuous high quality delivery and improvement of features throughout touchpoints.
Head of OperationsAntonia AdamikEnsuring that business operations at SQUAKE are adequately implemented and interlock, from client integration throughout data retrieval to provision of supply.
Chief of StaffChristopher TyrockEnsuring that all employee-related data processing and storage is compliant with requirements from GDPR and ISO 27001.

All other roles and responsibilities result from the individual processes.

Communication on the topic of information security takes place at SQUAKE as follows:

  • Externally: In order to learn about changing requirements for information security topics from external stakeholders in a timely manner, client-facing teams, Product and Operations are in constant contact with them. SQUAKE actively inquires about requirements and communicate information security issues (e.g., risks or incidents) to them as necessary.
  • Internally: The Chief Information Security Officer (CISO) keeps the topic of information security communicated internally at SQUAKE and is accessible to all employees. Through training and awareness campaigns, "consultation hours", Notion posts, brief information in staff meetings, and other similar means, they keep the topic of information security in the conversation.

All other communications are described in more detail in the process descriptions or SQUAKE's ISMS.

Rules

The requirements of ISO/IEC 27001:2022 are covered in this information security management system as follows:

Standard sectionCovered by
4.1 Understanding the organization and its contextThis document
4.2 Understanding the needs and expectations of interested partiesThis document
4.3 Defining the scope of the ISMSThis document
4.4 ISMSThis document
5.1 Leadership and commitmentThis document, Statement from Management towards ISMS
5.2 PolicyThis document
5.3 Roles, responsibilities and authorities in the organizationThis document, All process descriptions
6.1 Measures to deal with risks and opportunitiesSOP Information Security Risk Management
6.2 IS goals and planning to achieve themThis document, SOP Management Review
7.1 ResourcesThis document, SOP Management Review
7.2 CompetenceSOP Training
7.3 AwarenessSOP Training
7.4 CommunicationThis document
7.5 Documented informationSOP Document Control
8.1 Operational planning and controlAll process descriptions
8.2 IS risk assessmentSOP Information Security Risk Management
8.3 IS risk treatmentSOP Information Security Risk Management
9.1 Monitoring, measurement, analysis and evaluationSOP Performance Measurement
9.2 Internal auditSOP Internal Audit
9.3 Management evaluationSOP Management Review
10.1 Non-conformity and corrective actionsSOP Corrective and Preventive Action (CAPA)
10.2 Continuous improvementSOP Information Security Event and Incident Management
Annex AStatement of Applicability