Policies

ISO 9001

Quality Management

ISO 27001

Information Security Management

ISO 27701

Privacy Information Management

TSE SPICE

Software Process Capability

Our Management System Certifications

We prioritize quality, information security, the protection of personal data and the continual improvement of our processes in the products and services we provide to our customers. The management system certifications we hold, which conform to international standards, reflect this approach and our sense of corporate responsibility.

ISO 9001

Quality Management System

An international standard for quality management systems, ISO 9001 was created for the purpose of meeting customer expectations, raising service quality sustainably and continually improving organizational processes.

In line with the ISO 9001 approach, we manage our processes so that they can be measured, monitored and improved. We evaluate customer feedback, regularly review the effectiveness of our processes, and are guided by a commitment to continual improvement.

Our aim is to provide our customers with reliable, high-quality products and services that not only meet today’s needs but also adapt as those needs evolve.

ISO/IEC 27001

Information Security Management System

Information is one of today’s most valuable assets. An international standard for information security management systems, ISO/IEC 27001 aims to protect the information assets that organizations hold in line with the principles of confidentiality, integrity and availability.

As an ISO 27001 certified company, we manage information security risks systematically, apply the administrative and technical controls needed to protect our information assets, and continually review our processes.

Through this approach, we aim to keep the information of our customers, business partners and employees secure, to stay prepared for potential information security risks, and to provide reliable services.

ISO/IEC 27701

Privacy Information Management System

Protecting personal data is one of the most important elements of trust in the digital world. ISO/IEC 27701 is an international standard that helps organizations manage how they process and protect personal data in a systematic and effective way.

Under ISO 27701, we manage our processes for protecting the privacy of personal data as an integrated part of our information security management system. We assess the risks involved in processing personal data, apply appropriate controls, and continually improve our data privacy processes.

This certification is an important sign of how seriously we take the protection of personal data, and of the systematic management approach we apply to our data privacy responsibilities.

ISO/IEC 15504

Software Process Assessment Standard

In software development, quality is ensured through the effective and controlled management not only of the end product, but also of the process through which it is developed. ISO/IEC 15504 is an international standard used to assess software processes, determine their capability levels and continually improve them.

In line with this standard, we systematically assess our software development and management processes and identify their effectiveness, their level of maturity and the areas that need improvement.

Through the ISO/IEC 15504 approach, we aim to build software processes that are better planned, traceable, measurable and sustainable, and to continually improve the quality of our products and services.

Our Approach to Continuous Improvement and Trust

The management system certifications we hold are not merely a standards requirement we have fulfilled; they are a fundamental part of how we do business.

We continuously advance our work in information security, personal data protection, quality management and software process maturity, with the aim of providing our customers, business partners and all our stakeholders with reliable, high-quality and sustainable services.

ARKSOFT BİLİŞİM TEKNOLOJİ TİC. SAN. A.Ş. ISMS and QMS POLICY

The main theme of the TS EN ISO 27001:2022 and TS EN ISO 9001:2015 Information Security and Quality Management System is; to demonstrate that Information Security and Quality management is ensured at Arksoft Bilişim Teknoloji TİC. SAN. A.Ş. across people, infrastructure, software, hardware, user information, organizational information, information belonging to third parties and financial resources, to secure risk management, to measure the process performance of Information Security and Quality management, and to ensure the regulation of relations with third parties on matters related to information security.

The main theme of the Information Security and Quality Management System;

It covers all software used within the scope of Arksoft Bilişim Teknoloji Tic. San. A.Ş., all hardware and software on the basis of corporate business process management, all server system components and end-user computers together with all physical and electronic information assets included in their support and maintenance services, software development, integration, software maintenance processes and personal data processing activities.

Accordingly, the purpose of our ISMS and QMS Policy is;

  • To protect the information assets of Arksoft Bilişim Teknolojileri against all kinds of threats that may arise from inside or outside, knowingly or unknowingly,
  • To ensure accessibility to information as required by business processes,
  • To meet legal regulatory requirements,
  • To carry out work aimed at continual improvement,
  • To ensure the continuity of the three fundamental elements of the Information Security and Quality Management System in all activities carried out:

Confidentiality

Preventing unauthorized access to information of importance

Integrity

Demonstrating that the accuracy and integrity of information is ensured

Availability/Accessibility

Demonstrating that those who are authorized can access information when required

  • To be concerned with the security not only of data kept in electronic media, but of all data held in written, printed, verbal and similar media,
  • To ensure awareness by providing Information Security and Quality Management training to all personnel,
  • To report to the ISMS Team all vulnerabilities in Information Security that actually exist or are suspected, and to ensure that they are investigated by the ISMS Team,
  • To prepare, maintain and test business continuity plans,
  • To identify existing risks by carrying out periodic assessments on Information Security,
  • To review and follow up action plans as a result of the assessments,
  • To prevent all kinds of disputes and conflicts of interest that may arise from contracts,
  • To meet business requirements for accessibility to information and for information systems,
  • To closely follow current developments, and to continuously improve service quality and diversity,
  • To adhere to the principles of impartiality, independence, confidentiality, equality and reliability, and to fulfil the requirements of legal obligations and of all standards with which we are obliged to comply,
  • In the light of the values we hold, together with our management and all our employees, to ensure and maintain the highest level of customer satisfaction in our services,
  • To comply with all obligations under KVKK (the Turkish Personal Data Protection Law), GDPR (where applicable), Intellectual property rights, and national and international legislation,
  • We undertake to assess information security risks that may arise from climate change AND to aim for the efficient use of natural resources.

General Manager

21.07.2026

PREPARED BY CHECKED BY APPROVED BY
Quality Specialist Administrative Affairs Manager General Manager