---
title: "Information security policy — COCO Tecnologías"
description: "General information security policy of COCO Tecnologías. Learn about our legal commitments and policies to protect your information."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://cocotech.ai/#organization",
      "name": "COCO Tecnologías",
      "alternateName": "COCO Tech AI",
      "url": "https://cocotech.ai/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://cocotech.ai/assets/coco-logo.png",
        "width": 600,
        "height": 373
      },
      "sameAs": [
        "https://www.linkedin.com/company/coco-tecnologias/",
        "https://www.instagram.com/cocotech.ai",
        "https://www.youtube.com/c/COCOTecnolog%C3%ADas"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://cocotech.ai/en"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Security Policy"
        }
      ]
    }
  ]
---

We use cookies to improve your experience and analyze traffic. [More info](/en/contact-us)

Essential onlyAccept

[![COCO Tech](/assets/coco-logo-light-OLz8Qiw1.png)](/en)

Solutions

Academy

[About us](/en/about-us)[Contact us](/en/contact-us)

en 

[Schedule demo](/en/contact-us)

1.  [Home ](/en)
2.  Security Policy 

Legal · Security

# General information security policy

## 1\. Scope

This document was developed by the Information Security area and has received approval from the CEO of COCO INVERSIONES TECNOLÓGICAS S.A.S. Compliance is mandatory for all corporate personnel, as well as third parties, suppliers, and contractors. COCO INVERSIONES TECNOLÓGICAS S.A.S. specializes in providing communication services between healthcare institutions and patients through digital tools and artificial intelligence.

## 2\. Key definitions

Confidentiality: ensures that information will only be viewed and accessed by duly authorized individuals (ISO/IEC 27001:2022). Integrity: ensures that information will only be modified by duly authorized individuals (ISO/IEC 27001:2013). Availability: guarantees that information will always be available whenever it needs to be consulted or accessed (ISO/IEC 27001:2022). ISMS: Information Security Management System.

## 3\. Roles & responsibilities

The Information Security Leader implements ISO 27001, identifies risks and threats, designs mitigation strategies, and handles audit and evidence requirements. The Security Committee (CEO, CO-CEO, CMO, CTO, CFO, and RSI) reviews, evaluates, and approves the ISMS, the current policy, and measures against security threats. All internal and external personnel must accept this policy in writing, comply with ISMS regulations, attend training sessions, and report situations threatening information security.

## 4\. Policies & commitment

For COCO INVERSIONES TECNOLÓGICAS S.A.S., information is one of the most important pillars for service delivery. The organization commits to protecting it by upholding the principles of Confidentiality, Integrity, and Availability, complying with applicable legal requirements and security controls, and continuously monitoring the ISMS to improve and ensure its effectiveness.

## 5\. General Guidelines

All individuals linked to COCO (clients, collaborators, suppliers, contractors, partners) must safeguard corporate information they access and prevent its loss, alteration, destruction, or misuse. Protected assets include: information, collaborators, software applications, computer equipment, physical facilities, communication networks, auxiliary equipment, information systems, client databases, and patient databases. The organization manages and mitigates risks, takes proactive measures against cybersecurity threats, and implements a business continuity plan. Specific policies (acceptable use, passwords, backups, email, access control, remote work, encryption, etc.) are reviewed twice a year at the end of each semester or when significant changes occur.

## 6\. ISMS Objectives

Culture: train and raise awareness among collaborators and contractors on information protection. Incidents: identify, analyze, and promptly close information security incidents. Risks: control, mitigate, and prevent risks associated with information security. Continuity: ensure the availability of organizational processes. Security Controls: evaluate and monitor ISMS controls and procedures. Continuous Improvement: establish an organizational commitment to monitoring the management system.

## 7\. Responsibilities, Conformity & Validity

The Information Security area is responsible for managing implementation, ensuring compliance, conducting periodic reviews, updating, disseminating, and training personnel. Non-compliance with this policy entails sanctions established in the work regulations. This document must be reviewed and approved by senior management of COCO INVERSIONES TECNOLÓGICAS S.A.S. Its validity is permanent.

Last updated: January 2026 · COCO Inversiones Tecnológicas S.A.S.

[![COCO Tech](/assets/coco-logo-light-OLz8Qiw1.png)](/en)

We are a system of solutions designed for the healthcare sector, enabling clinics and hospitals to organize their operations and reduce revenue losses caused by inefficiencies in processes behind patient care.

AI & E-HEALTH

[](https://www.linkedin.com/company/coco-tecnologias/)[](https://www.instagram.com/cocotech.ai?igsh=eWtneG8zc2hnNDlt)[](https://www.youtube.com/c/COCOTecnolog%C3%ADas)

### Solutions

-   [All solutions](/en/solutions)
-   [Medical scheduling software](/en/medical-scheduling-software)
-   [Telemedicine platform](/en/telemedicine-platform)
-   [Queue management system](/en/queue-management-system)
-   [Surgical management software](/en/surgical-management-software)
-   [Patient engagement campaigns](/en/patient-engagement-campaigns)
-   [Clinical OCR software](/en/clinical-ocr-software)
-   [ROI calculator](/en/roi-calculator)

### Company

-   [About us](/en/about-us)
-   [Testimonials](/en/testimonials)
-   [Blog](/en/blog)
-   [Contact us](/en/contact-us)
-   [Support ](https://cocotecnologias.zendesk.com/hc/en-us)
-   [Sign in 
    
    COCO Reservas
    
    ](https://www.cocoreservas.com/)

[Privacy policy](/en/privacy)[Terms & conditions](/en/terms)[Data processing](/en/data-processing)[Security policy](/en/security-policy)[SLA](/en/sla)[API Documentation](https://coco-tecnologias.github.io/Agendaton/index.html)[Service status](https://cocoreservas1.statuspage.io/#)

© 2026 COCO Tecnologías. All rights reserved.

Made by COCO AI E-Health