The quality of our services, data security, and full regulatory compliance are fundamental elements of Previnet’s operating model. That is why we adopt internationally recognised standards and subject our processes to regular independent checks and audits. The certifications we have obtained demonstrate our commitment to ensuring reliability, transparency, and business continuity.

ISO 27001
The excellence of the operational model adopted has been further confirmed via certification to the ISO 27001 standard, which guarantees compliance with all data management security requirements in accordance with the highest international standards.
The implementation of the Information Security Management System (ISMS) enables us to adhere to the following Information Security Policy.

SOC1 (ISAE 3402) Type II
Obtaining (and annually renewing) this certification, issued by an external auditor, is a mandatory requirement for providing administrative and technological services on an international scale. Its importance is also recognised and valued within the Italian market.
No significant findings (“no weaknesses”) were identified during the 80 checks and tests carried out as part of the SOC1 certification. The audits covered the procedures and controls relating to the main administrative processes provided to international pension funds and insurance companies. Activities with a potential financial impact on clients were scrutinised with particular attention. The audits also covered IT systems, security and privacy in data management, as well as the ability to operate internationally.

SOC2 Type II
Obtaining (and annually renewing) this certification, issued by an external auditor, is a mandatory requirement for providing administrative and technological services on an international scale. Its importance is also recognised and valued within the Italian market.
No significant findings (“no weaknesses”) were identified during the 80 checks and tests carried out as part of the SOC1 certification. The audits covered the procedures and controls relating to the main administrative processes provided to international pension funds and insurance companies. Activities with a potential financial impact on clients were scrutinised with particular attention. The audits also covered IT systems, security and privacy in data management, as well as the ability to operate internationally.