Information Security Management System

Last Updated: August 15, 2026

Scope

This document describes the scope and core principles of RND Yazılım ve E-ticaret A.Ş.'s integrated management system for information security (ISO/IEC 27001), business continuity (ISO 22301), and personal data management (ISO/IEC 27701). The scope covers all information assets across the company's fulfillment, technology platform, and customer service operations.

Certification Status

RND operates and continuously improves its information security management system within the framework of the ISO/IEC 27001, ISO 22301, and ISO/IEC 27701 standards.

Information Security Principles

RND is committed to protecting the confidentiality, integrity, and availability of customer and employee data. This includes access authorization controls, network and application security, regular penetration testing, intrusion detection systems, and data backups. In the event of a security incident, affected data subjects and the relevant authority are notified without delay.