Client Area
Document

Integrated Quality and Information Security Policy

TN Solutions' Integrated Policy for Quality (ISO 9001) and Information Security (ISO/IEC 27001): our commitments and scope of application.

In an industry where service quality and information protection are essential foundations of trust, we have formalised, through an Integrated Management System, the commitments that have always guided our work. This is our Integrated Policy, made public for the sake of transparency towards all our stakeholders.

Why an Integrated Management System

TN Solutions operates in the ICT services sector, providing design, delivery and management of cybersecurity solutions, data centre infrastructure, cloud services and software development for the business market. In this highly dynamic context, Top Management has chosen to adopt an Integrated Management System compliant with the international standards ISO 9001 and ISO/IEC 27001, combining excellence in service delivery with the protection of our own information assets and those of our clients.

This Policy provides the framework for defining company objectives and steers the whole organisation towards meeting applicable requirements and continuously improving performance.

Scope

This Policy applies to all activities, processes and services carried out by TN Solutions at its operational site in Melzo (MI), and covers all internal staff, external collaborators and consultants who work on behalf of the organisation or who access company systems and information, regardless of contract type.

Our commitments

We believe that service quality and information security are not separate goals but two sides of the same promise of reliability. That's why we manage them together.

ISO 9001

Commitment to Quality

  • Deliver services that meet contractual requirements and client expectations

  • Maintain a structured dialogue to understand explicit and implicit needs

  • Set measurable objectives and monitor their achievement with indicators

  • Manage processes according to the Plan-Do-Check-Act cycle

  • Invest in training, skills and staff awareness

  • Select and qualify critical suppliers using rigorous criteria

ISO/IEC 27001

Commitment to Security

  • Preserve the confidentiality, integrity and availability of information

  • Adopt a risk-based approach to protecting our assets

  • Ensure the continuity of ICT services with tested disaster recovery plans

  • Apply the principles of least privilege and MFA to access management

  • Promote a widespread security culture through ongoing training

  • Manage incidents according to documented, traceable procedures

Regulatory compliance

We are committed to fully complying with the legislative, regulatory and contractual requirements applicable to our business:

  • Regulation (EU) 2016/679 (GDPR) — protection of personal data

  • ISO 9001 — quality management systems

  • ISO/IEC 27001:2022 — information security management systems

  • Italian Legislative Decree 81/2008 — occupational health and safety

Our stakeholders

The value we create comes from dialogue with everyone who has a legitimate interest in our activities:

Clients

To whom we guarantee service quality, compliance with contractual SLAs, confidentiality of the information entrusted to us, and timely support.

Staff and collaborators

To whom we guarantee a safe working environment, opportunities for professional growth, and ongoing training.

Suppliers and partners

With whom we build stable relationships based on clear requirements, timely payments and mutual collaboration.

Authorities and regulatory bodies

Towards whom we maintain full compliance and transparency, particularly in our dealings with the Italian Data Protection Authority, the National Cybersecurity Agency, and certification bodies.

Continuous improvement

Continuous improvement is a permanent commitment. We pursue it through systematic performance monitoring, periodic internal audits, management review, analysis of non-conformities and complaints, review of client feedback, and the ongoing development of our technical and organisational skills.

We recognise that every report — internal or external — is an opportunity to grow. That's why we have set up dedicated communication channels, accessible to all stakeholders, reachable through the contact section of our website.

Investing in an Integrated Management System is not a formal obligation — it is the natural evolution of the way we have always worked: with method, with care for our clients, and with responsibility towards the data we manage. Publishing this policy is our commitment in writing.

Marco Ursoleo Sole Director, TN Solutions

Review and updates

This Policy is reviewed at least annually as part of the Management Review, and whenever significant changes occur in the organisational context, the reference market, the regulatory framework or the risk profile. Every update is approved by Top Management and communicated promptly to staff and, where appropriate, to external stakeholders.

Download the full version

The complete Integrated Policy in PDF format, signed by the Sole Director.

Download the Integrated Policy (PDF)

MU

WRITTEN BY

Marco Ursoleo

Sole Director — TN Solutions

Over 25 years of experience in IT and cybersecurity. Leads TN Solutions with the vision of making technology a growth engine for performance, safety and scaling.

Want to discuss it with our team?

We analyse your infrastructure for free and propose the most suitable solution.