Integrated management system
Integrated policy.
The document in which the management of Upon Group states what it commits to in quality, the environment, health and safety, information security, privacy, continuity and artificial intelligence. And what it can be checked against.
What this is and what it is for.
The ISO standards we are certified against all require the same thing in their clause 5.2: that management writes down what it commits to, that the commitment serves as a framework for setting each year's objectives, that it is documented, that it is communicated within the organisation and that it is available to anyone who asks. This is that document.
It has been written for two readers at once. An auditor, who is going to read it with the standard alongside and needs to find each commitment where it belongs. And the people who work here, who are the ones who have to meet it — and a policy that isn't understood isn't met, which is also audited.
Scope: it applies to the three companies in the group —North Point Solution, S.L., West Point Solution, S.L. and Upon Solution, S.L.— and to all their activities: the engineering, installation and maintenance of electronic security systems, and the development, deployment and support of artificial intelligence systems applied to video.
The three commitments that run through everything.
These three hold for all seven standards, and they are the part management signs.
- COMPLYING WITH THE APPLICABLE REQUIREMENTS. The legal ones, the regulatory ones, the contractual ones and the ones we took on voluntarily when we got certified. It is not an aspiration: it is the line below which no work is done, and when a requirement and a deadline collide, the requirement wins.
- IMPROVING CONTINUALLY. The management system is not there to have a certificate on the wall: it is there so that what went wrong once does not go wrong again. Every non-conformity, every incident and every complaint is analysed looking for the cause, not the culprit.
- PROVIDING THE MEANS. A commitment without resources is a declaration. Management commits to providing the people, the training, the time and the technical means needed for what is below to actually be met.
Quality.
ISO 9001
We commit to understanding what each client needs before proposing anything, and to saying no when what they ask for can't be done properly. A job accepted knowing it will turn out mediocre is a quality failure that starts before the first visit.
The way of working is written down, measured and corrected. Processes have an owner, an input, an output and indicators, and client satisfaction is measured and reviewed in the management review.
And every non-conformity is recorded, including the ones nobody outside would see. A quality system in which only the failures the client has seen show up isn't measuring quality: it is measuring luck.
Environment.
ISO 14001
We commit to protecting the environment and preventing pollution in everything we do, identifying the environmental aspects of our activities and acting on the significant ones.
In this trade that means concrete things: the management of waste electrical and electronic equipment removed from a site, the electricity consumption of the equipment installed and of the servers that process the video, service engineers' travel, and the life cycle of what is bought — extending it is the most effective environmental measure there is in electronic security.
We comply with the applicable environmental regulations and, where it makes sense, we go beyond them.
Occupational health and safety.
ISO 45001
We commit to providing safe and healthy working conditions for the prevention of injury and ill health, and to eliminating hazards and reducing the risks that cannot be eliminated.
Here it isn't an abstract commitment: our people climb poles, work at height, go into electrical panels, tunnels, treatment plants and other people's sites. The risk is physical and it is daily, and that is why the order is always the same: eliminate the hazard if you can, substitute it if you can't, then the engineering controls, then the organisational ones and only at the end personal protective equipment.
And we commit to consulting workers and involving them in everything that affects their safety. Whoever does the work is the first to see the risk, and a channel for saying so that nobody uses is a channel that doesn't exist: nobody suffers retaliation for stopping a job they consider unsafe, and that is the part of this policy we most want read.
Information security.
ISO/IEC 27001 · ENS · NIS2
We commit to preserving the confidentiality, integrity and availability of our own information and of the information our clients entrust to us, and to this policy serving as a framework for setting security objectives.
The material we work with makes it particularly sensitive: images of people, number plates, access logs and site drawings. A leak here isn't an IT incident, it is a problem for specific people and for the physical security of a site.
Risks are identified, assessed and treated systematically. Access is granted on a need-to-know basis and reviewed. Incidents are detected, recorded, notified within the deadlines the regulations require and analysed so they don't happen again. And the requirements of the Esquema Nacional de Seguridad (ENS, the Spanish national security framework) and of the NIS2 directive apply to what we deliver to third parties too, not just to our own house.
Privacy.
ISO/IEC 27701 · GDPR
We commit to processing personal data in accordance with the GDPR and the LOPDGDD (the Spanish data protection act), and to applying data protection by design and by default in everything we build.
In practice that means collecting the minimum necessary, keeping it for the minimum time necessary, not using it for anything other than what it was collected for, and being able to demonstrate all three. And it means helping our clients comply when they are the controller and we are the processor: a video system that can't explain what it holds and for how long puts its owner in trouble.
People's rights —access, rectification, erasure, objection, restriction of processing and portability— are dealt with within the deadline, and there is a written procedure for it.
Business continuity.
ISO 22301
We commit to maintaining the ability to keep providing service in the face of a serious disruption, and to having tested it before we need it.
The critical activities and the maximum times they can be down are identified, there are continuity and recovery plans, and they are rehearsed at a defined frequency. A plan that has never been tested isn't a plan: it is a document.
This includes what keeps our clients' service running, not just our own offices: 24 × 7 support and the ability to respond to a critical fault at a site are part of the scope.
Artificial intelligence.
ISO/IEC 42001
We commit to developing and deploying artificial intelligence systems responsibly, traceably and under human supervision.
It is documented who trains the models, with what data, who verifies their performance and what is done when they fail. Systems are tested before delivery and monitored afterwards, because a scene changes and a model that used to work stops working without warning.
There are three things we take on expressly. The first: the decision belongs to a person. Our systems detect and alert; who decides what to do with an alert is always someone with a name inside the client's organisation. The second: the limits are communicated before the capabilities — what it doesn't detect, in what conditions it degrades and what margin of error it has, with a third party's measurement where one exists. And the third: no accuracy figure is claimed that can't be demonstrated, not in a proposal, not in a demonstration, and not on this website.
Who answers for this being met.
The management of Upon Group establishes this policy, reviews it at least once a year in the management review and updates it when the organisation's context, the applicable regulations or the scope of the certifications change.
The policy is communicated to all staff, explained in the induction of every new joiner and publicly available on this page to clients, suppliers, public authorities and any interested party who asks for it.
The specific, measurable objectives for each year are set from this framework, reviewed periodically and documented separately. They are deliberately not on this page: they are annual and they change, and a policy with out-of-date objectives inside it is a non-conformity waiting for someone to find it.
Document control.
- Version: PENDING
- Approval date: PENDING
- Approved by: PENDING — the senior management of Upon Group. The standards require management to be the one that establishes it, and that is evidenced with a signature and a date.
- Next review: at the annual management review.
Get started
Ask us for the certificates.
This policy is the framework. The certificates that back it up, with their scope and their validity date, are asked for and sent.