Certifications and Compliance

Integrated Management System

Qboxmail has adopted an Integrated Management System to ensure

  • The control and optimisation of business processes;
  • The security of data and information;
  • The provision of services according to appropriate quality standards;
  • Business continuity;
  • Continuous improvement;

The Integrated Management System for Quality and Information Security is a governance tool based on the principle of continuous improvement and the best practices provided for by the relevant ISO international standards.

The following documents are currently only available in Italian. The English version will be available soon.

Integrated Policy

Download

Cloud Policy

Download

Our certifications

Quality – ISO 9001:2015

ISO 9001 certifies the optimisation of Qboxmail’s business processes aimed at continuous improvement of service delivery and customer satisfaction.

Certified processes

Design, software development and delivery of cloud-based email hosting, email delivery and email security services.

Date of first issue

June 8, 2023

Date of current issue

June 8, 2026

Certificate valid until

June 7, 2029

Download the certification

Information security – ISO 27001:2022

The ISO 27001 standard certifies the secure management of information and personal data. Qboxmail has adopted advanced controls by extending the ISO 27001 certification to ISO 27017 and ISO 27018 standards on security and privacy of cloud services.

Certified processes

Design, software development and delivery of cloud-based email hosting, email delivery and email security services.

Date of first issue

June 8, 2023

Date of current issue

June 8, 2026

Certificate valid until

June 7, 2029

Download the certification

Qualified Cloud Services for the Italian Public Administration

Qboxmail Srl, for its email services delivered in SaaS mode, has obtained qualification from ACN (National Cybersecurity Agency of Italy) for its SaaS Cloud Services at QC1 level and for its Cloud Service Infrastructure at QI1 level.

Qualified services

The following products are listed in the Cloud Marketplace, the catalogue of qualified cloud services for the Italian Public Administration:

Qboxmail is a qualified provider of Cloud Services to the PA

Compliance with the NIS 2 Directive

Qboxmail is included in the list of essential entities provided for by the NIS 2 regulation. This confirms the adoption of advanced requirements for cybersecurity, risk management, operational continuity, and protection of digital infrastructures.
NIS 2 compliance complements Qboxmail’s ISO certifications and ACN qualification for cloud services.

Information Security

The relevant information security measures that Qboxmail implements and includes in the supply contract are specified below:

  • Protection against malware;
  • Backups;
  • Cryptographic controls;
  • Vulnerability management;
  • Incident management;
  • Technical compliance monitoring;
  • Security testing;
  • Auditing;
  • Collection, maintenance and protection of evidence, including logs and audit trails;
  • Protection of information in the event of termination of the service contract;
  • Authentication and access control;
  • Identity and access management;

Cloud-based data entrustment

Cloud-based data entrustment according to ISO 27017:2015 requires the verification of certain requirements for both the customer and the supplier.

Specifically, ISO 27017 provides Cloud-based guidance on 37 ISO 27002 controls, as well as seven new Cloud controls:

  • Responsibilities and roles between the cloud service provider and the cloud customer;
  • Removal and return of assets upon termination of a contract;
  • Protection and separation of the virtual environment between clients;
  • Robustness requirements of virtual machines to meet customer needs;
  • Procedures and regulations for managing a cloud environment;
  • Monitoring of customer activities within a cloud environment;
  • Aligning security management for both virtual and physical networks;

Qboxmail, in accordance with ISO 27017:2015 guidelines, has set out precise requirements to be met. Customers can contact us for details on how activities are managed.

We use cookies to provide you with a better browsing experience, by continuing, you accept their use. For more information, visit the Privacy Policy page.

Accept