This document is a technical report detailing the information security framework implemented by Visma Draftit AB. It outlines the company's commitment to maintaining data privacy and compliance with GDPR regulations, emphasizing the geographical location of data storage under Swedish legislation. The report describes the operational setup, which includes both traditional and cloud-based environments, and specifies that user login information is minimally stored. It details the data centre's compliance with various security standards, including ISO certifications and Swedish security specifications. Backup procedures are also documented, highlighting the frequency and storage of backups. Furthermore, the report explains security measures such as encryption, role-based access, and multi-factor authentication. It concludes with an overview of the support structure, which follows the ITIL model for incident management, ensuring effective handling of customer support issues.