Skip to content
Azari Holdings
Azari HoldingsCompany

The group, its ownership model and the standards that hold it together.

AboutOur StoryPurposeValuesLeadershipGovernanceGroup Structure
Azari HoldingsBusinesses

Specialist operating companies with distinct mandates and leadership.

OverviewCapitalLuxury PropertiesHotels & ResidencesConciergeAviationYachtsEnergyFoundationAzari Select
Azari HoldingsResponsibility

How the group approaches people, conduct, environment and resilience.

Responsible BusinessSustainabilityClimate & EnvironmentCommunitiesEthics & IntegrityRisk & Resilience
Azari HoldingsInstitution

Long-horizon ownership, partnerships, careers and public policies.

Operating PhilosophyLong-Term OwnershipThird-Party StandardsCareersPartnershipsPolicies
Contact
Azari Holdings

Azari Holdings

AboutOur StoryPurposeValuesLeadershipGovernanceGroup Structure
OverviewCapitalLuxury PropertiesHotels & ResidencesConciergeAviationYachtsEnergyFoundationAzari Select
Responsible BusinessSustainabilityClimate & EnvironmentCommunitiesEthics & IntegrityRisk & Resilience
Operating PhilosophyLong-Term OwnershipThird-Party StandardsCareersPartnershipsPolicies
Contact Azari Holdings
hello@azariholdings.comPrivate group. Long-term ownership.
Policies / Legal

Digital and Information

Information Security Statement

Azari treats information security as an operating responsibility across people, systems, providers and business processes. Public statements remain high level so that useful transparency does not expose sensitive controls.

Last updated 24 August 2026Azari Holdings

On this page

  1. 01Risk-based security
  2. 02Identity and access
  3. 03Data protection
  4. 04Secure development and change
  5. 05Incident response
  6. 06Third-party security
  7. 07Reporting security concerns
Public document

This page states Azari Holdings’ public policy position. Applicable law, contracts, regulatory requirements and more specific subsidiary procedures may impose additional or stricter requirements.

Risk-based security

Security effort should reflect the sensitivity of information, criticality of the service, threat environment and consequences of failure. A public brochure site and a financial-services ledger require different controls even though both sit within the group.

Businesses should identify critical systems and data rather than assume every asset has the same risk.

Identity and access

Access should be tied to legitimate roles, protected with appropriate authentication and removed when no longer required. Privileged access deserves stronger control and oversight because misuse can have wider consequences.

Shared credentials and unnecessary standing access should be avoided where practical.

Data protection

Sensitive information should be protected in storage, transit and use in a manner appropriate to risk. Secrets, credentials and personal data should not be committed to public source code or exposed through logs and error messages.

Data minimisation reduces both privacy and security exposure.

Secure development and change

Software and infrastructure changes should be reviewed and tested proportionately before production. Dependencies should be maintained, secrets separated from code and production debugging or unsafe defaults disabled.

Security testing should be authorised and designed to avoid unnecessary risk to live customers or data.

Incident response

Suspected compromise, data exposure, fraud or material service disruption should be contained, escalated and investigated with enough logging and evidence to understand what happened.

Response should include restoration, communication, required notification and corrective action rather than focusing only on immediate recovery.

Third-party security

Technology providers and other third parties can become part of Azari’s attack surface. Material providers should be assessed for the access, data and operational dependency they create.

Contracts and exit planning should address security responsibilities where the relationship warrants it.

Reporting security concerns

Good-faith security reports should be sent privately to hello@azariholdings.com with enough detail to reproduce or understand the issue. Do not exploit the issue beyond what is necessary to demonstrate it or access data that is not yours.

Azari does not promise a bug bounty through this statement; any reward programme would be published separately if introduced.

Related

Data ProtectionRisk & ResiliencePrivacy Policy

Azari Holdings

Specialist businesses.
One standard of ownership.

Explore the group ↗
Azari Holdings

Azari Holdings is the institutional home of the Azari group, providing long-term ownership, group governance and a common standard across specialist businesses.

hello@azariholdings.com

Company

AboutGovernanceGroup structureCareers

Group

BusinessesResponsibilityPartnershipsPolicies

Legal

PrivacyCookiesTermsAccessibilityLegal notice
© 2026 Azari HoldingsInstitutional website
Privacy by default.

This site does not use advertising or behavioural tracking cookies. A small local preference only remembers this notice.

Cookie policy