
Information Security Safeguards
Last Revised:October 1, 2026
your data?
Provider maintains the following administrative, technical, and physical safeguards designed to protect Client Confidential Information and Client Materials processed through the Platform.
Provider may update or modify these safeguards from time to time, provided that Provider will not materially decrease the overall level of security provided for Client Confidential Information and Client Materials during the applicable Order Form term.
Section 1
Information Security Program
Provider maintains a written information security program that includes administrative, technical, and physical safeguards appropriate to the nature of the Platform and the Client Confidential Information and Client Materials processed through the Platform.
Provider maintains written information security policies and an incident response program designed to identify, respond to, mitigate, and recover from security incidents. Such policies and procedures are reviewed and updated periodically, as appropriate.
Section 2
Access and Personnel Security
Provider maintains access controls designed to limit access to Client Confidential Information and Client Materials to authorized personnel with a legitimate business need. Access privileges are assigned based on role and the principle of least privilege and are periodically reviewed.
Provider maintains authentication controls, including multi-factor authentication where appropriate, and logging or auditing controls for access to systems containing Client Confidential Information or Client Materials.
Provider maintains personnel security and access-management processes appropriate to personnel roles and responsibilities, which may include background screening where permitted by applicable law and appropriate to the role. Provider maintains processes designed to timely modify or revoke access following termination of employment or changes in personnel responsibilities.
Personnel with access to Provider systems receive information security and privacy training upon hire and periodically thereafter, as appropriate to their roles and responsibilities.
Section 3
Data and Infrastructure Security
Provider maintains administrative and technical controls designed to protect systems and environments used to process Client Confidential Information and Client Materials.
Provider uses industry-standard encryption designed to protect Client Confidential Information and Client Materials in transit and at rest, where appropriate to the nature of the applicable system and information.
Provider maintains logical access and segregation controls designed to prevent one client from accessing another client’s Client Confidential Information or Client Materials, except where expressly authorized by the applicable client.
Provider also maintains controls designed to protect credentials, access tokens, encryption keys, secrets, and similar authentication information from unauthorized access or disclosure.
Section 4
Application and Development Security
Provider maintains secure software-development and change-management practices designed to protect the confidentiality, integrity, and availability of the Platform.
Provider uses appropriate development, testing, and production controls and maintains processes for reviewing, approving, and tracking material production changes.
Provider maintains security monitoring and vulnerability-management practices designed to identify malicious activity, unauthorized access, and security vulnerabilities affecting the Platform. Identified vulnerabilities are assessed, prioritized, and remediated based on risk.
Provider conducts periodic penetration testing or comparable security assessments of the Platform and supporting infrastructure.
Section 5
Third-Party Security
Provider maintains a risk-based process for evaluating third-party service providers that process Client Confidential Information or Client Materials or otherwise materially support the Platform.
Provider evaluates such providers based on factors including the nature of their access to information and Provider’s operational dependency on their services.
Provider’s use of subprocessors in connection with personal data is subject to the applicable data processing addendum.
Section 6
Business Continuity and Resiliency
Provider maintains business-continuity and disaster-recovery measures appropriate to the Platform and periodically reviews or tests such measures.
Provider maintains measures designed to support the availability and resiliency of systems used to provide the Platform.
Any service-level, recovery-time, or recovery-point commitments will apply only if expressly set forth in an Order Form or other written agreement between the parties.
Section 7
Security Assessments and Documentation
Provider will maintain independent security assessment or audit documentation applicable to the Platform.
Upon Client’s reasonable written request and subject to appropriate confidentiality protections, Provider will make available its then-current independent security audit report or other reasonable security documentation customarily provided to similarly situated clients.