Security Addendum
Information Security Requirements and Controls
1. Scope
This Addendum describes Provider’s security commitments for the Services identified in the applicable Order Form.
2. Security Program
Provider will maintain written security policies and a risk management program appropriate to the Services.
3. Access Control
Provider will use least-privilege and role-based access controls and MFA for privileged or sensitive access where appropriate.
4. Encryption
Provider will use industry-standard encryption for Customer Data in transit and, where supported, at rest.
5. Personnel Security
Personnel with access to Customer Data will be subject to confidentiality obligations and security training.
6. Vulnerability Management
Provider will maintain processes for identifying, prioritizing, and remediating vulnerabilities based on risk.
7. Incident Response
Provider will maintain an incident response program and notify Customer of confirmed Security Incidents involving Customer Data in accordance with the DPA.
8. Business Continuity
Provider will maintain reasonable backup, recovery, redundancy, and continuity controls. Binding RTO/RPO commitments, if any, are stated in the SLA or Order Form.
9. Security Testing
Provider will conduct security assessments appropriate to its risk profile, which may include vulnerability scanning, penetration testing, code review, and independent assessments.
10. Compliance Reports
Where applicable, Provider may provide SOC 2 Type II, penetration-test summaries, or other security documentation.
11. Customer Responsibilities
Customer is responsible for endpoint security, identity administration, user permissions, credentials, and security of systems integrated with the Services.
12. AI-Specific Controls
Provider will maintain controls appropriate to AI Services, including protection of prompts and Outputs, model/provider access restrictions where supported, protection of system prompts and credentials, monitoring for anomalous activity, and controls designed to reduce unauthorized disclosure of Customer Data.
13. Exceptions
Deviations must be documented in the Order Form or a written security exception approved by both Parties.
.5f521cec.png)