6 unchanged sentences
While we are in the process of enhancing our cybersecurity practices, we
−Removed: are committed to continually improving and adapting to evolving threats to maintain a high standard of protection.
+Added: are committed to continually improving and adapting to evolving threats to maintain a high standard of protection and to meet industry
+Added: best practices.
Managing Material Risks and Integrated Overall
3 unchanged sentences
critical systems.
−Removed: We use information security management standards like ISO 27001 as a guide to help us identify, assess, and manage cybersecurity
−Removed: risks relevant to our business.
−Removed: We are actively integrating
−Removed: cybersecurity risk management into our broader enterprise risk management framework.
−Removed: This integration is designed to promote a company-wide
−Removed: culture of cybersecurity awareness and risk management.
−Removed: Our risk management team, in collaboration with external consultants, is assessing
−Removed: and addressing cybersecurity risks in alignment with our operational and business needs.
−Removed: This ongoing integration ensures that cybersecurity
−Removed: considerations are increasingly embedded in our decision-making processes at every level.
+Added: We use information security management standards, such as ISO 27001, as a guide to help us identify, assess, and manage
+Added: cybersecurity risks relevant to our business.
+Added: We have integrated cybersecurity
+Added: risk management into our broader enterprise risk management framework.
+Added: This integration is designed to promote a company-wide culture
+Added: of cybersecurity awareness and risk management.
+Added: Our risk management team, in collaboration with external consultants, has assessed and
+Added: addressed and continues to assess and address cybersecurity risks in alignment with our operational and business needs.
+Added: This integration
+Added: ensures that cybersecurity considerations are increasingly embedded in our decision-making processes at every level.
Our cybersecurity framework
−Removed: draws upon the National Institute of Standards and Technology (“NIST”) cybersecurity framework, which provides guidance for
−Removed: identifying, assessing, and managing cybersecurity risks.
−Removed: While we are in the early stages of fully implementing this framework, we are
−Removed: committed to following its principles as we strengthen our cybersecurity measures to protect both our digital and physical assets.
+Added: also draws upon the National Institute of Standards and Technology Cybersecurity Framework (at its currently 2.0 version), which provides
+Added: guidance for identifying, assessing, and managing cybersecurity risks.
+Added: While we are in the early stages of fully implementing this framework,
+Added: we are committed to following its principles as we strengthen our cybersecurity measures to protect both our digital and physical assets.
Engage Third-parties on Risk Management
Recognizing the evolving nature
−Removed: of cybersecurity threats, we have been engaging with external experts, including cybersecurity assessors, consultants, and auditors, to
−Removed: assess and enhance our risk management systems.
−Removed: These third parties are assisting us with evaluating our cybersecurity posture, recommending
−Removed: improvements, and advising on the implementation of best practices.
−Removed: As we progress, we will continue leveraging these external insights
−Removed: to enhance our cybersecurity strategies and ensure alignment with industry standards.
+Added: of cybersecurity threats, we have engaged with external experts, including cybersecurity assessors, consultants, and auditors, to assess
+Added: and enhance our risk management systems.
+Added: These third-parties have and continue to assist us with evaluating our cybersecurity posture,
+Added: recommending improvements, and advising on the implementation of best practices.
+Added: In 2025, we completed a comprehensive cybersecurity assessment
+Added: across all platforms with external experts, such as Amazon Web Services, amongst others.
+Added: As we progress, we will continue leveraging these
+Added: external insights to enhance our cybersecurity strategies and ensure alignment with industry standards.
Oversee Third-party Risk
7 unchanged sentences
To date, we have not encountered
−Removed: cybersecurity incidents that have materially impaired our operations or financial position.
−Removed: However, we are proactively preparing for
−Removed: the possibility of cybersecurity risks, ensuring that our systems are protected against potential threats in the future.
−Removed: Our board of directors understands
−Removed: the critical nature of cybersecurity and is closely involved in overseeing our efforts to mitigate cybersecurity risks.
−Removed: We are in the
−Removed: process of formalizing governance structures and oversight mechanisms to ensure that these risks are managed effectively, with the aim
−Removed: of strengthening our operational integrity and enhancing stockholder confidence.
+Added: cybersecurity incidents that have materially impaired our operations or financial condition.
+Added: However, given the data-driven nature of
+Added: our business and the prevalent use of technology in operating our business, we face cybersecurity risks inherent to our normal course
+Added: of operation that, if realized, are reasonably likely to materially affect our operations or financial condition.
+Added: As a result, we have
+Added: a dedicated cybersecurity response team and proactively prepare for the possibility of cybersecurity risks, ensuring that our systems
+Added: are protected against potential threats.
+Added: The cybersecurity response team (i) responds to actual and suspected cybersecurity threats, (ii)
+Added: assesses the severity of any such actual or suspected cybersecurity threat, (iii) prepares and maintains incident reports and (iv) prepares
+Added: cybersecurity incident response procedures designed to help protect the security of the Company’s systems.
+Added: Our Board understands the
+Added: critical nature of cybersecurity and is closely involved in overseeing our efforts to mitigate cybersecurity risks.
+Added: We continue to formalize
+Added: governance structures and oversight mechanisms to ensure that these risks are managed effectively, with the aim of strengthening our operational
+Added: integrity and enhancing stockholder confidence.
+Added: As of December 31, 2025, no risks from cybersecurity threats, including as a result of
+Added: cybersecurity incidents we have experienced in the past, have materially affected us, including our results of operations and financial
Management’s Role Managing Risk
−Removed: The Chief Executive Officer
−Removed: (“CEO”), Chief Operating Officer (“COO”), and Chief Financial Officer (“CFO”) are actively involved
−Removed: in managing cybersecurity risks.
−Removed: They receive regular updates, which include an overview of the current cybersecurity landscape, the status
−Removed: of ongoing initiatives, and compliance with regulatory requirements.
−Removed: We are establishing structured processes for ongoing communication
−Removed: among the executive team to ensure they remain informed and involved in key cybersecurity decisions.
+Added: Our Chief Technology Officer
+Added: (“CTO”) is the senior officer responsible for cybersecurity risk management.
+Added: Our CTO receives regular updates, which include
+Added: an overview of the current cybersecurity landscape, the status of ongoing initiatives, and compliance with regulatory requirements.
+Added: are establishing structured processes for ongoing communication among the executive team to ensure they remain informed and timely involved
+Added: in key cybersecurity decisions.
Risk Management Monitoring
−Removed: We are committed to monitoring
−Removed: cybersecurity risks and are in the process of implementing enhanced monitoring systems.
−Removed: With the assistance of cybersecurity consultants,
−Removed: we are refining our cybersecurity policies and controls, including regular audits and the deployment of advanced security measures such
−Removed: as Multi-Factor Authentication (“MFA”) and stronger email filtering protocols.
−Removed: In addition, we are continuing to develop incident
−Removed: response plans, communication protocols, and disaster recovery plans to be prepared for any potential cybersecurity incidents.
+Added: We are committed to regularly
+Added: monitoring cybersecurity risks and are in the process of implementing enhanced monitoring systems.
+Added: With the assistance of cybersecurity
+Added: consultants, we are refining our cybersecurity policies and controls, including regular audits and the deployment of advanced security
+Added: measures such as Multi-Factor Authentication and stronger email filtering protocols.
+Added: In addition, we have an incident response team and
+Added: are continuing to refine our incident response plans, communication protocols, and disaster recovery plans to be prepared for any potential
+Added: cybersecurity incidents.
Security Training
3 unchanged sentences
ensure that our employees are well-prepared to identify and respond to cybersecurity threats in an effective manner.
−Removed: Reporting to Board of Directors
−Removed: The COO regularly informs
−Removed: the CEO and CFO on cybersecurity risks and initiatives.
−Removed: Significant cybersecurity matters will be escalated to the audit committee for
−Removed: review, where management will provide detailed updates on risk assessments, incident response, and the effectiveness of our cybersecurity
−Removed: The audit committee will continue to evaluate the progress of our cybersecurity initiatives and offer guidance to help strengthen
+Added: Reporting to Management and the Board
+Added: The CTO regularly provides
+Added: reports and informs the CEO and CFO cybersecurity profile.
+Added: These reports address the status of risk mitigation initiatives, the evolving
+Added: threat landscape, the results of vulnerability assessments and penetration testing, and the progress of key cybersecurity programs, including
+Added: the implementation of a Zero Trust access framework, continuous vulnerability scanning with centralized alerting, and our pursuit of SOC
+Added: The Board maintains direct
+Added: oversight of the Company’s cybersecurity program.
+Added: Management provides the Board with no fewer than annual comprehensive briefings
+Added: on cybersecurity risk assessment, the effectiveness of the Company’s information security controls and the status of ongoing cybersecurity
+Added: These briefings also cover the Company’s incident response preparedness and any changes in the regulatory environment
+Added: affecting the Company’s cybersecurity obligations.
+Added: In addition to the regularly
+Added: scheduled briefings, significant cybersecurity matters will be escalated to the Board for review, where management, including the CTO,
+Added: will provide detailed updates on risk assessments, incident responses, and the effectiveness of our cybersecurity strategies.
+Added: will continue to evaluate the progress of our cybersecurity initiatives and offer guidance to help strengthen our efforts.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.