25 unchanged sentences
For instance, we utilize external assessors, including security researchers and penetration testers, to identify and report vulnerabilities in our information systems.
−Removed: Further, our cybersecurity risk management program includes a third-party risk management program to assess and manage cybersecurity risks associated with our use of third-party services providers that have access to our information systems and/or employee, agent or agent client confidential information .
+Added: Further, our cybersecurity risk management program includes a third-party risk management program to assess and manage cybersecurity risks associated with our use of third-party services providers that have access to our information systems
+Added: Table of C ontents
+Added: and/or employee, agent or agent client confidential information .
For example, we perform certain due diligence before engaging third-party service providers and consider potential cybersecurity risks and exposures in our choice among providers.
3 unchanged sentences
Our third-party service providers have also been subject to a number of cybersecurity threats and incidents, but to date, none of those threats and incidents have had a materially adverse effect on our business, financial condition, or results of operations.
+Added: Given the data-driven nature of our business and the prevalent use of technology in operating our business, we face cybersecurity risks inherent to our normal course of operation that, if realized, are reasonably likely to materially affect our business strategy, results of operations and financial condition.
Please refer to the “Risk Factors” section of this Annual Report for additional information related to the cybersecurity risks that could potentially impact our business.
7 unchanged sentences
In 2026, we hired a new Chief Information Security Officer to oversee the cybersecurity program and lead the Information Security team.
−Removed: Our CISO has over 17 years of experience building security teams and driving security initiatives for public, high-growth, and regulated companies.
−Removed: He is a Certified Information Systems Security Professional and reports to our Senior Vice President and Head of Engineering.
+Added: The CISO’s experience includes more than 20 years in the security and fraud profession in multiple high-risk industries, including the critical infrastructure sector, and encompasses various cybersecurity leadership roles and almost seven years as a CISO.
+Added: She is a Certified Information Systems Security Professional (CISSP) and has a Master’s Degree in Information Systems Management.
Our CISO reports quarterly to the Audit Committee of our board of directors (the “Audit Committee”), which is responsible for overseeing the Company’s cybersecurity risk management program and cybersecurity risks.
1 unchanged sentence
The Audit Committee reports to the full board of directors regarding its activities, including reports that it receives from our CISO.
−Removed: We are headquartered in New York, New York, where we occupy approximately 32,500 square feet of office space pursuant to a lease that is expected to expire in June 2030 subject to the terms thereof.
+Added: We are headquartered in New York, New York, where we occupy approximately 32,500 square feet of office space pursuant to a lease that is expected to expire in November 2033 subject to the terms thereof.
We also lease operating and sales offices throughout the United States.
−Removed: Legal Proceedings.
−Removed: The information relating to legal proceedings contained in Note 11 to the consolidated financial statements included in Part II, Item 8 of this Annual Report is incorporated herein by this reference.
−Removed: Mine Safety Disclosures.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.