−Removed: Unresolved Staff Comments
+Added: Staff Comments
are no unresolved staff comments.
Cybersecurity
−Removed: the Trust has no directors, principal officers or employees, the Sponsor is responsible for managing cybersecurity risks to the
−Removed: The Sponsor has an information security program and policy in place, as mandated by new Regulation S-K Item 106.
−Removed: is designed to assess, identify, and manage material risks from cybersecurity threats.
−Removed: Regular reviews of cybersecurity and information
−Removed: technology plans are conducted for key service providers, as part of the Sponsor’s disaster recovery and business continuity
−Removed: planning process.
−Removed: Additionally, the Sponsor evaluates whether any cybersecurity threats, including those resulting from previous
−Removed: incidents, have materially affected or are reasonably likely to materially affect the Trust and the Fund.
−Removed: Sponsor’s Vice President of IT & Cybersecurity , Mr.
−Removed: Tiago DeMesquita, is responsible for identifying, assessing and
−Removed: managing the Sponsor’s risks from cybersecurity threats.
−Removed: DeMesquita has over 5 years of experience in technology and
−Removed: cybersecurity.
−Removed: DeMesquita heads the Cybersecurity Committee of the Sponsor which meets regularly to evaluate strategies, governance,
−Removed: risk management, compliance, engineering and development, security operations, and incident management.
−Removed: In addition, the Sponsor
−Removed: maintains a cybersecurity insurance policy.
−Removed: principal offices of the Sponsor, the Trust and the Fund are leased and are located at 234 West Florida Street, Suite 203, Milwaukee,
−Removed: Wisconsin 53204.
+Added: Management and Strategy
+Added: Trust does not have any employees or a dedicated information technology infrastructure.
+Added: The Trust's cybersecurity risk management relies
+Added: on the programs and practices maintained by the Sponsor and the Trust's key third-party service providers.
+Added: Sponsor is part of the Hashdex group of companies, which includes Hashdex Gestora de Recursos Ltda.
+Added: ("Hashdex Gestora"), a
+Added: Brazilian-regulated asset management firm that has adopted a formal Information Security and Cybersecurity Policy.
+Added: While this policy
+Added: is formally adopted at the Hashdex Gestora level, the Sponsor applies cybersecurity procedures and controls consistent with the principles
+Added: and standards set forth in that policy across its operations, including those relating to the Trust.
+Added: Sponsor's cybersecurity risk management processes are integrated into its overall risk management framework.
+Added: At least annually, the Sponsor
+Added: conducts a cybersecurity risk assessment to identify internal and external threats and evaluate the adequacy of existing controls, considering
+Added: potential financial, operational, and reputational impacts.
+Added: The Sponsor may engage specialized third-party firms to assist with these
+Added: assessments when deemed necessary.
+Added: Sponsor has implemented preventive and detective controls, including monitoring of workstations and network components, periodic vulnerability
+Added: and penetration testing, multi-factor authentication requirements, encryption protocols, employee cybersecurity training conducted at
+Added: least annually, and an incident response framework aligned with its Business Continuity Plan.
+Added: Sponsor also maintains processes to oversee and identify material cybersecurity risks associated with the Trust's use of third-party
+Added: service providers.
+Added: Prior to engaging third parties that will have access to confidential information or systems, the Sponsor conducts
+Added: a cybersecurity due diligence evaluation assessing, among other things, whether the third party maintains formal information security
+Added: policies, an incident response plan, adequate data protection mechanisms, and all necessary certifications.
+Added: These evaluations are periodically
+Added: reassessed and the Sponsor includes information security requirements in its service agreements.
+Added: of December 31, 2025, no cybersecurity threats or incidents, including as a result of any previous cybersecurity incidents, have materially
+Added: affected or are reasonably likely to materially affect the Trust, including its business strategy, results of operations, or financial
+Added: Trust is organized as a Delaware statutory trust and does not have a board of directors.
+Added: The Sponsor is solely responsible for the management
+Added: and control of the Trust's business and affairs, including oversight of cybersecurity risks.
+Added: Sponsor has established a risk and compliance committee (the "Risk & Compliance Committee"), composed of the head of the
+Added: risk and compliance function and the risk and compliance team.
+Added: The Risk & Compliance Committee meets at least quarterly and is responsible
+Added: for the supervision and monitoring of cybersecurity practices applicable to the Sponsor's activities, including those relating to the
Legal Proceedings
−Removed: the Trust, Fund or Sponsor are currently subject to any material legal proceedings, nor, to our knowledge, are any material legal
−Removed: proceedings threatened against Trust, Fund or Sponsor.
+Added: the Trust, the Fund or the Sponsor are currently subject to any material legal proceedings, nor, to our knowledge, are any material legal
+Added: proceedings threatened against the Trust, the Fund or the Sponsor.
Mine Safety Disclosures
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.