2 unchanged sentences
Risk Management and Strategy
−Removed: Our cybersecurity risk management process is aligned with our enterprise risk management framework and policy.
−Removed: This allows us to assess, identify, and manage material risks arising from cybersecurity threats.
+Added: Our cybersecurity risk management process is aligned with our enterprise risk management framework and policy, which supports our efforts to identify, assess, and manage risks arising from cybersecurity threats.
As part of our integrated approach to risk management, and to help safeguard the confidentiality, integrity and availability of our data and systems, we maintain a comprehensive cybersecurity program that is comprised of administrative and technical controls, cybersecurity, technology and privacy policies and procedures, management oversight, accountability structures, and technology design processes (collectively, our "Cybersecurity Program") .
3 unchanged sentences
We work to remain vigilant with respect to new and emerging risks utilizing these tools, and our security team continues to review and make strategic investments in our information security program in support of our efforts to keep our data and systems secure.
−Removed: The Cybersecurity Program includes a cyber incident response plan that provides controls and procedures designed to enable swift response, remediation, and timely and accurate reporting of any material cybersecurity incident.
+Added: Our Cybersecurity Program includes a cyber incident response plan that provides controls and procedures designed to enable swift response, remediation, and timely and accurate reporting of any material cybersecurity incident.
We also maintain an internally staffed cybersecurity operation center, which performs security monitoring and is directly responsible for our efforts to monitor, prevent, and detect cybersecurity incidents, as well as for appropriate and timely escalations concerning cybersecurity incidents that are discovered.
3 unchanged sentences
As delegated by our Board, the Audit and Risk Committee of the Board is responsible for oversight of our risk management process and framework which is designed to monitor and manage strategic and operational risks, including cybersecurity risk.
−Removed: Our senior management, including our Chief Information Security Officer (CISO), is responsible for oversight of our Cybersecurity Program, and maintains responsibility for the regular assessment and management of cybersecurity risks, including by direct work implementing the Cybersecurity Program and by supervising our cybersecurity team.
−Removed: Our Cybersecurity Program is further supported by our cybersecurity governance, risk and compliance team, which is led by our CISO, and is composed of experienced and skilled personnel who are responsible for our security assurance, risk and operational management.
−Removed: Our CISO has over 24 years of experience in cybersecurity, business leadership, investigations, compliance, and cyber-risk management, within the high-tech and financial services industries.
−Removed: Our CISO provides the Audit and Risk Committee with no less than quarterly updates on the status of the Cybersecurity Program, information systems and any material security incidents, or more frequently if circumstances warrant, including on topics related to information security, data privacy and cyber risks and mitigation strategies.
+Added: Our senior management, including our Chief Technology Officer , is responsible for the oversight of our information systems and Cybersecurity Program.
+Added: Our Cybersecurity Program is supported by our cybersecurity governance, risk and compliance team, which is led by our Head of Cybersecurity, who reports to our Chief Technology Officer, and is composed of experienced and skilled personnel who are responsible for our security assurance, risk and operational management.
+Added: Our Head of Cybersecurity maintains responsibility for the regular assessment and management of cybersecurity risks, including by direct work implementing the Cybersecurity Program and by supervising our cybersecurity team.
+Added: Our Chief Technology Officer has over 20 years of experience in information technology and systems infrastructure and holds an advanced degree in computer engineering, and our Head of Cybersecurity has over 12 years of experience in cybersecurity, investigations, compliance, and cyber-risk management, within the high-tech and financial services industries.
+Added: Our Chief Technology Officer, Chief Legal Officer and Head of Cybersecurity provide the Audit and Risk Committee with no less than quarterly updates on the status of the Cybersecurity Program, information systems and any material security incidents, or more frequently if circumstances warrant, including on topics related to information security, data privacy and cyber risks and mitigation strategies.
Like most technology companies, we have suffered cybersecurity incidents in the past and expect that we may face cybersecurity incidents in the future.
4 unchanged sentences
Our corporate headquarters is located in San Carlos, California pursuant to a lease expiring in February 2026.
−Removed: As of December 31, 2023, we leased additional facilities and office space in California, Texas, Mexico, and India.
+Added: As of December 31, 2024, we leased additional facilities and office space in California, Mexico, and India.
We also operate retail locations and co-locations throughout the United States.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.