Unresolved Staff Comments
+Added: Not Applicable.
Cybersecurity
−Removed: from Cybersecurity Threats
−Removed: Company faces risks associated with cybersecurity threats in carrying out its business operations.
−Removed: For more details regarding the risks
−Removed: related to PRC’s cybersecurity regulation, see “ Item 1A.
−Removed: Risk Factors—Compliance with China’s new Data Security
−Removed: Law, Measures on Cybersecurity Review, Personal Information Protection Law, regulations and guidelines relating to the multi-level protection
−Removed: scheme and any other future laws and regulations may entail significant expenses and could materially affect our business.
+Added: Risks from Cybersecurity Threats
+Added: The Company faces risks associated with cybersecurity threats in carrying out its business operations.
+Added: For more details regarding the risks related to PRC’s cybersecurity regulation, see “ Item 1A.
+Added: Risk Factors—Compliance with China’s new Data Security Law, Measures on Cybersecurity Review, Personal Information Protection Law, regulations and guidelines relating to the multi-level protection scheme and any other future laws and regulations may entail significant expenses and could materially affect our business.
and “I tem 1A.
−Removed: Risk Factors—Recent greater oversight by the CAC over data security, particularly for companies seeking
−Removed: to list on a foreign exchange, could adversely impact our business and our offering.
−Removed: the year ended March 31, 2025, the Company was not subject to material fines or penalties in connection with cybersecurity, and there
−Removed: were no material cybersecurity incidents arising from cybersecurity or personal data protection.
−Removed: board of directors does not have a standing risk management committee, but rather administers this oversight function directly through
−Removed: our board of directors as a whole, as well as through various standing committees of our board of directors that address risks inherent
−Removed: in their respective areas of oversight.
−Removed: While our board of directors has a fiduciary duty to monitor and assess strategic risk exposure,
−Removed: our audit committee is responsible for overseeing our major financial risk exposures and the steps our management has taken to monitor
−Removed: and control these exposures, overseeing cybersecurity risks and assisting the board of directors in its oversight over enterprise risk
+Added: Risk Factors—Recent greater oversight by the CAC over data security, particularly for companies seeking to list on a foreign exchange, could adversely impact our business and our offering.
+Added: For the year ended March 31, 2026, the Company was not subject to material fines or penalties in connection with cybersecurity, and there were no material cybersecurity incidents arising from cybersecurity or personal data protection.
+Added: Our board of directors does not have a standing risk management committee, but rather administers this oversight function directly through our board of directors as a whole, as well as through various standing committees of our board of directors that address risks inherent in their respective areas of oversight.
+Added: While our board of directors has a fiduciary duty to monitor and assess strategic risk exposure, our audit committee is responsible for overseeing our major financial risk exposures and the steps our management has taken to monitor and control these exposures, overseeing cybersecurity risks and assisting the board of directors in its oversight over enterprise risk management.
The audit committee also approves or disapproves any related person transactions.
−Removed: Our nominating and corporate governance
−Removed: committee monitors the effectiveness of our corporate governance guidelines and manages risks associated with the independence of the
−Removed: board of directors.
−Removed: Our compensation and leadership development committee assesses and monitors whether any of our compensation policies
−Removed: and programs has the potential to encourage excessive risk-taking.
−Removed: of Third-Party Service Providers
−Removed: have in place certain infrastructure, systems, policies, and procedures that are designed to proactively and reactively address circumstances
−Removed: that arise when unexpected events such as a cybersecurity incident occur.
−Removed: These include processes for assessing, identifying , and managing
−Removed: material risks from cybersecurity threats.
−Removed: Identifying, assessing, and managing cybersecurity risk is integrated into our overall risk
−Removed: management systems and processes, and we have in place cybersecurity and data privacy training and policies designed to (a) respond to
−Removed: new requirements in privacy laws and (b) prevent, detect, respond to, mitigate and recover from identified and significant cybersecurity
−Removed: have relied on the third-party security assessment procedures and data outflow control procedures to manage risks from cybersecurity
−Removed: threats associated with our use of third-party service providers.
−Removed: For example, the servers of the system of Hunan Ruixi are housed at
−Removed: third-party data centers, and its operations depend on the service providers’ ability to protect such systems in their facilities
−Removed: as well as their own systems.
−Removed: The qualified third-party performs security assessment by timely assessing their cybersecurity policies,
−Removed: data encryption and privacy policies and relevant certificates, establishing procedures in granting such third parties access to our
−Removed: database and requiring them to conduct regular inspections.
−Removed: Since in cooperation with third-party service providers may involve data
−Removed: outbound, we desensitize sensitive information before transferring such data.
−Removed: Chinese subsidiaries and affiliates have incurred, and will continue to incur, significant expenses in an effort to comply with cybersecurity
−Removed: and information security standards and protocols imposed by law, regulation, industry standards or contractual obligations to the date
−Removed: of this Report in all material respects.
+Added: Our nominating and corporate governance committee monitors the effectiveness of our corporate governance guidelines and manages risks associated with the independence of the board of directors.
+Added: Our compensation and leadership development committee assesses and monitors whether any of our compensation policies and programs has the potential to encourage excessive risk-taking.
+Added: Engagement of Third-Party Service Providers
+Added: We have in place certain infrastructure, systems, policies, and procedures that are designed to proactively and reactively address circumstances that arise when unexpected events such as a cybersecurity incident occur.
+Added: These include processes for assessing, identifying , and managing material risks from cybersecurity threats.
+Added: Identifying, assessing, and managing cybersecurity risk is integrated into our overall risk management systems and processes, and we have in place cybersecurity and data privacy training and policies designed to (a) respond to new requirements in privacy laws and (b) prevent, detect, respond to, mitigate and recover from identified and significant cybersecurity threats.
+Added: We have relied on the third-party security assessment procedures and data outflow control procedures to manage risks from cybersecurity threats associated with our use of third-party service providers.
+Added: For example, the servers of the system of Hunan Ruixi are housed at third-party data centers, and its operations depend on the service providers’ ability to protect such systems in their facilities as well as their own systems.
+Added: The qualified third-party performs security assessment by timely assessing their cybersecurity policies, data encryption and privacy policies and relevant certificates, establishing procedures in granting such third parties’ access to our database and requiring them to conduct regular inspections.
+Added: Since in cooperation with third-party service providers may involve data outbound, we desensitize sensitive information before transferring such data.
+Added: Our Chinese subsidiary and affiliates have incurred, and will continue to incur, significant expenses in an effort to comply with cybersecurity and information security standards and protocols imposed by law, regulation, industry standards or contractual obligations to the date of this Report in all material respects.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.