Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
Not applicable.
Item 1C. Cybersecurity
Risk Management and Strategy
We believe cybersecurity is critical to supporting our vision and enabling our strategy. We have servers, computers, and other technological equipment with electronic files containing Company intellectual property including customer information. We also have hardware and firmware that is provided to third parties for testing as part of our manufacturing process. Additionally, we are an IoT service provider through the e-Compass cloud-based platform. Although we mitigate the threat of a cyber-attack with updates, patches, lifecycle replacements of legacy equipment and employee training, no system is completely safe from an attack or theft of intellectual property that could cause significant loss or business interruption.
We generally face a multitude of cybersecurity threats that are common to most industries. Examples of threats to our systems could include: (i) ransomware allowing unauthorized users to access our databases, encrypt the data and demand payment in order to provide a decryption key, (ii) denial of Service (DoS) where an unauthorized user exerts heavy traffic on our servers, making them unavailable, (iii) SQL Infection where unauthorized users cause interference with database content, (iv) insider threats where users misuse our platforms, creating data loss or corruption, and (v) cloud misconfigurations leading to unintended exposure of sensitive data. A significant breach of our systems or those of our third-party vendors could result in the loss of sensitive data, intellectual property, or customer information, leading to operational disruptions, reputational damage, and litigation. Our customers, suppliers, and partners also face similar cybersecurity threats and, while we have not been materially affected to date, a cybersecurity incident impacting us or any of these entities could materially adversely affect our operations, performance, and results of operations. These cybersecurity threats and related risks make it imperative that we maintain a strong focus on cybersecurity.
We assess, identify and manage material risks from cybersecurity threats through various policies, procedures and processes of our information technology (“IT”) department, which include 1) review of IT security policy and change management policy review, 2) IT control procedures, 3) firewall reviews, 4) system backups and 5) procurement of cyber liability insurance .
We have one full-time IT employee, with over a decade of cybersecurity experience. This IT employee reports to the General Counsel, a former Certified Information Systems Security Professional. The General Counsel and other executive officers provide direct updates to the Audit Committee at least annually, or if a significant event were to occur, immediately. We also train our employees on cybersecurity threats on a regular basis and numerous cybersecurity service providers are engaged to monitor and proactively protect our IT systems. Cyber insurance coverage is maintained to mitigate risks to our operations. We conduct continuous vulnerability scanning. All vendor agreements are reviewed by our legal department, and risks are highlighted and mitigated through discussions with IT, and our Chief Executive Officer and Chief Financial Officer.
29
Table of Contents
During the fiscal year ended December 31, 2025, we did not experience any cybersecurity incidents that, individually or in the aggregate, were determined to be material to our financial condition or results of operations. We have not faced any threats that have resulted in loss of information, or inability to operate for any period of time; nor have any threats affected or been deemed likely to materially affect our business strategy, results of operations, or financial condition. If a material cybersecurity incident were to occur, it would be evaluated based on both quantitative and qualitative factors.
Governance
The Board of Directors oversees the risks of cybersecurity threats and communicates with the Chief Executive Officer and Chief Financial Officer regarding controls in place. The Board of Directors receives periodic briefings from the Chief Executive Officer and Chief Financial Officer, concerning cybersecurity, information security and technology risks, and our related risk mitigation programs. Any material cybersecurity threats, breaches or other concerns are immediately communicated to the Board of Directors.
Item 2. Properties
In 2025, we entered into a lease agreement for our corporate headquarters located at 3590 North First Street in San Jose, California. The lease is valid through the end of 2027. This space, with a total of 12,783 square feet, is used for our headquarters and for research and development efforts.
Item 3. Legal Proceedings
We are not currently a party to any legal proceedings that we believe will have a material adverse effect on our business or financial condition. We may, however, be subject to various claims and legal actions arising in the ordinary course of business from time to time.
Item 4. Mine Safety Disclosures
Not applicable.
PART II