XML 48 R28.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

We have implemented processes to identify and assess the cybersecurity threats that could affect our business and information systems and we use various tools and methodologies to test our cybersecurity defenses on a regular basis. As part of this process, we perform regular vulnerability scans and penetration tests and engage third party experts to perform evaluations of our strengths and vulnerabilities. In addition, we perform an annual enterprise risk assessment procedure that evaluates business continuity risks, including an evaluation of cybersecurity risks. The results of these evaluations, along with recommendations for improvements and remediations to our cybersecurity program, if deemed necessary, are periodically reported to senior management and the audit committee of our board of directors, which is tasked with oversight of our cybersecurity program. Reports provided to our senior management and audit committee include updates on our cyber risks and threats, the status of projects to strengthen our information technology systems and assessments of our cybersecurity program. Our senior management and audit committee use the results from these evaluations and reports as part of their risk assessment and decision-making functions.

We require that all employees, consultants and third party contractors adhere to our cybersecurity policies. Key third party contractors undergo a qualification process under our quality management programs (including cGMP and GCP) wherein we assess, among other things, their cybersecurity risk profile. Third party contractors, such as CROs and information technology service providers, that handle sensitive data, including patient data, are subjected to increased scrutiny. Based on identified risks, we may periodically review and reassess our third party contractors on an ongoing basis.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We have implemented processes to identify and assess the cybersecurity threats that could affect our business and information systems and we use various tools and methodologies to test our cybersecurity defenses on a regular basis. As part of this process, we perform regular vulnerability scans and penetration tests and engage third party experts to perform evaluations of our strengths and vulnerabilities. In addition, we perform an annual enterprise risk assessment procedure that evaluates business continuity risks, including an evaluation of cybersecurity risks. The results of these evaluations, along with recommendations for improvements and remediations to our cybersecurity program, if deemed necessary, are periodically reported to senior management and the audit committee of our board of directors, which is tasked with oversight of our cybersecurity program. Reports provided to our senior management and audit committee include updates on our cyber risks and threats, the status of projects to strengthen our information technology systems and assessments of our cybersecurity program. Our senior management and audit committee use the results from these evaluations and reports as part of their risk assessment and decision-making functions.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The results of these evaluations, along with recommendations for improvements and remediations to our cybersecurity program, if deemed necessary, are periodically reported to senior management and the audit committee of our board of directors, which is tasked with oversight of our cybersecurity program. Reports provided to our senior management and audit committee include updates on our cyber risks and threats, the status of projects to strengthen our information technology systems and assessments of our cybersecurity program. Our senior management and audit committee use the results from these evaluations and reports as part of their risk assessment and decision-making functions.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] audit committee of our board of directors, which is tasked with oversight of our cybersecurity program.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Reports provided to our senior management and audit committee include updates on our cyber risks and threats, the status of projects to strengthen our information technology systems and assessments of our cybersecurity program. Our senior management and audit committee use the results from these evaluations and reports as part of their risk assessment and decision-making functions.
Cybersecurity Risk Role of Management [Text Block] Our cybersecurity program is overseen by our head of information technology, who has significant experience in the information technology space. Our information technology team is responsible for leading our cybersecurity strategy, policy, standards, architecture and processes. Such team is responsible for the identification and reporting of risks to our management and board, as described above. Our information technology team maintains a security operations center intended to identify anomalous activity. Further, our policies require all employees to notify our compliance, legal or information technology functions in the event of a cybersecurity incident.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] our head of information technology
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our cybersecurity program is overseen by our head of information technology, who has significant experience in the information technology space.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our cybersecurity program is overseen by our head of information technology, who has significant experience in the information technology space. Our information technology team is responsible for leading our cybersecurity strategy, policy, standards, architecture and processes. Such team is responsible for the identification and reporting of risks to our management and board, as described above. Our information technology team maintains a security operations center intended to identify anomalous activity.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true