XML 55 R36.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Risk Management and Strategy

We have implemented robust processes for assessing, identifying and managing material risks from cybersecurity threats and monitoring the prevention, detection, mitigation and remediation of material cybersecurity incident. We adopt security and data privacy practices in compliance with local cyber security law and data privacy regulations in the countries and regions that we operate, including cyber security law of mainland China and GDPR. We have also integrated cybersecurity risk management into our overall enterprise risk management system.

We have developed a comprehensive cybersecurity threat defense system to address both internal and external threats. This system encompasses various levels, including network, host and application security and incorporates systematic security capabilities for threat defense, monitoring, analysis, response, deception and countermeasures. We are committed to protecting information security of all users and business partners within our cloud SIM architecture, and strive to manage cybersecurity risks and protect sensitive information through various means, such as technical safeguards, procedural requirements, an intensive program of monitoring on our corporate network, continuous testing of aspects of our security posture, a robust incident response program and regular cybersecurity awareness training for employees.

We have a security team of engineers and technicians dedicated to protecting the security of our data and our system. The mechanism of our cloud SIM technology is secure as it does not authorize third parties to modify SIM card profiles. We anonymize and encrypt confidential personal information and take other technological measures to ensure the secure processing, transmission and usage of data. We have also established stringent internal protocols under which we grant classified access to confidential personal data only to limited employees with strictly defined and layered access authority. In addition, we use third-party security system provided by our cloud service providers. We have processes in place to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers. Our security system is capable of handling malicious attacks each day to safeguard the security of our architecture and to protect the privacy of our users. Furthermore, our IT department regularly monitors the performance of our app, platform and infrastructure to enable us to respond quickly to potential problems, including potential cybersecurity threats.

Cybersecurity Risk Management Processes Integrated [Text Block] We have also integrated cybersecurity risk management into our overall enterprise risk management system.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]

As of the date of this annual report, we have not experienced any material cybersecurity incidents or identified any material cybersecurity threats that have affected or are reasonably likely to materially affect us, our business strategy, results of operations or financial condition.

Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] true
Cybersecurity Risk Role of Management [Text Block]

Governance

Our board of directors is responsible for overseeing our cybersecurity risk management. Our board of directors shall (i) maintain oversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our company, (ii) review updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, presented by our chief executive officer, chief financial officer and cybersecurity officer on a quarterly basis, and (iii) review disclosure concerning cybersecurity matters in our annual report on Form 20-F presented by our chief executive officer, chief financial officer and cybersecurity officer.

At management level, our chief executive officer, chief financial officer and cybersecurity officer, which are collectively referred to as our Cybersecurity Risk Management Officers, are responsible for assessing, identifying and managing material risks from cybersecurity threats to our company and monitoring the prevention, detection, mitigation and remediation of material cybersecurity incident. Our Cybersecurity Risk Management Officers report to our board of directors (i) on a quarterly basis on updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, and (ii) on disclosure concerning cybersecurity matters in our annual report on Form 20-F.

If a cybersecurity incident occurs, our Cybersecurity Risk Management Officers will promptly organize relevant personnel for internal assessment and if it is determined that the incident could potentially be a material cybersecurity event, our Cybersecurity Risk Management Officers will promptly report the incident and assessment results to our disclosure committee, our board of directors, and other members of senior management and external legal counsel, to the extent appropriate. Our Cybersecurity Risk Management Officers shall prepare disclosure material on the cybersecurity incident for review and approval by the disclosure committee and board of directors, and other members of senior management (if necessary), before it is disseminated to the public.

Cybersecurity Risk Board of Directors Oversight [Text Block]

Our board of directors is responsible for overseeing our cybersecurity risk management. Our board of directors shall (i) maintain oversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our company, (ii) review updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, presented by our chief executive officer, chief financial officer and cybersecurity officer on a quarterly basis, and (iii) review disclosure concerning cybersecurity matters in our annual report on Form 20-F presented by our chief executive officer, chief financial officer and cybersecurity officer.

At management level, our chief executive officer, chief financial officer and cybersecurity officer, which are collectively referred to as our Cybersecurity Risk Management Officers, are responsible for assessing, identifying and managing material risks from cybersecurity threats to our company and monitoring the prevention, detection, mitigation and remediation of material cybersecurity incident. Our Cybersecurity Risk Management Officers report to our board of directors (i) on a quarterly basis on updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, and (ii) on disclosure concerning cybersecurity matters in our annual report on Form 20-F.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our board of directors shall (i) maintain oversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our company, (ii) review updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, presented by our chief executive officer, chief financial officer and cybersecurity officer on a quarterly basis, and (iii) review disclosure concerning cybersecurity matters in our annual report on Form 20-F presented by our chief executive officer, chief financial officer and cybersecurity officer.
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our Cybersecurity Risk Management Officers shall prepare disclosure material on the cybersecurity incident for review and approval by the disclosure committee and board of directors, and other members of senior management (if necessary), before it is disseminated to the public.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true