XML 43 R29.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Risk Management and Strategy

We acknowledge the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data. While we are in the process of enhancing our cybersecurity practices, we are committed to continually improving and adapting to evolving threats to maintain a high standard of protection and to meet industry best practices.

Managing Material Risks and Integrated Overall Risk Management

We have developed and implemented a cybersecurity program that seeks to ensure the confidentiality, integrity, and availability of our information assets, including its critical systems. We use information security management standards, such as ISO 27001, as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.

We have integrated cybersecurity risk management into our broader enterprise risk management framework. This integration is designed to promote a company-wide culture of cybersecurity awareness and risk management. Our risk management team, in collaboration with external consultants, has assessed and addressed and continues to assess and address cybersecurity risks in alignment with our operational and business needs. This integration ensures that cybersecurity considerations are increasingly embedded in our decision-making processes at every level.

Our cybersecurity framework also draws upon the National Institute of Standards and Technology Cybersecurity Framework (at its currently 2.0 version), which provides guidance for identifying, assessing, and managing cybersecurity risks. While we are in the early stages of fully implementing this framework, we are committed to following its principles as we strengthen our cybersecurity measures to protect both our digital and physical assets.

Engage Third-parties on Risk Management

Recognizing the evolving nature of cybersecurity threats, we have engaged with external experts, including cybersecurity assessors, consultants, and auditors, to assess and enhance our risk management systems. These third-parties have and continue to assist us with evaluating our cybersecurity posture, recommending improvements, and advising on the implementation of best practices. In 2025, we completed a comprehensive cybersecurity assessment across all platforms with external experts, such as Amazon Web Services, amongst others. As we progress, we will continue leveraging these external insights to enhance our cybersecurity strategies and ensure alignment with industry standards.

Oversee Third-party Risk

We understand the potential risks associated with third-party service providers, and we are working on implementing stronger oversight processes. While we have initiated security assessments for our third-party providers, we are in the process of enhancing these efforts to include more frequent evaluations and ongoing monitoring. This will help mitigate the risk of security incidents originating from third-parties.

Risks from Cybersecurity Threats

To date, we have not encountered cybersecurity incidents that have materially impaired our operations or financial condition. However, given the data-driven nature of our business and the prevalent use of technology in operating our business, we face cybersecurity risks inherent to our normal course of operation that, if realized, are reasonably likely to materially affect our operations or financial condition. As a result, we have a dedicated cybersecurity response team and proactively prepare for the possibility of cybersecurity risks, ensuring that our systems are protected against potential threats. The cybersecurity response team (i) responds to actual and suspected cybersecurity threats, (ii) assesses the severity of any such actual or suspected cybersecurity threat, (iii) prepares and maintains incident reports and (iv) prepares cybersecurity incident response procedures designed to help protect the security of the Company’s systems.

Cybersecurity Risk Management Processes Integrated [Text Block] We have developed and implemented a cybersecurity program that seeks to ensure the confidentiality, integrity, and availability of our information assets, including its critical systems.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] To date, we have not encountered cybersecurity incidents that have materially impaired our operations or financial condition.
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Governance

Our Board understands the critical nature of cybersecurity and is closely involved in overseeing our efforts to mitigate cybersecurity risks. We continue to formalize governance structures and oversight mechanisms to ensure that these risks are managed effectively, with the aim of strengthening our operational integrity and enhancing stockholder confidence. As of December 31, 2025, no risks from cybersecurity threats, including as a result of cybersecurity incidents we have experienced in the past, have materially affected us, including our results of operations and financial condition.

Management’s Role Managing Risk

Our Chief Technology Officer (“CTO”) is the senior officer responsible for cybersecurity risk management. Our CTO receives regular updates, which include an overview of the current cybersecurity landscape, the status of ongoing initiatives, and compliance with regulatory requirements. We are establishing structured processes for ongoing communication among the executive team to ensure they remain informed and timely involved in key cybersecurity decisions.

Risk Management Monitoring

We are committed to regularly monitoring cybersecurity risks and are in the process of implementing enhanced monitoring systems. With the assistance of cybersecurity consultants, we are refining our cybersecurity policies and controls, including regular audits and the deployment of advanced security measures such as Multi-Factor Authentication and stronger email filtering protocols. In addition, we have an incident response team and are continuing to refine our incident response plans, communication protocols, and disaster recovery plans to be prepared for any potential cybersecurity incidents.

Security Training

We are providing cybersecurity training to our employees and plan to continue enhancing this program on an ongoing basis. Regular updates and internal campaigns will ensure that our employees are well-prepared to identify and respond to cybersecurity threats in an effective manner.

Reporting to Management and the Board

The CTO regularly provides reports and informs the CEO and CFO cybersecurity profile. These reports address the status of risk mitigation initiatives, the evolving threat landscape, the results of vulnerability assessments and penetration testing, and the progress of key cybersecurity programs, including the implementation of a Zero Trust access framework, continuous vulnerability scanning with centralized alerting, and our pursuit of SOC 2 readiness.

The Board maintains direct oversight of the Company’s cybersecurity program. Management provides the Board with no fewer than annual comprehensive briefings on cybersecurity risk assessment, the effectiveness of the Company’s information security controls and the status of ongoing cybersecurity initiatives. These briefings also cover the Company’s incident response preparedness and any changes in the regulatory environment affecting the Company’s cybersecurity obligations.

In addition to the regularly scheduled briefings, significant cybersecurity matters will be escalated to the Board for review, where management, including the CTO, will provide detailed updates on risk assessments, incident responses, and the effectiveness of our cybersecurity strategies. The Board will continue to evaluate the progress of our cybersecurity initiatives and offer guidance to help strengthen our efforts.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board understands the critical nature of cybersecurity and is closely involved in overseeing our efforts to mitigate cybersecurity risks. We continue to formalize governance structures and oversight mechanisms to ensure that these risks are managed effectively, with the aim of strengthening our operational integrity and enhancing stockholder confidence. As of December 31, 2025, no risks from cybersecurity threats, including as a result of cybersecurity incidents we have experienced in the past, have materially affected us, including our results of operations and financial condition
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our Chief Technology Officer (“CTO”) is the senior officer responsible for cybersecurity risk management.
Cybersecurity Risk Role of Management [Text Block]

Our Chief Technology Officer (“CTO”) is the senior officer responsible for cybersecurity risk management. Our CTO receives regular updates, which include an overview of the current cybersecurity landscape, the status of ongoing initiatives, and compliance with regulatory requirements. We are establishing structured processes for ongoing communication among the executive team to ensure they remain informed and timely involved in key cybersecurity decisions.

Cybersecurity Risk Management Expertise of Management Responsible [Text Block]

We are committed to regularly monitoring cybersecurity risks and are in the process of implementing enhanced monitoring systems. With the assistance of cybersecurity consultants, we are refining our cybersecurity policies and controls, including regular audits and the deployment of advanced security measures such as Multi-Factor Authentication and stronger email filtering protocols. In addition, we have an incident response team and are continuing to refine our incident response plans, communication protocols, and disaster recovery plans to be prepared for any potential cybersecurity incidents.

Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]

The CTO regularly provides reports and informs the CEO and CFO cybersecurity profile. These reports address the status of risk mitigation initiatives, the evolving threat landscape, the results of vulnerability assessments and penetration testing, and the progress of key cybersecurity programs, including the implementation of a Zero Trust access framework, continuous vulnerability scanning with centralized alerting, and our pursuit of SOC 2 readiness.