XML 49 R30.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
In the normal course of business, we may collect and store personal information and other sensitive information, including proprietary and confidential business information, financial information, trade secrets, intellectual property, information regarding trial participants in connection with clinical trials, sensitive third-party information and employee information. In an effort to protect this information from cybersecurity risks, we have developed a cybersecurity program that has been
integrated into our overall risk management process; it incorporates policies and practices designed to protect the confidentiality, integrity and security of our sensitive information.
As part of our cybersecurity risk management procedures, we perform system monitoring and scanning and utilize security tools supported by a third-party managed services provider. We also conduct penetration testing performed by a third-party provider. Employees are enrolled in cybersecurity awareness training courses designed to help them identify cybersecurity concerns and take appropriate actions, and we conduct periodic simulated phishing tests in an effort to further raise cybersecurity awareness and reduce the risk of a successful cyberattack. We have an incident response plan to guide us in responding to cybersecurity incidents, and have conducted tabletop exercises to test the plan. We also take steps to protect against business interruption and conduct annual restoration testing for major systems. In addition, we use a risk-based approach to assessing cybersecurity risks from certain critical third-party vendors. This program aims to assess the cybersecurity maturity of vendors who have access to our data or systems through an evaluation of the vendor’s cybersecurity practices.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
In the normal course of business, we may collect and store personal information and other sensitive information, including proprietary and confidential business information, financial information, trade secrets, intellectual property, information regarding trial participants in connection with clinical trials, sensitive third-party information and employee information. In an effort to protect this information from cybersecurity risks, we have developed a cybersecurity program that has been
integrated into our overall risk management process; it incorporates policies and practices designed to protect the confidentiality, integrity and security of our sensitive information.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Audit Committee, pursuant to its charter, has oversight over management of cybersecurity risks. Senior management provide the Audit Committee with periodic updates on data management and cybersecurity initiatives, as well as on significant existing and emerging cybersecurity risks, including cybersecurity incidents, as applicable.
We have a process to record identified risks from cybersecurity threats in our risk register, along with an assessment of the severity of the potential impact and the likelihood of occurrence. This process is designed to facilitate a unified and integrated assessment of corporate risk and governance. The risk register is reviewed periodically by senior management and at least annually by the Board of Directors.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee, pursuant to its charter, has oversight over management of cybersecurity risks. Senior management provide the Audit Committee with periodic updates on data management and cybersecurity initiatives, as well as on significant existing and emerging cybersecurity risks, including cybersecurity incidents, as applicable.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Senior management provide the Audit Committee with periodic updates on data management and cybersecurity initiatives, as well as on significant existing and emerging cybersecurity risks, including cybersecurity incidents, as applicable.
Cybersecurity Risk Role of Management [Text Block] Our cybersecurity program is managed by our Manager of Operations and IT Systems, who reports directly to senior management on matters regarding cybersecurity, as appropriate, and is supported by third-party vendors. Together, our senior management and Manager of Operations and IT Systems are responsible for leading company-wide cybersecurity strategy, policies, standards, and processes.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
Our cybersecurity program is managed by our Manager of Operations and IT Systems, who reports directly to senior management on matters regarding cybersecurity, as appropriate, and is supported by third-party vendors. Together, our senior management and Manager of Operations and IT Systems are responsible for leading company-wide cybersecurity strategy, policies, standards, and processes.
The Audit Committee, pursuant to its charter, has oversight over management of cybersecurity risks. Senior management provide the Audit Committee with periodic updates on data management and cybersecurity initiatives, as well as on significant existing and emerging cybersecurity risks, including cybersecurity incidents, as applicable.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our cybersecurity program is managed by our Manager of Operations and IT Systems, who reports directly to senior management on matters regarding cybersecurity, as appropriate, and is supported by third-party vendors
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true