This Security Addendum is agreed between 91导航 and Customer pursuant to the terms of the 91导航 Master Services Agreement (which together with any attachments or supplements thereof constitutes the “Agreement“) under which Customer has agreed to procure and 91导航 has agreed to provide certain Services (as defined in the Agreement). This is version v1202609 which is effective from September 15, 2026.
This Security Addendum sets out non-exhaustive details of the administrative, physical, and technical safeguards implemented and maintained by 91导航 to protect the security, confidentiality and integrity of Customer Data, summarising the minimum security standards maintained by 91导航. These may be subject to technical progress and development and 91导航 may update or modify them from time to time at its sole discretion and without notice to Customer, provided always that such updates and modifications do not result in the material decrease in or degradation of the overall functionality or security of the Software or the Services subscribed for by Customer.
Definitions
Capitalised terms used but not defined in this Security Addendum have the same meanings as set out in the Agreement.
For the purposes of this Security Addendum the following words and phrases shall have the following meanings:
鈥91导航 Personnel鈥 means 91导航 and its affiliate鈥檚 officers, directors, employees, agents, contractors, and consultants who may have access to Customer Data.
鈥Security Incident鈥 means a violation of 91导航鈥檚 or its computer security policies that has or is reasonably expected to have a material impact on 91导航鈥檚 Services and business operations, including but not limited to unplanned disruptions, denials of service attack, malware infection such as ransomware, or an outside cyber-attack intended to disrupt, disable or destroy 91导航鈥檚 computing environment.
鈥Security Breach鈥 means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data, transmitted, stored or otherwise Processed by 91导航 or its Sub-processors of which 91导航 becomes aware.
Security Governance
Protection of Customer Data. 91导航 has and will maintain appropriate administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Customer Data, as summarized in this document. 91导航 will not materially decrease the overall security of the Services during any Subscription Period.
Security Program. 91导航 has and will maintain a comprehensive information security program that is aligned with industry best practices and appropriate to the nature and scope of 91导航鈥檚 activities and services. This program utilizes a standard set of controls and includes the use of precautionary measures identifying internal and external risks and assessing the sufficiency of any systems and procedures in place to control these risks.
Security Policies. 91导航 has and will maintain information security policies, standards and procedures, which shall be kept up to date, and revised whenever relevant changes are made that impact the security, confidentiality, and integrity of the Services provided. All policies are reviewed no less often than annually.
Independent Attestation. 91导航 has and will continue to engage third party auditors to verify the adequacy of its security measures. These audits: (i) will be performed annually; (ii) will be performed according to internationally recognized standards; (iii) will be performed by independent third party security professionals at 91导航鈥檚 selection and expense.
Security Assessment Questionnaires. 91导航 shall grant Customer access to 91导航鈥檚 Whistic profile, which contains up to date standard form security questionnaires. Not more than once per year, 91导航 shall provide Customer with responses to reasonable questions from Customer, provided that the answers are not already available from within the Whistic profile.
Certification. 91导航 has and will maintain certification to the ISO/IEC 27001 standard as external validation of its security controls. A copy of the certificate will be provided to Customer upon request.
Other Reviews; Audits. 91导航 engages third party auditors to verify the adequacy of its security measures. These audits: (i) will be performed at least annually; (ii) will be performed according to internationally recognized standards; (iii) will be performed by independent third party security professionals at 91导航鈥檚 selection and expense and (iv) will result in the generation of an audit report (鈥淎udit Report鈥) which will constitute 91导航鈥檚 Confidential Information. No more than once during any consecutive 12-month period, on the Customer鈥檚 written request and subject to the confidentiality obligations in the Agreement, 91导航 shall make available to a Customer that is not a competitor of 91导航 (or Customer鈥檚 independent, third-party auditor that is not a competitor of 91导航) a copy of 91导航鈥檚 then most recent Audit Report or the summary results, as appropriate. Within such request, the Customer shall be entitled to ask reasonable questions of 91导航 related to its compliance with the terms of this agreement, and 91导航 shall use its reasonable endeavors to respond adequately when providing the Audit Report.
Security Contact. In the event that Customer identifies a security issue or concern with 91导航, they can contact the appropriate personnel via security@gearset.com.
Privacy Contact. In the event that Customer identifies a data privacy issue or concern with 91导航, they can contact the appropriate personnel via privacy@gearset.com.
Personnel Management
Background Checks. 91导航 will, in accordance with applicable law and regulation, perform, or require to have performed, criminal background checks for all 91导航 Personnel with access to Customer Data prior to granting access to such data.
Personnel security and nondisclosure. All 91导航 personnel with access to Customer Data shall be bound by obligations of confidentiality no less onerous than those set out in clause 7 of the Agreement.
Security & Privacy Training. 91导航 has and will maintain a security and privacy awareness program to train all 91导航 Personnel. This program will include but is not limited to training about: (i) data classification and handling; (ii) physical security controls; (iii) data protection; (iv) malware and phishing; (v) removable media; (vi) credential management, and; (vii) security incident reporting. 91导航 provides such training upon hire and annually thereafter.
Disciplinary Action. 91导航 has and will maintain policies to address 91导航 Personnel violations of internal policies and procedures, and implement any disciplinary measures appropriate for the violation committed, including and up to termination of employment.
Access Management
Physical Security. 91导航 has and will maintain appropriate physical security controls to prevent unauthorized physical access to areas in which Customer Data is handled, processed, or stored, over which 91导航 has control.
Hosting Infrastructure Security. 91导航 will ensure that all instances are hosted on Amazon Web Services (鈥AWS鈥). These AWS data centers offer state-of-the art physical and environmental protection for the servers and infrastructure that comprise 91导航鈥檚 hosting environment.
Access Controls. 91导航 has and will maintain commercially reasonable and appropriate technical controls, which shall follow industry best practices such as least privilege principle and segregation of duties, to prevent unauthorized access and disclosure of Customer Data.
91导航 will only grant 91导航 Personnel access to systems that process or store Customer Data if it is required to perform their roles.
91导航 will no less than annually perform access reviews for all 91导航 Personnel in accordance with its internal policy. Findings shall be remediated in a timely manner.
91导航 Personnel credentials will be promptly deactivated upon the termination of employment or the end of the relevant services being provided.
Multi-Factor Authentication (鈥淢FA鈥). MFA will be used for all accounts to applications that store or process Customer Data. Where possible, 91导航 will utilize hardware keys and will not utilize SMS as the authentication method.
Password Management. 91导航 has and will maintain password policies and controls to ensure that 91导航 Personnel use strong (at least 16 characters), unique passwords for all services. Passwords will be stored in secured password vaults protected by MFA. Passwords will be rotated in the event of, or suspicion of, their compromise.
Third-Party Management. 91导航 has and will maintain a third-party risk management program and ensure that all third-party service providers that have access to Customer Data employ technical and organizational security measures that meet 91导航鈥檚 expectations and provide adequate protection to Customer Data.
Business Continuity and Disaster Recovery
91导航 has and will maintain a formal Business Continuity Plan (鈥BCP鈥) and a Disaster Recovery Plan (鈥DRP鈥) that clearly define roles and responsibilities of the applicable 91导航 Personnel as well as set out the appropriate scope and purpose of contingency plans to ensure organizational resiliency.
The BCP and DRP will cover resiliency of both the organization itself and the Services.
The BCP and DRP will be tested annually, and associated findings resulting from plan testing must be remediated in a timely manner.
The BCP and DRP will be reviewed annually and updated as necessary to address new risks and align with industry standards.
Data Security and Management
Data Availability. 91导航 will ensure that Customer Data is protected against accidental destruction or loss in line with our published RPO of 24 hours and RTO of 1 hour. 91导航 will use reasonable commercial efforts to make the Software available 24 hours a day, 7 days a week, except for (i) scheduled maintenance (of which 91导航 shall endeavour to give advance electronic warning), and (ii) any unavailability (including unplanned maintenance) caused by circumstances beyond 91导航鈥檚 reasonable control.
Data Loss Prevention. 91导航 has and will maintain controls to protect Customer Data from being shared or leaked via network file sharing, and which prevents the use of removable storage media (i.e. USB, CD, DVD etc.) on its endpoints.
Data Return and Destruction. Customer has the ability through its use of the Software to retrieve or delete Customer Data during the Subscription Period. On request, within 60 days of termination or expiry of the Agreement, 91导航 will, at Customer鈥檚 election, delete or return to Customer all relevant Customer Data (including copies) in 91导航鈥檚 possession, save to the extent that 91导航 is required by any applicable law to retain some or all of the Customer Data.
Deletion Standard. All Customer Data deleted by 91导航 will be securely deleted using an industry-accepted practice designed to prevent data from being recovered using standard disk and file recovery utilities (e.g. secure overwriting, degaussing of magnetic media in an electromagnetic flux field of 5000+ GER, shredding, or mechanical disintegration).
Data Residency. Customer Data is processed and (where applicable) stored in Amazon Web Services data centres in specific hosting regions, selected by Customer when creating their account in the Software. Unless Customer has given written prior approval, 91导航 will ensure that Customer Data will not be transferred out of the region selected by Customer.
Encryption. 91导航 will ensure that Customer Data is encrypted to protect it against unauthorized access.
Encryption at Rest. Customer Data stored on 91导航 managed or controlled systems, networks, and environments will be encrypted using industry standard mechanisms and cipher suites (such as AES-256).
Encryption in Transit. Customer Data that is transmitted between the 91导航 Software and Third-Party Services shall be encrypted using industry standard mechanisms and cipher suites (such as TLS 1.2).
Key Management. 91导航 utilizes dedicated encryption keys to encrypt Customer Data. Such encryption keys are uniquely associated with each Customer.
All keys are protected against modification; secret and private keys are protected against unauthorized disclosure.
When a cryptographic key is compromised, all use of the key will cease.
Encryption key management systems are designed so that the compromise of a single key does not cause failure to the wider Software.
Software Security
Secure Software Development Life Cycle (鈥淪DLC鈥). 91导航 has and will maintain processes to promote SDLC practices to ensure the security, hygiene, and integrity of its code output. This includes regular code review, quality assurance checks, and adherence to applicable industry standards for coding practices.
Production Environments. Production environments will be logically and/or physically separated from any testing, development, or staging environments. Production code will not be released without 91导航 Personnel first conducting code reviews and analysis.
Change Management
Configuration and Change Management Policies. 91导航 has and will maintain formal configuration and change management policies which shall be reviewed and updated as needed, but in no case reviewed less than annually.
Software Changes. Any change to the Software will be documented in accordance with these policies, and will be implemented utilizing segregation of duties 鈥 the change performer must differ from the change approver.
Risk Management
91导航 has and will maintain a defined security risk management and assessment methodology to identify ongoing security risks and how to address them. Risk assessments will be reviewed at least annually, and whenever there is a significant change to company operations or products. Such risk assessments, their findings, and attendant remediation plans will be documented.
Asset Management
Asset Management Program. 91导航 has and will maintain an asset management program which includes an inventory of all devices that connect to 91导航 systems. 91导航 will programmatically monitor and protect these devices, and ensure they are securely configured.
Endpoint Protection. 91导航 has and will maintain the following controls for all devices that connect to 91导航 systems:
ensure endpoints are encrypted (i.e. full disk encryption).
ensure a firewall is enabled on endpoints (where it is possible to do so).
ensure endpoints deploy an industry-standard anti-malware and anti-virus system which is centrally managed and performs regular scans.
ensure 91导航 Personnel are utilizing the latest and most secure web- browser when accessing 91导航鈥檚 production environment.
limit the administrative privileges of assets to only authorized 91导航 Personnel with a need for access.
apply Operating System and server hardening controls to minimize the attack surface and protect against malicious attacks.
configure endpoints to automatically apply critical Operating System patches.
Network Security
Network Security. 91导航 secures its networks using a defence-in-depth approach that incorporates both commercially available equipment and industry standard techniques.
91导航 has and will maintain either a network or host-based Intrusion Detection Solution or Intrusion Protection Solution on all 91导航-controlled networks used to store, process, transmit or access Customer Data. These systems provide continuous monitoring of 91导航鈥檚 network and early detection of potential security threats.
Unauthorized attempts to access the 91导航 network will be investigated accordingly.
91导航 will collect, manage, retain, and analyse audit logs of events to help detect, investigate, and recover from unauthorized activity that may affect Customer Data. Logs will be kept and maintained for at least 12 months. If 91导航 is providing any software (either as a service or as packaged software), 91导航 will provide Customer access to an Audit and Reporting API at /api/. 91导航 will implement reasonable controls to control access to and prevent modification of security audit logs.
91导航 will review access logs regularly to ensure that access permissions are appropriate and necessary and to analyse them for security threats.
Guest Access. 91导航 has and will maintain appropriate controls to ensure that only authorized devices are connected to its networks. 91导航 will ensure that guests or unauthorized endpoints do not have access to 91导航鈥檚 systems and production networks.
Vulnerability Management
Vulnerability Management Program. 91导航 has and will maintain a Vulnerability Management Program that adheres to industry best practices. At minimum, 91导航 will conduct scans for known vulnerabilities on all externally facing systems, environments, and networks that are managed and/or controlled by 91导航.
Penetration Testing. At least annually, 91导航 will engage a qualified independent third- party supplier to conduct a penetration test of 91导航鈥檚 externally facing production systems, network, and environments and produce a written report of the findings. A copy of the recent penetration test report will be made available to Customer upon request.
Patching and Remediation. All vulnerabilities identified through the scans/testing performed by 91导航 will be remediated in accordance with the following timelines (risk ratings of vulnerabilities shall be based on the Common Vulnerability Scoring System):
Urgent, critical, and high-risk vulnerabilities will be remediated with 30 days of discovery;
Medium-risk vulnerabilities will be remediated within 90 days of discovery;
Low-risk vulnerabilities or those which have no impact on Customer Data will be remediated at 91导航鈥檚 discretion.
Mitigating Controls. Should 91导航 be unable to remediate the vulnerabilities within the defined time frame, mitigating controls will be implemented.
Bug-bounty. 91导航 has and will maintain a bug-bounty and crowdsourced penetration testing program to encourage responsible disclosure of any vulnerabilities. Reported vulnerabilities are triaged, prioritized, and remediated in a timely manner in line with the remediation timelines.
Incident and Breach Management
Incident Response Plan. 91导航 has and will maintain formal incident response policies and procedures (鈥Incident Response Plan鈥 or 鈥IRP鈥) that respond to both Security Incidents and Security Breaches. The IRP establishes responsibilities for incident oversight and management, and is reviewed at least annually to ensure its consistency with industry standards and company practices. 91导航 trains all 91导航 Personnel on IRP procedures.
Breach Notification. 91导航 will notify Customer promptly, and in any case within 72 hours, after becoming aware of any Security Breach by emailing a customer appointed contact and providing incident detail, impact and a dedicated point of contact within 91导航 that will engage with the Customer security team until the incident is remediated and information requested by Customer security is made available. 91导航 shall make reasonable efforts to identify the cause of any Security Breach and take those steps as 91导航 deems necessary and reasonable to remediate the cause of such a Security Breach to the extent the remediation is within 91导航鈥檚 reasonable control. 91导航 will provide reasonable updates to Customer regarding its investigation, remediation and resolution timeframe of the issue.
The notice to be provided above shall detail, to the extent relevant and reasonably available to 91导航 at the time:
the date and time of the Security Breach;
the cause of the Security Breach, if known;
the categories and approximate number of records of Customer Data affected;
the likely consequences of the Security Breach;
the measures taken, or proposed to be taken, by 91导航 to address and remediate the cause of the Security Breach; and
the name and contact details of the person from whom more information can be obtained.
91导航 shall keep Customer reasonably updated of any material developments to its investigation, handling and remediation of the Security Breach, and Customer and 91导航 shall reasonably co-operate to mitigate the risk to each party.
The obligations in paragraph 13 shall not apply to incidents that are caused by Customer or its Authorised Users, or by access to the Services in breach of clause 4 (Use of Services and Documentation, Customer Obligations) of the MSA, unless and until the Customer has notified 91导航 that they constitute a Security Breach in which case 91导航 shall provide the Customer with reasonable assistance (at Customer鈥檚 cost) in investigating the information set out in paragraph 13.3 above.
Third-Party Notifications. 91导航 agrees that, except to the extent required by law, it shall not notify any third party (including any regulatory authority or customer) of any Security Breach without first obtaining Customer鈥檚 prior written consent (which shall not be unreasonably withheld or delayed). Further, 91导航 agrees that, subject to any legal obligation on 91导航, Customer shall have the sole right to determine: (i) whether notice of the Security Breach is to be provided to any individuals, regulators, law enforcement agencies, or others; and (ii) the form and contents of such notice
Subcontracts
Should 91导航 engage any subcontractors in relation to the provision of the Services, it shall enter into a written agreement with each subcontractor containing obligations relating to the security and confidentiality of data which are no less protective than those in the Agreement, to the extent applicable to the nature of the services provided by such subcontractor. 91导航 shall be liable for the acts and omissions of its subcontractors to the same extent 91导航 would be liable if performing the services of each subcontractor directly under the terms of the Agreement, except as otherwise set forth in the agreement.
Artificial Intelligence
91导航 shall not use, nor permit any third party to use, Customer Data to train any artificial intelligence or machine learning engine or system, neural network, or similar system except as expressly permitted by Customer in writing (such written consent may be withheld by Customer in its sole discretion).
HIPAA (if applicable)
HIPAA Compliance. If Customer has (a) executed a Business Associate Agreement (鈥BAA鈥) with 91导航, and (b) Customer is using 91导航鈥檚 HIPAA instances to process ePHI, and (c) Customer has followed 91导航鈥檚 HIPAA implementation guidelines; then 91导航 affirms that it has and will maintain appropriate safeguards for the ePHI as required by HIPAA, in accordance with the terms of the BAA.
Code Reviews
To the extent that Customer is using 91导航鈥檚 Code Reviews licenses, Customer Data shall be processed and (where applicable) stored in AWS data centres in region AWS EU-West-1 (Dublin, Ireland). This is regardless of the 91导航 hosting region chosen for use with other 91导航 products.