|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
We recognize the importance of assessing, identifying, and managing material risks associated with cybersecurity threats, as such term is defined in Item 106(a) of Regulation S-K. These risks include, among other things: operational risks, intellectual property theft, fraud, extortion, harm to employees or customers and violation of data privacy or security laws. Identifying and assessing cybersecurity risk is integrated into our overall risk management systems and processes. Our integration involves regular, systematic reviews and assessments conducted alongside other operational risks inspections. The findings from these reviews are communicated across relevant departments timely to inform decision-making. We have not engaged outside assessors, consultants, auditors or third parties in connection with such processes. We have processes to oversee and identify such risks from cybersecurity threats associated with our use of any third-party provider. Such processes include conducting due diligence assessments for all vendors, regularly reviewing vendor security practices, and including cybersecurity performance metrics in our vendor contracts to ensure they comply with our security requirements.
We are a holding company and our operations are conducted substantially in China by our China subsidiary. Our PRC subsidiary, the main operating entity of ours, has implemented comprehensive internal policies and measures on protection of cyber security, data privacy and personal information to make sure its compliance with relevant PRC laws and regulations. The main internal policies and measures are as follows:
In compliance with PRC laws and regulations with respect to data security in all material aspects, we have implemented comprehensive internal policies and measures on protection of cyber security, data privacy and personal information as listed above.
In addition, while we take various measures to comply with all applicable data privacy and protection laws and regulations, there is no guarantee that our current security measures and those of our third-party service providers may always be adequate for the protection of our customer, employee or company data; and like all companies, we have experienced data incidents from time to time. In addition, given the size of our customer base and the types and volume of personal data on our system, we may be a particularly attractive target for computer hackers, foreign governments or cyber terrorists. Unauthorized access to our proprietary internal and customer data may be obtained through break-ins, sabotage, breach of our secure network by an unauthorized party, computer viruses, computer denial-of-service attacks, employee theft or misuse, breach of the security of the networks of our third-party service providers, or other misconduct. Because the techniques used by computer programmers who may attempt to penetrate and sabotage our proprietary internal and customer data change frequently and may not be recognized until launched against a target, we may be unable to anticipate these techniques. Unauthorized access to our proprietary internal and customer data may also be obtained through inadequate use of security controls. Any of such incidents may harm our reputation and adversely affect our business and results of operations. In addition, we may be subject to negative publicity about our security and privacy policies, systems, or measurements from time to time.
Any failure to prevent or mitigate security breaches, cyber-attacks or other unauthorized access to our systems or disclosure of our customers’ data, including their personal information, could result in loss or misuse of such data, interruptions to our service system, diminished customer experience, loss of customer confidence and trust, impairment of our technology infrastructure, and harm our reputation and business, resulting in significant legal and financial exposure and potential lawsuits and could cause the value of such securities to significantly decline or be worthless. In addition, any violation of the provisions and requirements under relevant laws and regulations with respect to cyber security, data security and personal information protection may subject us to rectifications, warnings, fines, confiscation of illegal gains, suspension of the related business, revocation of licenses, cancellation of qualifications being entered into the relevant credit record or even criminal liabilities.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Cybersecurity Governance
Our board of directors currently does not oversee our cybersecurity program and had delegated the oversight to our PRC subsidiary which established its Information Security Committee headed by our CEO, Mr. Guolin Tao to be the head of the committee. The Information Security Committee meets quarterly to discuss cybersecurity risks and effectiveness and will provide the board of directors occasional updates on the effectiveness of our cybersecurity program.
Mr. Guolin Tao will monitor the engineers responsible for the cybersecurity program to monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents. Such engineers will keep Mr. Guolin Tao informed of relevant developments related to cybersecurity. Mr. Tao brings more than 20 years of professional experience in business consultation, operations, and management, with a focus on the marketing industry.
In addition, Mr. Tao graduated with a Bachelor of Science degree from Beijing Institute of Technology and holds an MBA from Beijing University of Posts and Telecommunications. This combination of education in computer science and business management allows Mr. Tao to oversee our cybersecurity governance.
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Our board of directors currently does not oversee our cybersecurity program and had delegated the oversight to our PRC subsidiary which established its Information Security Committee headed by our CEO, Mr. Guolin Tao to be the head of the committee.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef