|
Cybersecurity
|12 Months Ended
Sep. 30, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity.
Risk Management and Strategy
The protection of our clients’ data, our brand, and our systems is of utmost importance. We are subject to governmental regulation and other legal obligations, particularly related to privacy, data protection and information security. We have implemented comprehensive cybersecurity and data privacy programs, fostering a culture of awareness across all employee groups and systems. In 2025, we achieved SOC2 Type 2 certification, reflecting our commitment to supporting our clients by aligning our controls and processes with the System
and Organization Controls (SOC) compliance framework established by the American Institute of Certified Public Accountants (AICPA). This achievement builds on our previous SOC2 Type 1 certification and complements our ongoing TX Ramp compliance.
Our process to assess, identify and manage material risks from cybersecurity threats include potential threats associated with third-party service providers, including cloud-based platforms. On an annual basis, we review the SOC2 (or equivalent) attestation of controls for material third-party service providers, coupled with monitoring industry notices and threat intelligence regarding potential vulnerabilities or threats targeting these third-party services.
We developed our cybersecurity program by integrating proactive training, vulnerability management, and system design with active threat defense mechanisms. Our marketplace services are protected by multiple layers of security including firewalls, endpoint protection, WAF and Bot mitigation. Our "defense in depth" approach to asset protection is backed by AI-powered threat detection and response systems and actively monitored 24/7 by a dedicated team of security professionals. We maintain a formal incident response plan, which is regularly tested and updated to ensure prompt detection, reporting, and mitigation of cybersecurity incidents.
In addition, we undertake integrated planning activities to support business continuity and operational resiliency. We assess our program's effectiveness through various exercises, including active Disaster Recovery production environment tests, tabletop exercises, continuous vulnerability tests, and annual penetration testing. We conduct company-wide mandatory cybersecurity training as well as periodic employee education exercises, such as phishing simulation email campaigns designed to emulate real-world attacks.
We view cybersecurity protection and data privacy as a shared responsibility in which all employees are active participants. Each employee undergoes annual cybersecurity training with supplemental training disseminated throughout the year. This continual education helps promote a culture that understands the critical role cybersecurity and data privacy play in protecting our clients' assets. Furthermore, our computing environments, products, and services are reviewed by our internal security team and our controls are tested regularly by independent third-party assessors as part of our annual SOC2 and SOX re-certifications.
Cybersecurity Governance
Board and Committee Oversight. Our Board of Directors is responsible for oversight of the Company's cyber risk management program, including risk identification, mitigation strategy and efforts, and resources and receives quarterly updates on cybersecurity risks and mitigation efforts from management, including our Chief Technology Officer (CTO). The Audit Committee of the Board of Directors is responsible for reviewing the Company's financial reporting of cybersecurity risks and incidents in accordance with SEC rules. We will continue to invest in our security infrastructure to ensure it meets or exceeds industry standards for cybersecurity and employs dedicated resources to protect our systems.
Management's Role. Our internal security team in conjunction with the Chief Technology Officer (CTO) reviews current risks with a cross-functional leadership committee on a quarterly basis.
We are not currently aware of risks from known cybersecurity threats that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. For additional information regarding cybersecurity risks, see the risk factor in Part I, Item 1A. Risk Factors captioned: "We are required to maintain the privacy and security of personal and business information amidst multiplying threat landscapes and in compliance with privacy and data protection regulations globally. Failure to do so could damage our business, including our reputation with sellers, buyers, and employees, cause us to incur substantial additional costs, and make us subject to litigation and regulatory action."
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
In addition, we undertake integrated planning activities to support business continuity and operational resiliency. We assess our program's effectiveness through various exercises, including active Disaster Recovery production environment tests, tabletop exercises, continuous vulnerability tests, and annual penetration testing. We conduct company-wide mandatory cybersecurity training as well as periodic employee education exercises, such as phishing simulation email campaigns designed to emulate real-world attacks.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Board and Committee Oversight. Our Board of Directors is responsible for oversight of the Company's cyber risk management program, including risk identification, mitigation strategy and efforts, and resources and receives quarterly updates on cybersecurity risks and mitigation efforts from management, including our Chief Technology Officer (CTO). The Audit Committee of the Board of Directors is responsible for reviewing the Company's financial reporting of cybersecurity risks and incidents in accordance with SEC rules. We will continue to invest in our security infrastructure to ensure it meets or exceeds industry standards for cybersecurity and employs dedicated resources to protect our systems.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors is responsible for oversight of the Company's cyber risk management program, including risk identification, mitigation strategy and efforts, and resources and receives quarterly updates on cybersecurity risks and mitigation efforts from management, including our Chief Technology Officer (CTO). The Audit Committee of the Board of Directors is responsible for reviewing the Company's financial reporting of cybersecurity risks and incidents in accordance with SEC rules.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors is responsible for oversight of the Company's cyber risk management program, including risk identification, mitigation strategy and efforts, and resources and receives quarterly updates on cybersecurity risks and mitigation efforts from management, including our Chief Technology Officer (CTO).
|Cybersecurity Risk Role of Management [Text Block]
|
Management's Role. Our internal security team in conjunction with the Chief Technology Officer (CTO) reviews current risks with a cross-functional leadership committee on a quarterly basis.
We are not currently aware of risks from known cybersecurity threats that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. For additional information regarding cybersecurity risks, see the risk factor in Part I, Item 1A. Risk Factors captioned: "We are required to maintain the privacy and security of personal and business information amidst multiplying threat landscapes and in compliance with privacy and data protection regulations globally. Failure to do so could damage our business, including our reputation with sellers, buyers, and employees, cause us to incur substantial additional costs, and make us subject to litigation and regulatory action."
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Audit Committee of the Board of Directors is responsible for reviewing the Company's financial reporting of cybersecurity risks and incidents in accordance with SEC rules. We will continue to invest in our security infrastructure to ensure it meets or exceeds industry standards for cybersecurity and employs dedicated resources to protect our systems.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our internal security team in conjunction with the Chief Technology Officer (CTO) reviews current risks with a cross-functional leadership committee on a quarterly basis.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef