|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Jan. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
As part of our overall enterprise risk management program, we maintain a robust cybersecurity risk management program. The cross-functional group responsible for the cybersecurity risk management program includes members of our information security, data privacy and product security personnel, including members of our senior management team. Our cybersecurity program provides a foundation for identifying, monitoring, evaluating, and responding to cybersecurity threats and incidents, including those associated with our use of
software, applications, services, and cloud infrastructure developed or provided by third-party vendors and service providers. This framework includes steps for identifying the source of a cybersecurity threat or incident, including whether such cybersecurity threat or incident is associated with a third-party vendor or service provider, assessing the severity and overall risk of a cybersecurity threat or incident, implementing cybersecurity countermeasures and mitigation or remediation strategies, and informing the relevant members of our senior management team, which informs the Audit Committee and our Board of Directors of material cybersecurity threats and incidents.
We engage third parties, including vendors and other external service providers, to support our cybersecurity and data privacy processes. For example, we regularly engage independent third parties for penetration testing and evaluation of our various security compliance standards. We also conduct internal assessments of our cybersecurity risk management program. We review and update our cybersecurity policies, standards and procedures as needed, to account for changes in the threat and operational landscapes, as well as in response to legal and regulatory developments. Our team has established a continuous improvement process through which we regularly update our risk register against the evolving capabilities of adversaries and incorporate findings from internal and external testing. Further, we require mandatory training for all employees and contractors on our cybersecurity and privacy policies. We also have processes to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers. To that end, we maintain a comprehensive, risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems. In addition, we perform diligence on our vendors and prospective vendors regarding their cybersecurity posture. Although we have continued to invest in our diligence, onboarding, and monitoring capabilities over our critical third parties, including our third-party vendors and service providers, our control over the security posture of our critical third parties is limited, and there can be no assurance that we can prevent or mitigate the risk of any compromise or failure in the information assets owned or controlled by such third parties.
A cross-functional incident response team, comprised of representatives from information security, information technology, privacy and legal, is responsible for the monitoring and disposition of potential occurrences such as data breaches, intrusions, and other security incidents and implementing our detailed incident response plan. Our incident response plan includes processes and procedures for assessing potential internal and external threats, activation and notification, and post-incident recovery designed to safeguard the confidentiality, availability, and integrity of our information assets.
In fiscal 2025, and through the filing of this Annual Report on Form 10-K, cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected our business strategy, operating results, and/or financial condition. If we were to experience a material cybersecurity incident in the future, such an incident could potentially have a material effect, including on our business strategy, operating results, or financial condition. For more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see Part I, Item 1A, “Risk Factors” in this Annual Report on Form 10-K.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
As part of our overall enterprise risk management program, we maintain a robust cybersecurity risk management program. The cross-functional group responsible for the cybersecurity risk management program includes members of our information security, data privacy and product security personnel, including members of our senior management team. Our cybersecurity program provides a foundation for identifying, monitoring, evaluating, and responding to cybersecurity threats and incidents, including those associated with our use of
software, applications, services, and cloud infrastructure developed or provided by third-party vendors and service providers. This framework includes steps for identifying the source of a cybersecurity threat or incident, including whether such cybersecurity threat or incident is associated with a third-party vendor or service provider, assessing the severity and overall risk of a cybersecurity threat or incident, implementing cybersecurity countermeasures and mitigation or remediation strategies, and informing the relevant members of our senior management team, which informs the Audit Committee and our Board of Directors of material cybersecurity threats and incidents.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our Board of Directors has oversight responsibility for our overall enterprise risk management, and cybersecurity risk management in particular is regularly reviewed and overseen by our Audit Committee. The Audit Committee provides oversight and reviews management policies, processes, and procedures designed to identify, monitor, evaluate, and respond to cybersecurity risks to which the company is exposed. Management regularly reports to the Audit Committee regarding its process and procedures to mitigate or remediate cybersecurity risks, threats and incidents, along with monitoring activities of the cybersecurity team.
Our Audit Committee provides oversight of our cybersecurity program and receives quarterly cybersecurity updates from our Chief Information Security Officer (CISO) through written reports and presentations. Our CISO has over 20 years of experience in cybersecurity, and has held senior leadership positions at publicly traded companies in the technology industry, bringing extensive expertise in managing cybersecurity risks. The CISO’s leadership team consists of seasoned information security professionals with experience at globally recognized organizations, ensuring a robust and comprehensive approach to cybersecurity oversight.
Management is responsible for day-to-day risk management activities, including identifying and assessing cybersecurity risks, establishing processes to ensure that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures, and maintaining cybersecurity programs. Our cybersecurity programs are under the direction of our CISO, who is a member of our executive management team and closely coordinates as needed with other senior management personnel including the President of Product, Technology, and Operations and the Chief Legal Officer, who collectively possess significant experience in evaluating, managing and mitigating security and other risks, including cybersecurity risks.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Board of Directors has oversight responsibility for our overall enterprise risk management, and cybersecurity risk management in particular is regularly reviewed and overseen by our Audit Committee.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Management is responsible for day-to-day risk management activities, including identifying and assessing cybersecurity risks, establishing processes to ensure that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures, and maintaining cybersecurity programs.
|Cybersecurity Risk Role of Management [Text Block]
|
As part of our overall enterprise risk management program, we maintain a robust cybersecurity risk management program. The cross-functional group responsible for the cybersecurity risk management program includes members of our information security, data privacy and product security personnel, including members of our senior management team. Our cybersecurity program provides a foundation for identifying, monitoring, evaluating, and responding to cybersecurity threats and incidents, including those associated with our use of
software, applications, services, and cloud infrastructure developed or provided by third-party vendors and service providers. This framework includes steps for identifying the source of a cybersecurity threat or incident, including whether such cybersecurity threat or incident is associated with a third-party vendor or service provider, assessing the severity and overall risk of a cybersecurity threat or incident, implementing cybersecurity countermeasures and mitigation or remediation strategies, and informing the relevant members of our senior management team, which informs the Audit Committee and our Board of Directors of material cybersecurity threats and incidents.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Audit Committee provides oversight of our cybersecurity program and receives quarterly cybersecurity updates from our Chief Information Security Officer (CISO) through written reports and presentations. Our CISO has over 20 years of experience in cybersecurity, and has held senior leadership positions at publicly traded companies in the technology industry, bringing extensive expertise in managing cybersecurity risks. The CISO’s leadership team consists of seasoned information security professionals with experience at globally recognized organizations, ensuring a robust and comprehensive approach to cybersecurity oversight.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our CISO has over 20 years of experience in cybersecurity, and has held senior leadership positions at publicly traded companies in the technology industry, bringing extensive expertise in managing cybersecurity risks. The CISO’s leadership team consists of seasoned information security professionals with experience at globally recognized organizations, ensuring a robust and comprehensive approach to cybersecurity oversight.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
Management is responsible for day-to-day risk management activities, including identifying and assessing cybersecurity risks, establishing processes to ensure that potential cybersecurity risk exposures are monitored, implementing appropriate mitigation or remediation measures, and maintaining cybersecurity programs. Our cybersecurity programs are under the direction of our CISO, who is a member of our executive management team and closely coordinates as needed with other senior management personnel including the President of Product, Technology, and Operations and the Chief Legal Officer, who collectively possess significant experience in evaluating, managing and mitigating security and other risks, including cybersecurity risks.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef