XML 79 R11.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk Management and StrategyThe Company maintains a multi-layered cybersecurity risk management framework designed to identify, assess, and mitigate cybersecurity risks across its systems and operations. This framework includes continuous system monitoring, role-based access controls, and regular training for new and existing employees, on data protection and cybersecurity awareness.

 

The Company is certified under ISO/IEC 27001, the international standard for information security management systems, and undergoes annual audits and recertification by independent accredited certification bodies to ensure ongoing compliance with the standard and the effectiveness of its information security controls.

 

Oversight of cybersecurity risks is integrated into the Company’s enterprise risk management framework. The Company maintains a dedicated cybersecurity task force that includes key executive members overseeing the effort in monitoring cybersecurity threats, coordinating incident response activities, and escalating material cybersecurity risks to senior management and the Board of Directors, as appropriate. The Board of Directors receives updates regarding significant cybersecurity risks, incidents, and mitigation measures.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Oversight of cybersecurity risks is integrated into the Company’s enterprise risk management framework
Cybersecurity Risk Board of Directors Oversight [Text Block] GovernanceThe board of directors is ultimately responsible for overseeing the Company’s cybersecurity risk management and being informed on risks from cybersecurity threats. The audit committee periodically reviews our cybersecurity risks and controls with management and our external auditor (as appropriate).

 

At the management level, we have established a cyber security steering committee, which consists of two top executives, the general counsel, and is chaired by the head of the information security office. Our Director of Technology and Product Operations and Information Security Manager are responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s overall risk management strategy, and communicating key priorities to relevant personnel. Our cyber security steering committee reports to the board of directors on a periodic basis regarding its assessment, identification and management on material risks from cybersecurity threats happened in the ordinary course of our business operations. If a cybersecurity incident occurs, our information security office, together with relevant members of the internal security incident response team, will organize relevant personnel for internal assessment and, depending on the situation, may seek the opinions of external experts and/or legal advisors. If it is determined that the incident could potentially be a material cybersecurity event, the investigation and assessment results will be reported by the cyber security steering committee to the audit committee and/or the board of directors who will provide assistance on determining the relevant response measures and whether any disclosure is necessary. If such disclosure is determined to be necessary, the cyber security steering committee will prepare disclosure materials for review and approval by the board of directors before it is disseminated to the public.