Consultiply's security practices. Incorporated into the Agreement by reference and updatable under Section 23. Applies to all Services; describes Consultiply's current program as of the date of the governing MSA.
Preamble
Consultiply maintains administrative, technical and physical safeguards designed to protect Client Data in its possession or control. The practices below describe Consultiply's current program. Consultiply will not materially degrade these practices during the term of an Order Form or SOW.
1. Governance
- Security ownership: a named principal (the Founder & CEO) owns Consultiply's security program and reviews it on a defined cadence.
- Written policies: Consultiply maintains written security, confidentiality and acceptable-use policies covering personnel and contractors.
- Review cadence: the program is reviewed at least annually and upon any material change to operations.
2. Personnel
- All employees and contractors are bound by written confidentiality and acceptable-use undertakings no less protective than the MSA.
- Access is revoked on role change or exit, on a defined checklist.
3. Access Control
- Least privilege: access to systems holding Client Data is limited to what each role requires.
- Multi-factor authentication is required on administrative and remote access to systems holding Client Data.
- Shared accounts: no shared accounts are used for administrative access; each person has named credentials.
4. Data Protection
- Encryption in transit: Client Data is transmitted only over encrypted connections (TLS).
- Credentials and secrets are stored in a managed credential store, not in documents, chat, or code.
- Client Data is logically separated from other clients' data.
5. Endpoint and Network
- Endpoint protection is maintained on devices used to deliver Services.
- Access and administrative activity logging is maintained on systems that store or process Client Data.
- Patching: operating systems and applications are kept current on a defined cadence.
6. AI Providers
- Categories of AI provider used: foundation-model providers and AI-platform providers, engaged on their business or enterprise terms.
- Contractual footing: each AI provider used in delivering Services is engaged on terms that exclude Client Data from that provider's model training, consistent with Section 29.2 of the MSA; Consultiply does not use a provider for work involving Client Data where such terms are unavailable.
7. Incident Response
- Consultiply maintains a written incident response plan and follows it when incidents occur.
- A security incident affecting Consultiply's systems is handled under the MSA's security provisions (Section 19 carve-out; this Exhibit).
- Consultiply shall notify Client without undue delay after becoming aware of a security incident that affects Client Data in Consultiply's possession or control.
8. Business Continuity
- Recovery objectives for a specific Deliverable, where agreed, are stated in the applicable SOW or service schedule. Absent such a statement, no recovery objective is represented.
9. Certifications and Diligence
- Consultiply does not currently hold a third-party security attestation such as SOC 2 or ISO 27001.
- Diligence path offered instead: a written security-posture summary is made available on reasonable written request, not more than once per calendar year, under a mutually agreeable non-disclosure agreement.
- Client is not entitled to conduct an on-site audit of Consultiply's systems, facilities or personnel.