Security Policy Overview

Last Updated: January 2026 | Version 1.0

SCOPE AND PURPOSE

This Security Policy describes the technical and organizational measures implemented by Valority Technologies Ltd. to protect information systems and Personal Data processed in connection with its website, services, and internal operations. This document is provided for transparency purposes and does not create contractual obligations unless expressly incorporated into a written agreement.

Valority Technologies Ltd. ("Valority", "Company" or "we") is committed to protecting Personal Data in accordance with applicable data protection laws, including the EU General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"), and other applicable privacy and security regulations (collectively, the "Data Protection Laws").

This information security policy outlines the Company's security, technical and organizational practices. As part of our data protection compliance process we have implemented technical, physical and administrative security measures to protect the Personal Data, including upholding standards of Cybersecurity and Infrastructure Security Agency and the national institute standards and technology and technology and the GDPR TOM requirements.

Security Frameworks

Valority's information security program is designed in alignment with recognized industry standards and best practices, including ISO/IEC 27001, SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, and GDPR Technical and Organizational Measures (Article 32).

Physical Access Control

Valority operates in a cloud-based environment and does not maintain on-premises data centers. Customer data is hosted with reputable cloud service providers selected by the Customer or by Valority, such as Amazon Web Services (AWS), Google Cloud Platform, or Microsoft Azure, each of which maintains industry-standard physical security controls.

Risk Management

Valority maintains a risk-based information security program, including periodic assessments to identify reasonably foreseeable internal and external risks to the confidentiality, integrity, and availability of information systems and Personal Data. Identified risks are evaluated and mitigated through appropriate administrative, technical, and organizational safeguards.

System Control

Access to the Company's database is highly restricted in order to ensure that solely the appropriate prior approved personnel can access the Company's Personal Data. Safeguards related to remote access and wireless computing capabilities are in implemented therein. Employee are required to comply with the Company's password policy when composing a password in order to allow strict access or use related to Personal Data all in accordance with position, and solely to the extent such access or use is required. There is constant monitoring of the access to the data and the passwords used to gain login access. The Company is using automated tools to identify non-human login attempts and rate-limiting login attempts to minimize the risk of a brute force attack.

Data Access Control

There are restrictions in place to ensure that the access to the Personal Data is restricted to employees which have a permission to access it. Any permission is granted by the Company's authorized personal. The Personal Data information shall not be accessed, modified, copied, used, transferred or deleted without specific authorization. The access to the Personal Data information, as well as any action performed involving the use of the Personal Data requires a password and user name, which is routinely changed, as well as blocked when applicable. Each employee is able to perform actions solely according to the permissions determined by the Company. Each access is logged and monitored, and any unauthorized access is automatically reported. Further, the Company has ongoing review of which employees' have authorizations, to assess whether access is still required. Company revokes access immediately upon termination of employment. Authorized individuals can solely access Personal Data that is established in their individual profiles.

Access to systems and data is granted based on the principle of least privilege and role-based access controls (RBAC), and is reviewed periodically.

Multi-factor authentication (MFA) is enforced for administrative access and privileged accounts where technically feasible.

Logging and Monitoring

Valority maintains centralized logging and monitoring mechanisms designed to detect unauthorized access, anomalous activity, and potential security incidents. Logs are retained for a limited period in accordance with operational and legal requirements.

Security Incident Response

Valority maintains an incident response process designed to detect, assess, contain, remediate, and document security incidents. Where required by applicable law or contractual obligation, Valority will notify affected customers or authorities of a confirmed Personal Data breach without undue delay.

Organizational and Operational Security

The Company invests a multitude of efforts and resources in order to ensure compliance with the Company's security practices, as well as continuously provides employees on-going training and periodic updates regarding Company's security procedures. The Company strives to raise awareness to the risk involved in the processing of Personal Data. In addition, the Company implemented applicable safeguards for its hardware and software, including web content filtering, firewalls and anti-virus software ("Protection Measures") on applicable Company hardware, software or employee's computer, in order to protect against virus, worms, Trojan identifications or any other malicious software. The Protection Measures cannot be deactivated by any user other than the Company's cyber security officer and according to the Company's policies.

Transfer Control

Except for transfer data to our business partners, The Company does not transfer any Personal Data outside of the Company's cloud servers. All transfer of Personal Data between the client side and the Company's servers is protected using encryption and safeguards. The Company's servers are protected by industry standards. Furthermore, the destruction of Personal Data following termination of the engagement is included within the contract between the parties. In addition, to the extent applicable, the Company's business partners execute an applicable Data Processing Agreement, all in accordance with applicable laws.

Personal Data is encrypted in transit using industry-standard encryption protocols (such as TLS), and encrypted at rest where supported by the underlying infrastructure.

International Transfer

Where Personal Data is transferred outside of its originating jurisdiction, Valority relies on approved transfer mechanisms such as Standard Contractual Clauses and implements supplementary safeguards where required, in accordance with applicable data protection laws and regulatory guidance.

Application Security

Valority follows secure development lifecycle (SDLC) practices, including code reviews, dependency management, vulnerability scanning, and remediation of identified security issues. Common vulnerabilities such as those listed by OWASP are assessed and addressed as part of ongoing development and maintenance.

Data Retention

Personal Data is retained for as long as needed to provide the services or as required under applicable laws. Individuals may request data deletion; however, this request is not absolute and is limited, all as detailed in the Company Privacy Policy.

Data retention periods are defined in accordance with Valority's Privacy Policy and contractual obligations.

Personnel Security

All Valority employees and contractors are subject to confidentiality and data protection obligations and receive security awareness training. Access rights are revoked promptly upon termination of engagement. In addition, employees undergo a screening process applicable per regional law. In the event of a breach of an employee's obligation or non-compliance with the Company's policies, the Company includes repercussions to ensure compliance with the policies. In addition, prior to the Company's engagement with third party contractors, the Company reviews such third party's security policies, specifically their information data security policies to ensure it complies with the Company's standard for data security protection. Third party contractors may solely access the Personal Data as explicitly instructed by the Company.

Reporting a Security Issue

Valority is exerting considerable resources to ensure a secure code and infrastructure for all of its products. If you believe that you have found a security vulnerability in any of our products, please report it to us straight away via e-mail to privacy@valority.ai. Please be sure to include a brief description, detailed steps to reproduce and what might be the impact.

Responsible Disclosure Policy

We encourage responsible disclosure, and we promise to investigate all legitimate reports and fix any issues as soon as we can. We ask that during your research you make every effort to maintain the integrity of our any data you come across, avoiding violating the privacy of any person or degrading our offerings. Please provide Valority reasonable time to fix any vulnerability you find before you make it public. In return we promise to investigate reports promptly and not to take any legal action against you.

Reports submitted in good faith will not result in legal action, provided they comply with this Responsible Disclosure Policy.

No Guarantee

While Valority implements reasonable and appropriate security measures, no system can be completely secure. This Security Policy does not guarantee the prevention of all security incidents.