LEGAL-004 Version 1.2 RC1
Privacy & Security

Security Policy

Describes the administrative, technical, organizational, operational, and governance safeguards supporting the security of the Portal Platform™ and related services.

Portal Platform™ Legal Suite LEGAL-004

Preamble

JHS Solutions LLC ("Company," "we," "our," or "us") recognizes that information security is fundamental to maintaining the trust of our customers, signers, enterprise organizations, business partners, and regulatory authorities.

This Security Policy describes the Company's security objectives, administrative safeguards, technical safeguards, operational safeguards, and governance principles for protecting the Portal Platform and the information entrusted to it.

This Security Policy applies to all current and future products, services, applications, communication systems, APIs, artificial intelligence services, enterprise offerings, and related technologies operated by the Company.

This Policy forms part of the Portal Platform Legal Suite™ and should be read together with:

LEGAL-001 — Master Terms of Service

LEGAL-002 — Privacy Policy

LEGAL-003 — Communications Policy

Record Retention Policy

AI Services Policy

Trust Center™ Policy

Electronic Signature Disclosure

Cookie Policy

other applicable legal documents.

ARTICLE I — Security Program, Scope and Security Principles

1.1 Purpose

The Company's security program is designed to protect:

confidentiality;

integrity;

availability;

authenticity;

accountability;

resilience

of Platform services and information processed through the Platform.

The Company seeks to reduce cybersecurity risk through continuous improvement, responsible governance, operational discipline, and commercially reasonable security practices.

1.2 Scope

This Policy applies to:

employees;

contractors;

administrators;

developers;

enterprise administrators;

vendors;

cloud providers;

third-party service providers;

APIs;

artificial intelligence services;

mobile applications;

future Platform technologies.

1.3 Security Objectives

The Company's security objectives include:

protecting customer information;

protecting signer information;

protecting enterprise information;

protecting communications;

protecting authentication systems;

protecting payment-related information;

protecting document integrity;

maintaining Platform availability;

detecting unauthorized activity;

reducing fraud;

supporting legal compliance;

supporting business continuity.

1.4 Security Principles

The Company seeks to operate in accordance with the following security principles:

defense in depth;

least privilege;

need-to-know access;

secure-by-design;

privacy-by-design;

continuous monitoring;

continuous improvement;

responsible innovation;

risk-based decision making;

operational resilience.

1.5 Security Governance

The Company's leadership is responsible for establishing, reviewing, maintaining, and improving the Company's information security program.

Security governance includes:

policy development;

operational oversight;

vendor management;

security awareness;

incident response;

vulnerability management;

business continuity planning;

disaster recovery planning;

legal compliance;

periodic policy review.

1.6 Continuous Improvement

Cybersecurity threats evolve continuously.

Accordingly, the Company continuously evaluates:

emerging threats;

software vulnerabilities;

operational risks;

regulatory developments;

technological improvements;

customer expectations;

artificial intelligence risks;

communication risks;

cloud infrastructure risks.

Security controls may be modified, expanded, replaced, or enhanced without prior notice where reasonably necessary to maintain Platform security.

1.7 Security Culture

The Company recognizes that cybersecurity depends upon people, processes, and technology.

Accordingly, security awareness, operational discipline, responsible software development, and continuous improvement remain fundamental principles of the Company's security program.

1.8 Future Security Maturity

As the Platform grows, the Company intends to mature its security program through appropriate governance, independent assessments, documented operational procedures, enhanced monitoring, and other commercially reasonable improvements.

Where appropriate, the Company may pursue independent security attestations, certifications, audits, or assessments. References to future objectives do not constitute representations that any specific certification or audit has been completed unless expressly stated in writing.

ARTICLE II — Administrative Safeguards, Identity Management and Access Controls

2.1 Administrative Security Program

The Company maintains administrative safeguards intended to support the secure operation of the Platform and reduce cybersecurity risk.

Administrative safeguards may include:

written policies;

operational procedures;

personnel responsibilities;

security awareness;

risk assessments;

vendor oversight;

incident response planning;

business continuity planning;

disaster recovery planning;

change management;

periodic policy review.

These safeguards are reviewed and updated as technology, business operations, and legal requirements evolve.

2.2 Identity Management

The Company maintains identity management practices designed to ensure that access to Platform resources is appropriately authenticated and authorized.

Identity management processes may include:

account creation;

identity verification where applicable;

authentication;

authorization;

credential management;

account recovery;

account suspension;

account termination;

privilege review;

future identity technologies.

Identity requirements may vary depending upon account type, subscription level, security risk, or applicable law.

2.3 Authentication

Users must authenticate before accessing protected Platform resources.

Authentication methods may include:

usernames;

passwords;

authenticator applications;

one-time verification codes;

email verification;

SMS verification where supported;

security keys;

biometric authentication where legally authorized;

enterprise identity providers;

future authentication technologies.

The Company reserves the right to modify authentication requirements to maintain Platform security.

2.4 Multi-Factor Authentication (MFA)

Where available, Multi-Factor Authentication ("MFA") provides an additional layer of account protection.

The Company may require MFA for:

Administrator Accounts;

Enterprise Organizations;

Workspace Owners;

billing administration;

payment changes;

API administration;

sensitive account modifications;

elevated privileges;

security-sensitive workflows;

future Platform services.

Supported authentication methods may evolve over time as security standards improve.

2.5 Password Security

Users are responsible for maintaining the confidentiality of their authentication credentials.

Users shall:

create reasonably strong passwords;

avoid sharing credentials;

promptly update compromised passwords;

protect recovery codes;

secure authentication devices;

report suspected credential compromise without unreasonable delay.

The Company may establish password complexity requirements, expiration policies, reuse restrictions, or other credential management standards as part of its security program.

Passwords are stored using secure cryptographic methods and are not retained in plain text.

2.6 Role-Based Access Control (RBAC)

The Platform utilizes Role-Based Access Control ("RBAC") to limit access according to a User's assigned responsibilities.

Roles may include:

Customer;

Signer;

Administrator;

Enterprise Administrator;

Team Member;

Developer;

API User;

Support Personnel;

Future Platform Roles.

Users receive only the permissions reasonably necessary to perform their authorized functions.

2.7 Least Privilege

The Company applies the principle of least privilege whenever reasonably practicable.

Access is granted based upon:

operational necessity;

assigned responsibilities;

business requirements;

security considerations;

contractual obligations;

applicable law.

Administrative privileges are granted only to authorized individuals with legitimate operational responsibilities.

2.8 Session Security

To reduce the risk of unauthorized access, the Platform may:

automatically expire inactive sessions;

invalidate expired authentication tokens;

require re-authentication;

revoke compromised sessions;

terminate suspicious sessions;

invalidate password reset tokens;

expire invitation links;

implement future session protection technologies.

Session duration may vary depending upon security requirements and Platform functionality.

2.9 Administrative Accounts

Administrative Accounts possess elevated privileges and therefore require additional safeguards.

Administrative safeguards may include:

enhanced authentication;

Multi-Factor Authentication;

activity logging;

privilege reviews;

restricted administrative access;

periodic credential review;

separation of duties where appropriate.

Administrative actions may be recorded within Platform audit logs.

2.10 Personnel Security

The Company seeks to ensure that personnel with access to Platform systems understand their security responsibilities.

Personnel security practices may include:

role-based training;

security awareness;

confidentiality obligations;

acceptable use requirements;

incident reporting procedures;

access reviews;

termination procedures;

future personnel security practices.

The scope of these measures depends upon the individual's responsibilities.

2.11 Vendor Security

The Company may engage third-party service providers to support Platform operations.

Where appropriate, vendors may be evaluated based on factors including:

security capabilities;

confidentiality commitments;

operational reliability;

compliance obligations;

contractual protections;

incident response cooperation;

business continuity capabilities.

The Company reserves the right to replace or discontinue vendors as business or security needs evolve.

2.12 Change Management

To promote Platform stability and security, significant operational changes may be managed through documented change management practices.

Change management activities may include:

planning;

testing;

approval;

deployment;

validation;

rollback planning where appropriate;

documentation;

post-implementation review.

Emergency changes may follow expedited procedures where necessary to address security incidents or operational risks.

2.13 Security Awareness

The Company recognizes that cybersecurity depends upon informed personnel.

Accordingly, security awareness may include:

phishing awareness;

password security;

incident reporting;

secure communication practices;

data protection;

authentication security;

artificial intelligence awareness;

social engineering awareness;

future security education initiatives.

2.14 Administrative Reviews

The Company may periodically review:

administrative privileges;

user roles;

authentication practices;

access permissions;

vendor relationships;

security procedures;

operational controls;

governance processes.

Reviews are intended to support continuous improvement and risk reduction.

2.15 Continuous Improvement

Administrative safeguards will continue to evolve as:

cybersecurity threats change;

technologies advance;

Platform services expand;

legal requirements develop;

customer expectations increase;

operational experience grows.

The Company reserves the right to improve, replace, or expand administrative controls whenever reasonably necessary to maintain Platform security.

ARTICLE III — Technical Safeguards, Security Operations and Platform Protection

3.1 Technical Security Program

The Company maintains technical safeguards intended to protect the confidentiality, integrity, availability, and resilience of the Platform.

Technical safeguards may include:

authentication technologies;

encryption;

secure communications;

access controls;

network protections;

audit logging;

monitoring;

vulnerability management;

incident detection;

software security;

artificial intelligence-assisted security;

future cybersecurity technologies.

The Company continuously evaluates these safeguards as technology and cybersecurity risks evolve.

3.2 Encryption

The Platform may provide both standard protected workflows and expressly designated Customer-Controlled Encryption workflows. Encryption at rest using infrastructure-controlled keys is not represented as Zero-Knowledge or No-View encryption.

A workflow is a "Zero-Knowledge Enabled Service" or "No-View Service" only when the applicable workspace, order form, or written agreement expressly identifies it as such and the supporting technical controls have been activated.

For an activated Zero-Knowledge Enabled Service, supported document content is encrypted on the authorized User's device before server storage. The Company stores encrypted content and encrypted key envelopes but is not intended to possess the content-decryption key needed to read the protected document.

When activated, supported document content must use authenticated encryption with a unique per-document key. The current design standard is AES-256-GCM, or a documented successor providing equivalent or stronger protection, together with separately encrypted key envelopes for authorized participants and Customer-controlled organizational recovery.

Until a workflow is expressly identified as Zero-Knowledge Enabled, the Company may process document content as reasonably necessary to provide document preparation, signature placement, completion, verification, safety screening, support, or other requested functionality, subject to access controls and this Policy.

Encryption may be used for:

communications;

authentication;

stored information;

backup systems;

API communications;

administrative access;

future Platform functionality.

The Company may update encryption methods as industry standards evolve.

3.3 Secure Communications

Communications transmitted through the Platform may utilize secure communication protocols intended to reduce the risk of unauthorized interception or alteration.

Such protections may include:

encrypted web sessions;

authenticated communications;

secure API connections;

integrity validation;

secure messaging technologies;

future communication protections.

No communication network can guarantee absolute confidentiality or uninterrupted availability.

3.4 Network Security

The Company maintains network security measures designed to protect Platform infrastructure.

Network safeguards may include:

firewalls;

network segmentation;

traffic monitoring;

intrusion detection;

intrusion prevention;

denial-of-service mitigation;

secure routing;

rate limiting;

future network security technologies.

Network protections are periodically evaluated and may be modified as operational needs change.

3.5 Secure Software Development

The Company seeks to incorporate security considerations throughout the software development lifecycle.

Development practices may include:

secure coding practices;

code review;

software testing;

defect management;

dependency review;

change management;

release validation;

future secure development practices.

Security improvements may be introduced throughout the development lifecycle.

3.6 Application Security

The Platform is designed with security considerations intended to reduce operational risk.

Application security measures may include:

authentication controls;

authorization controls;

input validation;

session management;

audit logging;

request validation;

access restrictions;

error handling;

future application security technologies.

3.7 API Security

Where APIs are provided, the Company may implement security controls including:

API authentication;

authorization;

credential management;

rate limiting;

request validation;

audit logging;

token management;

monitoring;

future API protections.

API users remain responsible for protecting their credentials.

3.8 Artificial Intelligence Security

Where Artificial Intelligence ("AI") Services are offered, the Company may implement safeguards intended to reduce operational and security risks associated with AI systems.

Such safeguards may include:

access controls;

usage monitoring;

prompt validation where appropriate;

abuse detection;

output review processes;

security monitoring;

future AI governance technologies.

The Company continuously evaluates AI-related risks as technologies evolve.

3.9 Vulnerability Management

The Company seeks to identify, evaluate, prioritize, and remediate security vulnerabilities using commercially reasonable practices.

Vulnerability management activities may include:

software updates;

security patches;

dependency reviews;

vulnerability scanning;

configuration reviews;

threat monitoring;

risk prioritization;

future vulnerability management processes.

The timing of remediation depends upon the nature and severity of the identified risk.

3.10 Security Testing

The Company may perform security testing to evaluate Platform security.

Testing activities may include:

internal testing;

vulnerability assessments;

configuration reviews;

software validation;

code analysis;

infrastructure reviews;

penetration testing performed internally or by qualified third parties where appropriate;

future security assessments.

The Company reserves the right to determine the frequency, scope, and methodology of such testing.

3.11 Logging and Audit

The Platform may generate security logs documenting operational and security events.

Logs may include:

authentication events;

administrative actions;

API activity;

document activity;

communication events;

system alerts;

configuration changes;

audit records;

future operational events.

Security logs support:

incident response;

fraud prevention;

troubleshooting;

compliance;

Platform integrity.

3.12 Monitoring

The Company may monitor Platform systems to support:

availability;

performance;

fraud detection;

intrusion detection;

abuse prevention;

security investigations;

operational reliability;

future Platform improvements.

Monitoring activities are conducted for legitimate operational and security purposes.

3.13 Incident Detection and Response

The Company maintains procedures intended to detect, investigate, contain, mitigate, and remediate security incidents.

Response activities may include:

event analysis;

containment;

forensic review where appropriate;

credential protection;

restoration of services;

coordination with service providers;

customer notification where required by law;

continuous improvement following significant incidents.

The Company's incident response procedures may evolve over time.

3.14 Business Continuity

The Company seeks to maintain operational resilience through business continuity planning.

Business continuity activities may include:

backup procedures;

recovery planning;

infrastructure redundancy where appropriate;

operational recovery processes;

communication planning;

future resilience improvements.

Business continuity planning is periodically reviewed and updated as operational needs evolve.

3.15 Disaster Recovery

The Company maintains disaster recovery planning intended to support restoration of critical Platform operations following significant operational disruptions.

Recovery procedures may include:

backup restoration;

infrastructure recovery;

communication restoration;

authentication restoration;

document recovery where available;

operational prioritization;

future disaster recovery enhancements.

Recovery objectives may vary depending upon the nature of the disruption.

3.16 Security Operations

The Company maintains ongoing security operations intended to support the secure administration of the Platform.

Security operations may include:

security monitoring;

vulnerability management;

threat assessment;

software maintenance;

infrastructure maintenance;

incident response;

access reviews;

vendor coordination;

operational reporting;

future security operations.

Security operations evolve continuously in response to changing technologies and cybersecurity threats.

3.17 Future Security Technologies

The Company may implement future security technologies designed to enhance Platform protection.

Future technologies may include:

advanced authentication;

hardware security technologies;

behavioral analytics;

artificial intelligence-assisted detection;

automated response technologies;

advanced encryption methods;

quantum-resistant cryptographic technologies as appropriate;

future industry security innovations.

References to current technologies include reasonable technological successors unless the context requires otherwise.

3.18 Document Safety Gateway

The Company may operate a Document Safety Gateway designed to evaluate supported documents before they enter signing, template, storage, video-signing, API, or future notarial workflows.

Security controls may include file-type validation, cryptographic hashing, malware inspection where available, PDF structural analysis, active-content detection, text-risk analysis, language-aware indicators, account and workflow risk signals, and approved third-party content-safety technologies.

For a Zero-Knowledge Enabled Service, content inspection must occur before encryption on the authorized User's device, through privacy-preserving controls, or after an express and auditable customer authorization. The Company does not reserve a standing decryption key merely to perform content inspection.

3.19 English, Spanish and Global Risk Detection

The Company may maintain multilingual security rules, including English and Spanish detection dictionaries, together with jurisdiction-specific indicators. Language detection and keyword matching are risk-reduction tools and do not independently establish illegality, fraud, classification status, or authenticity.

3.20 Quarantine and Fail-Closed Controls

When a document cannot safely proceed, the Platform may prevent creation of a signing request and move the affected file to restricted quarantine storage. Quarantined content may be isolated from normal customer, signer, and administrator interfaces and protected through more restrictive access controls.

Where a required security control is unavailable or a safety determination cannot be recorded reliably, the Platform may fail closed and decline the upload until the security control becomes available.

3.21 Restricted Human Review

Administrative safety review is intended to be risk-based and access-limited. Certain categories of suspected illegal or highly sensitive content may be handled without exposing the underlying file through ordinary browser interfaces. Review personnel must follow applicable Company procedures and legal requirements.

Human review of plaintext content protected by a Zero-Knowledge Enabled Service is prohibited unless an authorized Customer deliberately provides a limited, purpose-specific and auditable decryption grant. Such a grant does not create standing administrative access.

3.22 Document Hash Decisions

The Platform may use a cryptographic document hash to associate an exact file with a prior security decision. An approved exact-file hash may be permitted on a subsequent upload, while a rejected exact-file hash may be blocked, subject to applicable law and later authorized review.

3.23 No Guarantee and No Legal Determination

Security screening reduces risk but cannot identify every malicious, fraudulent, illegal, classified, restricted, or explicit document. A CLEAR result does not certify legality, authenticity, authority, security classification, or legal enforceability. Users remain responsible for lawful possession, authority, content, recipients, and use.

3.24 Customer-Controlled Keys and Recovery

Each supported Zero-Knowledge document is intended to use a unique content-encryption key. Access is provided through separately encrypted key envelopes issued only to authorized participants and, where selected, to a Customer-controlled organizational recovery key.

The Company will not maintain a universal document master key for Zero-Knowledge Enabled Services. Enterprise recovery material must be controlled by the Customer organization and not by ordinary Company administrators.

If every authorized key and Customer-controlled recovery method is lost, the Company may be technically unable to restore plaintext document content. Customers are responsible for maintaining authorized recovery methods and continuity procedures appropriate to their legal and regulatory obligations.

3.25 Administrative and Support Access

Company administrators, developers, contractors, and support personnel are not authorized to browse customer document content for curiosity, convenience, product development, advertising, or unrelated purposes.

For Zero-Knowledge Enabled Services, ordinary administrative tools must expose only operational metadata, encrypted content, integrity values, and other information needed to operate the service without revealing plaintext document content.

Where customer support requires plaintext review, access must be initiated or expressly approved by an authorized Customer, limited to the stated support purpose, time-limited where technically supported, and recorded in an audit log. The Company may decline support actions that would require bypassing Customer-Controlled Encryption.

3.26 Temporary Files, Backups and Derived Content

Zero-Knowledge protections apply to supported originals, completed documents, rendered copies, previews, thumbnails, temporary processing files, and backups. The Platform must not silently create a persistent plaintext copy outside the authorized User's device.

Operational systems may retain non-content metadata and encrypted recovery copies as described in the Privacy Policy and applicable retention schedules.

3.27 Metadata and Audit Evidence

Zero-Knowledge encryption protects document content; it does not necessarily conceal account identifiers, participant routing information, timestamps, IP addresses, device information, consent events, document size, key-envelope metadata, hashes, billing records, audit events, or other operational metadata.

The Company may process such metadata to authenticate Users, deliver invitations, operate signing workflows, prevent fraud, maintain security, generate audit evidence, comply with law, and provide Trust Center verification.

3.28 Regulated Data Configurations

Health information, nonpublic financial information, and other regulated data may be used only through an eligible service configuration expressly approved for that purpose and subject to any required written agreement.

A subscription, encryption feature, or marketing description does not by itself establish compliance with HIPAA, the Gramm-Leach-Bliley Act, an institution's regulator, or any other legal framework. Healthcare use may require an executed Business Associate Agreement. Financial-sector use may require service-provider terms, risk allocation, audit rights, incident obligations, and additional Customer controls.

Applicable financial-sector safeguards may include the FTC Safeguards Rule, regulator or supervisory requirements, and contractual controls imposed by the Customer. Puerto Rico institutions remain responsible for determining whether OCIF, COSSEC, NCUA, or another authority governs the particular institution and transaction.

Customers must not upload regulated information to a trial, standard plan, or feature that has not been expressly approved for the applicable regulated use.

3.29 Truthful Security Representations

The Company will describe a service as Zero-Knowledge, No-View, HIPAA-ready, GLBA-ready, certified, audited, or independently assessed only when the specific statement is current, documented, applicable to the identified service, and not misleading.

Security and privacy statements must be supportable and consistent with applicable consumer-protection law, including Section 5 of the Federal Trade Commission Act. The Company also recognizes the strong protection for private and family life reflected in Article II, Section 8 of the Constitution of Puerto Rico; application of constitutional or statutory duties to a particular Customer or transaction remains a fact-specific legal determination.

No statement in this Policy represents that every Platform workflow currently provides Customer-Controlled Encryption or that any certification, attestation, or legal compliance determination has been completed.

ARTICLE IV — Security Governance, Incident Response, Compliance and General Provisions

4.1 Security Incident Response

The Company maintains procedures designed to identify, investigate, contain, mitigate, recover from, and document security incidents affecting the Platform.

Security incident response activities may include:

event identification;

incident classification;

containment measures;

forensic analysis where appropriate;

recovery activities;

root cause analysis;

corrective actions;

customer notification where required by applicable law;

coordination with service providers;

coordination with governmental authorities where legally required.

Incident response procedures are periodically reviewed and updated to reflect changes in technology, threats, and business operations.

4.2 Notification of Security Incidents

Where required by applicable law, the Company will provide notice of confirmed security incidents involving personal information or other protected information.

Notification may be provided through:

email;

authenticated Platform notifications;

Dispatch Center™ communications;

website notices where appropriate;

other reasonable electronic methods permitted by law.

The timing, content, and recipients of notifications will depend upon:

applicable law;

the nature of the incident;

the information involved;

operational considerations;

recommendations of law enforcement where applicable.

4.3 Vendor Security Management

The Company may engage third-party vendors to support Platform operations.

Vendor oversight may include evaluation of:

security capabilities;

confidentiality commitments;

operational reliability;

incident response capabilities;

privacy practices;

contractual obligations;

business continuity planning;

disaster recovery capabilities.

Where a vendor will create, receive, maintain, or transmit regulated information, vendor onboarding may also require a Business Associate Agreement, data processing terms, financial-institution service-provider provisions, or other written safeguards appropriate to the Customer's regulated use.

The Company reserves the right to suspend, replace, or discontinue vendors that no longer meet operational or security expectations.

4.4 Cloud Infrastructure

The Platform may utilize cloud infrastructure operated by qualified service providers.

Cloud services may support:

hosting;

storage;

computing resources;

communications;

backup services;

disaster recovery;

artificial intelligence services;

future Platform technologies.

While the Company selects providers carefully, the operation of cloud infrastructure remains subject to the independent practices and availability of those providers.

4.5 Independent Security Assessments

As the Platform matures, the Company may engage qualified independent organizations to perform:

security assessments;

penetration testing;

vulnerability assessments;

operational reviews;

privacy reviews;

infrastructure evaluations;

compliance assessments;

future independent reviews.

The Company reserves discretion regarding the frequency, scope, and publication of assessment results.

4.6 Future Certifications and Attestations

The Company may pursue recognized security certifications, attestations, or compliance programs as appropriate for its business operations.

These may include, where applicable:

SOC examinations;

ISO standards;

privacy frameworks;

industry-specific compliance programs;

independent security attestations;

future regulatory certifications.

References to these frameworks reflect potential future objectives only and shall not be interpreted as representations that any certification or attestation has been achieved unless expressly stated in writing.

4.7 Regulatory Cooperation

The Company may cooperate with:

law enforcement agencies;

regulatory authorities;

courts;

governmental entities;

auditors;

authorized investigators;

where required or permitted by applicable law.

Such cooperation will be conducted in accordance with applicable legal requirements and the Company's legal obligations.

For Customer-Controlled Encryption, the Company may be able to produce only encrypted content and the operational metadata in its possession. The Company will not create or retain a hidden decryption capability for the purpose of responding to legal process.

4.8 User Security Responsibilities

Security is a shared responsibility.

Users are responsible for:

protecting passwords;

enabling Multi-Factor Authentication where available;

maintaining secure devices;

promptly reporting suspected unauthorized access;

maintaining current contact information;

protecting authentication devices;

using the Platform responsibly;

following published security guidance.

Users remain responsible for the security of systems and devices under their own control.

4.9 Responsible Disclosure

The Company encourages responsible reporting of potential security vulnerabilities.

Security researchers and Users are encouraged to report suspected vulnerabilities through designated security channels.

The Company requests that reported vulnerabilities not be publicly disclosed until the Company has had a reasonable opportunity to investigate and address the issue.

Nothing in this section authorizes unauthorized access, testing, or exploitation of Platform systems.

4.10 Availability Disclaimer

Although the Company is committed to maintaining secure and reliable services, no information system can guarantee:

uninterrupted operation;

complete availability;

absolute security;

immunity from cyberattacks;

immunity from malware;

immunity from human error;

immunity from third-party failures;

immunity from force majeure events.

The Company continually works to improve Platform resilience but cannot eliminate every operational or cybersecurity risk.

4.11 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY SHALL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES ARISING FROM:

cybersecurity incidents;

unauthorized access;

service interruptions;

communication failures;

Internet outages;

cloud provider failures;

third-party service interruptions;

force majeure events;

events beyond the Company's reasonable control.

Nothing in this section limits liability that cannot lawfully be limited under applicable law.

4.12 Relationship to Other Policies

This Security Policy forms part of the Portal Platform Legal Suite™ and should be interpreted together with:

LEGAL-001 — Master Terms of Service;

LEGAL-002 — Privacy Policy;

LEGAL-003 — Communications Policy;

LEGAL-005 — AI Services Policy;

LEGAL-006 — Electronic Signature Disclosure & Consent;

LEGAL-007 — Cookie Policy;

LEGAL-008 — Acceptable Use Policy;

LEGAL-009 — Trust Center™ Policy;

LEGAL-010 — Record Retention Policy;

LEGAL-013 — Data Processing Addendum (where applicable); and

any additional policies adopted by the Company.

Where another policy governs a more specific security-related subject, that policy shall control with respect to that subject matter while this Security Policy continues to govern the Company's overall security program.

4.13 Amendments

The Company may revise this Security Policy periodically to reflect:

technological developments;

cybersecurity threats;

legal requirements;

operational improvements;

new Platform services;

organizational growth;

future products and services.

Material revisions will be communicated using reasonable electronic methods where required by applicable law.

Continued use of the Platform after the effective date of revised policies constitutes acceptance of the updated Security Policy to the extent permitted by applicable law.

4.14 Contact for Security Questions

Questions regarding this Security Policy or the Company's security practices may be submitted to:

JHS Solutions LLC

Email: support@esignare.com

Support is available for matters including:

Security Concerns

Vulnerability Reports

Unauthorized Access

Account Security

Security Incident Reports

Security Questions

General Customer Support

Additional contact methods and support resources may be published through the Portal Platform™ from time to time.

Where required by applicable law, the Company may designate a security or compliance representative to assist with security-related inquiries.

End of Document

LEGAL-004 — Security Policy

Version 1.2 RC1 · JHS Solutions LLC