Coldreach — Legal

Information Security Policy

Effective Date: October 10, 2025 · Last Reviewed: July 4, 2026 · Next Review: July 4, 2027

Purpose and Objectives

Protect the confidentiality, integrity and availability of Coldreach's information assets.

Define the baseline controls and risk management processes for information security across Coldreach's products, services and internal operations.

Ensure compliance with relevant legal, regulatory and contractual obligations.

Scope

• This policy applies to all Coldreach employees, contractors and third party service providers who access, store or process company data.

• It covers all systems, applications, infrastructure and data owned or managed by Coldreach, including customer data processed by our AI SDR platform.

Roles and Responsibilities

• CEO / CTO: Approves the information security program and allocates resources to enforce the policy.

• CTO: Implements security controls, monitors compliance and manages risk assessments.

• Engineering: Design, build and maintain systems following secure development practices.

• All Employees: Follow the security guidelines, complete training and report incidents promptly.

Control Requirements

• Risk Assessment & Vendor Management: Regularly assess threats and vulnerabilities, perform vendor risk reviews and implement appropriate mitigations.

• Identity & Access Management: Enforce multi-factor authentication (MFA), adopt least-privilege role-based access and regularly review permissions.

• Security Monitoring & Testing: Implement continuous monitoring for cloud infrastructure and systems to detect misconfigurations, vulnerabilities, and unauthorized activity.

• Data Protection: Encrypt sensitive data at rest and in transit, implement secure backup procedures, and classify data based on sensitivity levels.

• Change Management: Document and approve changes to production systems to minimize the risk of unintended exposures or service outages.

Data Classification and Handling

Coldreach classifies information into four categories:

• Public: Information intended for public disclosure (e.g., marketing content).

• Internal: Operational information not intended for external distribution.

• Confidential: Proprietary or customer data that requires strict controls; access is restricted to authorized personnel.

• Restricted: Highly sensitive information (e.g., encryption keys, credentials) that requires additional security measures and logging.

Handling guidelines

• Store confidential and restricted data only in approved systems with encryption.

• Transmit sensitive data using secure protocols (TLS/HTTPS).

• Do not share confidential or restricted data externally without a non-disclosure agreement and proper authorization.

Security Awareness and Training

• Provide onboarding and security awareness training for all personnel, covering phishing prevention, password hygiene and incident reporting.

• Require developers to complete secure coding training and follow secure development lifecycle practices.

Incident Reporting and Response

• Encourage employees to report any suspected or actual security incidents immediately to the CTO and engineering.

• Refer to the separate Incident Response Policy for detailed procedures on how Coldreach prepares for, responds to and recovers from security events.

Compliance and Review

• This policy will be reviewed at least annually and updated to reflect changes in technology, regulations or business operations.

• Non-compliance with this policy may result in disciplinary action, up to and including termination or legal penalties.