Effective Date: April 14, 2026

1. Purpose

GemBox Ltd. is committed to maintaining appropriate technical and organizational measures to protect its software, website, systems, and business information from security threats and unauthorized access.

This page provides a general overview of GemBox's information security and cybersecurity practices.

2. Scope

This policy applies to GemBox products, the website: www.gemboxsoftware.com, internal company accounts and employee and contractor devices (whether owned by GemBox or the individual), source code repositories, build and release systems, backups, and related business operations relevant to security.

3. Security measures

GemBox maintains security measures that include, where appropriate:

4. Incident handling

GemBox maintains a process for handling reported security incidents and vulnerabilities, including triage, containment, investigation, remediation, and communication where appropriate.

For details or to report a suspected security issue, please see:

Security Incident Response and Vulnerability Disclosure Policy
https://www.gemboxsoftware.com/company/security

5. Business continuity and recovery

GemBox uses backups, redundancy, and alternative operational arrangements intended to support continuity of critical business functions and recovery from operational disruptions.

Business Continuity Plan
https://www.gemboxsoftware.com/company/business-continuity

6. Third-party services

GemBox uses a limited number of third-party suppliers and service providers to support hosting, communication, development, payments, security, backups, and related business operations.

A general list is available at:

Third-Party Supplier List
https://www.gemboxsoftware.com/company/third-party-suppliers

7. Security notices

Published security notices, if any, are available at:

Security Notices and Incident Updates
https://www.gemboxsoftware.com/company/security-incidents

8. Review and updates

This policy will be reviewed periodically and updated when needed to reflect changes in GemBox products, operations, or security practices.