Effective Date: February 27, 2025

1. Purpose

At GemBox Ltd., we are committed to ensuring the security of our software development processes and the protection of our customers' sensitive data. We have established a Workforce Device Security Policy to maintain a high standard of security across all work-related activities.

This document outlines our security requirements for all employees and contractors who use devices (whether owned by GemBox or the individual) when working for GemBox, providing services to GemBox, or providing services on behalf of GemBox.

2. Scope

This policy applies to all employees and contractors who use their personal or company-issued devices to execute tasks for GemBox.

3. Security Requirements

3.1. Access Control & Authentication

3.2. Device Security

3.3. Data Security & Privacy

4. Compliance

To ensure continued compliance with this policy, we have implemented a yearly self-assessment checklist that all employees and contractors must complete. Responses will be stored at least for five years for auditing purposes.

5. Enforcement

Failure to comply with this policy may result in restricted access to company systems, security reviews, or contract termination.

6. Review & Updates

This policy is subject to annual review and updates based on emerging security threats and evolving best practices. Employees and contractors will be notified of any changes accordingly.