Effective Date: August 12, 2026
Owner: RYMYS Technology Consultants, LLL

Enterprise Policy Notice. This document is part of the REP Enterprise Application Legal Policies framework and applies specifically to JantryIQ. It should be read with any applicable order form, enterprise agreement, data-processing terms, and other posted RYMYS policies.

1. Purpose and Scope

This Security Statement summarizes the security principles used by RYMYS Technology Consultants, LLC to protect JantryIQ, customer information, accounts, infrastructure, and authorized integrations. It is a public summary and does not disclose confidential configurations, defensive controls, or information that could increase security risk.

2. Security Governance

RYMYS applies risk-based administrative, technical, and organizational controls across application development, deployment, infrastructure, access, monitoring, incident handling, and vendor management. Security responsibilities are assigned across platform operations and application teams, and controls are reviewed as the platform evolves.

3. Identity and Access

The Service uses authenticated access, role- and organization-based authorization, least-privilege principles, and administrative controls appropriate to the product. Customers are responsible for maintaining accurate user membership, promptly removing access that is no longer required, protecting credentials, and enabling available security features.

4. Data Protection

RYMYS uses encryption in transit for supported network communications and applies encryption at rest where appropriate to the data store and service. Sensitive credentials, secrets, tokens, and connector credentials are handled through protected configuration or credential-management controls and should not be placed in ordinary user content unless specifically required by an approved workflow.

5. Secure Development and Release

RYMYS incorporates security into application development and release practices, including dependency management, configuration review, controlled deployment, environment separation where appropriate, logging, health validation, and post-release verification. Security fixes may be deployed on an expedited basis.

6. Infrastructure and Monitoring

RYMYS uses hosting, network, application, logging, monitoring, malware-defense, access-control, and operational safeguards designed to detect or reduce unauthorized access, malicious activity, service abuse, and infrastructure failures. Specific defensive configurations are confidential for security reasons.

7. Vulnerability Management

RYMYS evaluates reported and identified vulnerabilities based on severity, exploitability, affected assets, and customer risk. Remediation priority and timing depend on the nature of the issue and available mitigations. Customers should promptly install or accept security-related updates when customer action is required.

8. Incident Response

RYMYS maintains processes for identifying, triaging, containing, investigating, remediating, and documenting security incidents. When legally or contractually required, affected customers or users will be notified in accordance with applicable obligations.

9. Availability, Backup, and Recovery

RYMYS uses backup, recovery, deployment, and operational practices intended to support resilience and restoration. No backup or availability process eliminates all risk of outage or data loss. Customers should maintain independent copies of information when their own continuity requirements call for them.

10. Third Parties

RYMYS may use vetted service providers for infrastructure, communications, AI, analytics, support, payment, and other functions. Third-party access is limited to the purposes necessary to provide the applicable service and is subject to contractual, technical, or organizational controls appropriate to the relationship.

11. Customer Responsibilities

Security is shared. Customers and users must protect credentials and devices, maintain authorized-user lists, use strong passwords and available authentication controls, avoid sharing secrets through insecure channels, review integration permissions, report suspicious activity, and comply with applicable security policies.

12. Responsible Reporting

Suspected vulnerabilities or security incidents involving RYMYS should be reported to security@rymys.com. Do not access, modify, retain, destroy, or disclose data that is not yours; disrupt services; conduct denial-of-service testing; or use social engineering against RYMYS personnel or customers. RYMYS will evaluate good-faith reports and coordinate remediation as appropriate.

13. Security Changes

Security controls evolve in response to technology, threats, regulatory requirements, and platform architecture. RYMYS may update this Security Statement without disclosing details that would weaken defensive security.