The lab’s second partner cohort, one hundred organizations, closes August 7 →

Legal

Information Security & Compliance Schedule

Transformation, Co. (formerly Altrix Technologies, Inc.)  ·  Exhibit B to the Master Services & License Agreement

Provider: Transformation, Co., operating as “Latent Variables” (“Provider”). Customer: the counterparty to the Agreement (“Customer”).

This Information Security & Compliance Schedule (this “Exhibit”) is incorporated into and forms part of the Master Services & License Agreement between Provider and Customer (the “Agreement”). Capitalized terms used but not defined in this Exhibit have the meanings given to them in the Agreement. In the event of a conflict between this Exhibit and the body of the Agreement with respect to the subject matter of this Exhibit, this Exhibit controls.

This Exhibit describes the administrative, technical, and physical safeguards Provider has designed and maintains to protect Customer Data, including any Protected Health Information (“PHI”) that comes within the scope of an engagement. Except where expressly stated as an absolute obligation, the controls described in this Exhibit are commitments Provider maintains and operates on a commercially reasonable basis, and Provider’s obligation is to use commercially reasonable efforts to operate the security program described here.

1Hosting & Tenancy

1.1 Hosting. The Platform and all Provider-controlled processing of Customer Data run on Amazon Web Services (“AWS”) infrastructure located in United States regions only. Provider maintains no on-premises servers and no physical storage of Customer Data; physical and environmental safeguards for the underlying data-center facilities are provided and independently audited by AWS.

1.2 Single-tenant isolation. In the standard deployment, Provider provisions each Customer in a dedicated, single-tenant environment within Provider’s AWS organization, bounded by a dedicated account and virtual private cloud (“VPC”) with its own data stores. There is no shared, multi-tenant database in which Customer records are commingled with the data of any other customer at any layer of the Platform.

1.3 Per-tenant key separation. Each tenant’s Customer Data is encrypted under tenant-specific keys managed in AWS Key Management Service (“KMS”), such that data created in one engagement cannot be read in the context of another.

1.4 No data on local devices. Customer Data is not stored on local devices or personal workstations. Insights and rollout artifacts are surfaced to Authorized Users through a web interface.

1.5 Alternative deployment topologies. Where agreed in an Order Form, Provider may deploy the Platform so that Customer Data and the derived behavioral model reside in infrastructure Customer controls (for example, Customer’s own cloud account or a Customer-managed data platform). Where Customer operates a portion of the Platform in its own environment, the controls governing that portion are Customer’s, and the boundary between the parties’ respective responsibilities is documented during scoping.

2Encryption

2.1 At rest. Provider encrypts Customer Data at rest using AES-256 (or an equivalent or stronger industry-standard algorithm).

2.2 In transit. Provider encrypts Customer Data in transit using TLS 1.2 or higher. API endpoints are secured with TLS 1.2 or higher.

2.3 No unencrypted Customer Data. Provider does not store or transmit Customer Data in unencrypted form.

2.4 Key management. Encryption keys are managed in AWS KMS, isolated per tenant, access-controlled, and rotated on a defined schedule. Provider personnel cannot export key material.

3Access Control

3.1 Least privilege (RBAC). Provider applies role-based access controls that limit each account — Provider personnel and Authorized Users alike — to the minimum data and functions required for its function, consistent with the minimum-necessary standard.

3.2 Multi-factor authentication. Provider requires multi-factor authentication for all administrative and production access and for Customer access to the web interface.

3.3 Single sign-on. Single sign-on via SAML 2.0 is available for Customers that require it.

3.4 Session timeout. Sessions require re-authentication after a defined period of inactivity.

3.5 Periodic access reviews. Provider reviews access rights on a periodic basis, no less frequently than quarterly, and removes dormant accounts.

3.6 No shared administrative accounts. Administrative privileges are granted sparingly, logged, and reviewed. Provider does not maintain shared administrator accounts.

3.7 Account lifecycle. Accounts are provisioned through a documented request-and-approval workflow with a retained audit trail and are de-provisioned promptly on role change or departure.

3.8 Secrets management. Authentication secrets are stored only in hashed, salted form, and application secrets are held in a managed secrets store, never in source code.

4Audit Logging

4.1 Logging of access and activity. Provider logs access to electronic Customer Data with, at minimum, user identity, timestamp, action performed, and the records touched.

4.2 PHI log retention. Where PHI is within the scope of an engagement, Provider retains the associated audit logs for at least six (6) years, consistent with 45 CFR §164.316(b)(2).

4.3 Integrity controls. Provider maintains mechanisms designed to authenticate stored data and protect it against unauthorized alteration or destruction.

5Network Security

5.1 Perimeter. Production systems sit behind firewalls, a web application firewall (“WAF”), and network segmentation. Only required services are exposed.

5.2 No public data stores. No Customer Data store is exposed to the public internet.

5.3 TLS-only ingress. All ingress to production is over TLS. Administrative access is restricted to authorized operators over encrypted, authenticated channels.

6Environment Separation

6.1 Production vs. non-production. Provider separates production environments from development and test environments.

6.2 No Customer Data in non-production. Customer Data is never used in non-production environments.

6.3 Synthetic and de-identified test data. Testing is performed using synthetic or de-identified data.

7Vulnerability Management

7.1 Scanning and testing. Provider maintains a vulnerability-management program that includes vulnerability scanning and periodic penetration testing performed on at least a quarterly basis.

7.2 Remediation. Provider tracks identified vulnerabilities to remediation according to documented severity and timeline criteria.

7.3 Penetration-test summary. A penetration-test summary and a vulnerability-management overview are available to Customer under a non-disclosure agreement.

8Endpoint & Threat Detection

8.1 Endpoint protection. Provider deploys endpoint detection and response (“EDR”) on workstations used to access Customer Data.

8.2 Intrusion detection and prevention. Provider operates intrusion detection and prevention (“IDS/IPS”) monitoring of production for threats.

8.3 Continuous monitoring. Automated monitoring provides continuous visibility into security events, which are classified by severity with defined response times.

9Change Management

9.1 Code review and testing. Provider maintains a change-management process that includes code review, testing, and approval before changes are promoted to production.

10Personnel Security

10.1 Background checks. Provider conducts background checks prior to granting personnel access to systems that hold Customer Data, to the extent permitted by applicable law.

10.2 Confidentiality obligations. Provider personnel and contractors with access to Customer Data are bound by written confidentiality obligations.

10.3 Security and privacy training. Every employee and contractor with access to Customer Data completes privacy and security training at onboarding and annually thereafter, with documented acknowledgment.

10.4 Sanctions policy. Provider maintains a written sanctions policy governing workforce members who fail to comply with its security and privacy policies.

11Availability & Resilience

11.1 Uptime target. Provider maintains a target Platform availability of 99.9%, with real-time monitoring and alerting.

11.2 Redundancy. Provider operates the Platform with multi-availability-zone redundancy and automatic failover.

11.3 Disaster recovery. Provider maintains a disaster-recovery program designed to achieve a recovery-time objective (“RTO”) of under four (4) hours and a recovery-point objective (“RPO”) of under one (1) hour.

11.4 Backups and restore testing. Provider maintains encrypted backups of Customer Data and performs periodic restore testing.

11.5 Contingency planning. Provider maintains a data backup plan, a disaster-recovery plan, and an emergency-mode operation plan, which are tested at least annually.

12Sub-processor Governance

12.1 Engagement of Sub-processors. Provider may engage Sub-processors to process Customer Data in connection with delivering the Services. Provider maintains a current list of Sub-processors that touch Customer Data and makes it available to Customer.

12.2 Vendor risk assessment. Each Sub-processor undergoes a security and compliance review before onboarding and is reassessed at least annually, with ongoing monitoring of the critical Sub-processors.

12.3 Contractual safeguards. Provider executes a Business Associate Agreement (“BAA”) or an equivalent data-protection agreement (“DPA”) with each Sub-processor that creates, receives, maintains, or transmits Customer Data (and, where PHI is in scope, with each Sub-processor that handles PHI).

12.4 Advance notice and right to object. The Sub-processor list is maintained as a living list. Provider gives Customer advance notice of any new Sub-processor that would have access to Customer Data, and Customer may object to a new Sub-processor as provided in the Agreement or the DPA.

12.5 US processing. Provider’s primary Sub-processors process Customer Data exclusively in United States regions.

13Model-Provider Controls

13.1 Enterprise API. The interview layer and language-model inference are performed through OpenAI’s enterprise API, not consumer products.

13.2 No training on Customer Data. Customer Data — including Interview recordings, transcripts, and the derived behavioral model and memory graph — is processed under enterprise terms that contractually exclude it from model training. Customer Data is not used to train or fine-tune any model, whether Provider’s or a Sub-processor’s. PHI is never used for model development under any circumstance.

13.3 Zero retention where offered. Where the model provider offers it, zero-retention processing is used, so that prompts and outputs are not persisted by the provider beyond the moment of inference. Where zero-retention processing is not offered, retention by the provider is limited to what is required to deliver the Services. This is a conditional commitment and not an unconditional warranty.

13.4 US processing. Model inference is performed in the United States.

13.5 BAA where PHI in scope. Where PHI is within the scope of an engagement, the relationship with the model provider is governed by a Business Associate Agreement.

14Compliance Program

14.1 Information-security program. Provider maintains an information-security program aligned with the AICPA Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, and Privacy) underlying SOC 2 Type II.

14.2 SOC 2 status. Provider is undergoing independent examination toward SOC 2 Type II attestation. Provider is not SOC 2 certified or attested as of the Effective Date. Interim evidence — including a description of the control environment, current audit status, and, where applicable, a bridge letter — is available to Customer under a non-disclosure agreement, and the SOC 2 Type II report will be made available when issued.

14.3 HIPAA program. Where PHI is within the scope of an engagement, Provider maintains a HIPAA compliance program, including a designated Privacy Officer and Security Officer, workforce privacy and security training, a documented risk analysis conducted at least annually, a written sanctions policy, and breach notification as described in Section 15. A BAA is available and governs any engagement in which PHI is in scope.

14.4 De-identification. Where the work permits, Provider operates on de-identified data under the Safe Harbor method (45 CFR §164.514(b)) or by Expert Determination.

14.5 Optional regulatory modules. Where Customer requires, the parties may execute additional data-protection modules (for example, CCPA service-provider terms or a GDPR/SCC annex). Provider makes no representation as to active operations in any jurisdiction not addressed by an executed module.

15Incident Response & Breach Notification

15.1 Incident response. Provider maintains an incident-response program with maintained runbooks, escalation contacts, and communication templates; detection and analysis with severity classification; containment and eradication; recovery to a known-good, verified state; and a documented post-incident review.

15.2 Triage. Provider triages a potential incident promptly upon discovery and begins a formal investigation to establish its nature, scope, and cause.

15.3 Breach notice. In the event of a confirmed breach of unsecured Customer Data (including unsecured PHI), Provider will notify Customer without unreasonable delay and in any event within thirty (30) calendar days of discovery. The notification will identify the affected individuals where known, describe the incident and the categories of data involved, recommend protective measures, and record the investigation and the mitigation undertaken.

15.4 Mitigation. Provider applies immediate technical and procedural measures to contain the incident and prevent recurrence, including credential rotation, access revocation, and forensic analysis.

16Data Retention, Deletion & Export

16.1 Retention during the engagement. Provider retains Customer Data only for the period required to deliver the contracted Services. Default transcript retention is twelve (12) months unless otherwise agreed in an Order Form.

16.2 Deletion on termination. On termination or expiration of the Agreement, Provider securely deletes Customer Data held by Provider within thirty (30) calendar days, unless a written alternative is agreed (including a port-over to Customer’s own environment).

16.3 Backup purge. Encrypted backups containing Customer Data are purged within ninety (90) calendar days of termination.

16.4 Certificate of destruction. A certificate of destruction is available on request.

16.5 Participant deletion requests. Participant deletion requests are processed within fifteen (15) days.

16.6 Export and no lock-in. Customer may export its Customer Data and Outputs during the engagement and on its conclusion. Structured data is provided in open, non-proprietary formats (for example, CSV or Parquet), and analytical Outputs are provided as standard documents (for example, spreadsheets and slide decks). No proprietary format is required to read or retain what Customer exports, and export does not depend on the continuation of the engagement.

This Exhibit describes Provider’s security program as of the Effective Date and may be updated to reflect improvements, provided protections are not materially diminished. © Transformation, Co. All rights reserved.