Legal

Information Security

IQ8 Technology, Inc. · Version Date: July 14, 2026

IQ8 Technology, Inc. provides a work management platform for businesses (the “Platform”). Our customers entrust the Platform with business and legal information, and protecting that information is foundational to how we build and operate. This page describes our information security program. It is provided for general informational purposes; the security commitments applicable to a customer are set out in that customer’s agreement with IQ8, including the Data Processing Addendum.

Security Program and Governance

IQ8 maintains an information security program that includes administrative, technical, and physical safeguards designed to protect customer data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The program is supported by written security policies, security awareness training for personnel, and confidentiality obligations that apply to everyone with access to customer data. Security oversight is the responsibility of a designated executive who serves as IQ8’s security lead.

Independent Assessment

IQ8’s security program is subject to independent assessment; audit reports are available through our Trust Center under confidentiality.

Access Controls

Access to systems that process customer data is governed by role-based access control and the principle of least privilege. Personnel use unique credentials, and multi-factor authentication is required for administrative and remote access. Access is revoked in a timely manner when a role changes or employment ends.

Encryption

Customer data is encrypted in transit over public networks using industry-standard protocols, and encrypted at rest using industry-standard algorithms.

Operational Security

IQ8 employs network protections including firewalls and segmentation, together with logging and monitoring of relevant systems. We maintain a vulnerability management program that includes patching and periodic security testing, and we follow formal change-management and secure software-development practices.

Resilience and Continuity

Customer data is backed up regularly, and IQ8 maintains documented business-continuity and disaster-recovery procedures.

Incident Response

IQ8 maintains a documented incident-response process. If a personal data breach affects customer data, we notify affected customers consistent with our contractual commitments and applicable law, and provide information reasonably available to us to assist customers in meeting their own notification obligations.

To report a suspected security issue involving the Platform, contact security@iq8.ai.

Subprocessors and Vendor Management

IQ8 uses a limited set of subprocessors to deliver the Platform, including cloud infrastructure and AI model providers. Each subprocessor is subject to data protection obligations substantially the same as, and no less protective than, those IQ8 owes its customers, and IQ8 maintains a vendor risk-management process. The current list of subprocessors is published at iq8.ai/subprocessors, and customers receive advance notice of changes as described in the Data Processing Addendum.

Data Handling, Return, and Deletion

Where IQ8 processes personal data on behalf of customers through the Platform, IQ8 acts as a processor (or service provider) and processes that data only on the customer’s documented instructions, as described in the Data Processing Addendum. The Platform provides self-service functionality that enables customers to access, correct, export, restrict, and delete their data. Upon termination of a customer’s agreement, IQ8 deletes customer data following an export-then-delete process, except where retention is required by applicable law, with residual copies in routine backups deleted or put beyond use as they are overwritten in the ordinary course.

International Transfers

IQ8 is a U.S.-based company and may process customer data in the United States and other countries. Where data subject to the GDPR or UK GDPR is transferred internationally, IQ8 relies on appropriate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Agreement or Addendum.

Shared Responsibility

Security is a partnership. Customers are responsible for safeguarding their account credentials, restricting access to authorized users, using unique credentials and available multi-factor authentication, deactivating access for users who no longer require it, and promptly notifying IQ8 of any suspected unauthorized access, as described in our Acceptable Use Policy.

Trust Center

Additional security documentation — including audit reports and detailed security information — is available through the IQ8 Trust Center. Access is provided upon request and approval; visit trust.iq8.ai to request access.

For privacy-related inquiries, contact privacy@iq8.ai. For security questions or to report an issue, contact security@iq8.ai.