Appendix No. 1

Tino Security Controls and Requirements

This Appendix forms an integral part of the Tino Service Agreement and has been prepared in connection with the provisions relating to information security, data protection, and privacy. The purpose of this Appendix is to provide a general description of the technical security controls and measures implemented within the Tino platform during the provision of the Services.

1. Role-Based Access Control (RBAC)

The Tino platform utilizes a Role-Based Access Control (RBAC) mechanism. User access to system features and information is determined based on the user's assigned role, access level, and the permissions defined for their account.

The System Administrator or Company Administrator is responsible for managing users and assigning appropriate access permissions within the capabilities provided by the platform.

2. Login and Logout Audit Records

The Tino platform maintains records of user login and logout activities. These records may include information relating to login/logout time, authentication status, and other technical authentication-related information.

The retention period and accessibility of such records may be determined in accordance with the platform's operational, technical, and data retention policies.

3. Encrypted Communications

Communications between users and the Tino platform are protected through secure communication protocols and encrypted connections, including HTTPS based on SSL/TLS, to safeguard information transmitted between users and the platform against unauthorized interception or tampering.

4. Password Protection

User passwords are never stored in plain text. Secure one-way password hashing mechanisms are used to protect password information.

Users are responsible for keeping their passwords confidential and must not disclose them to unauthorized persons.

5. API and Integration Security

Access to the platform's APIs and integration services is protected, depending on the service type and intended use, through appropriate authentication and access control mechanisms, including API Keys, OAuth, or equivalent authentication methods.

Users are responsible for safeguarding their API Keys, Tokens, and other authentication credentials. In the event of disclosure or suspected unauthorized access, users must promptly revoke, rotate, or replace the affected credentials.

6. Web Security Headers

The Tino platform implements standard web security mechanisms, including security headers appropriate to the platform architecture. These controls may include HTTP Strict Transport Security (HSTS), Content Security Policy (CSP), X-Frame-Options, and other similar mechanisms designed to reduce the risk of common web-based attacks.

7. Protection Against Common Web Attacks

The Tino platform incorporates technical controls intended to mitigate the risk of common web vulnerabilities and attacks, including but not limited to:

a. Cross-Site Request Forgery (CSRF);

b. Cross-Site Scripting (XSS);

c. SQL Injection.

These controls are implemented as part of the platform's technical architecture and may be enhanced over time through ongoing security improvements and system updates.

8. Separation of Technical Environments

The software development and deployment lifecycle of the Tino platform utilizes segregated technical environments, including Development, Testing, User Acceptance Testing (UAT), and Production environments.

This segregation is intended to minimize the risk of development or testing activities affecting the live production environment.

9. Web Application Firewall

Depending on the underlying infrastructure architecture and enabled services, the Tino platform utilizes a Web Application Firewall (WAF) or equivalent security mechanisms to assist in detecting and mitigating certain malicious web requests and security threats.

10. Continuous Security Management and Improvement

The Company continuously reviews the platform's security posture, known threats, and technical security requirements and may update, strengthen, or modify security controls and mechanisms over time.

The security controls described in this Appendix represent the security measures implemented at the time the Services are provided and may be updated to reflect changes in architecture, technology, infrastructure, legal requirements, or applicable security standards.

11. User Security Responsibilities

Users and System Administrators are responsible for implementing reasonable security practices, including but not limited to:

a. Protecting usernames, passwords, API Keys, Tokens, and other authentication credentials;

b. Not sharing user accounts or login credentials with unauthorized individuals;

c. Granting users and employees only the access permissions required for their legitimate responsibilities;

d. Promptly notifying the Company of any unauthorized access or suspected compromise of authentication credentials;

e. Refraining from attempting to bypass or disable any security controls implemented by the platform;

f. Not conducting vulnerability assessments, penetration testing, or any activities that may disrupt the platform without the Company's prior written authorization.

12. Limitation of Security Guarantee

Although the Company implements reasonable and industry-appropriate security controls consistent with the nature of online services, no Internet-connected system can guarantee absolute security or complete protection against every potential threat, attack, or vulnerability.

The Company undertakes to implement reasonable safeguards appropriate to the nature of the Services and known security risks to protect the confidentiality, integrity, and availability of information. However, the occurrence of security incidents resulting from factors beyond the Company's reasonable control, previously unknown vulnerabilities, sophisticated cyberattacks, or the actions of third parties shall not, by itself, constitute a breach of the Company's contractual obligations.

13. Relationship Between this Appendix and the Main Agreement

This Appendix constitutes an integral part of the Tino Service Agreement.

In the event of any inconsistency between this Appendix and the main Agreement, the provisions of the main Agreement shall prevail unless expressly stated otherwise therein.

Acceptance of the Agreement by the User, System Administrator, or an authorized representative of the Company shall constitute acknowledgment, acceptance, and agreement to the terms and conditions of this Appendix.