# GLBA Safeguards Addendum

**Kyroco, LLC** - Korium · Version 1.0 · Effective July 21, 2026

⚠ Draft - precautionary, pending legal review

This addendum is prepared in advance so Korium can be offered to **financial-institution** customers. It **applies only where the Customer is a “financial institution” under the Gramm-Leach-Bliley Act (GLBA) and this addendum has been executed** as part of the Agreement; it is otherwise inactive. It has **not yet been reviewed by qualified counsel**, and the internal program items it commits to (a designated Qualified Individual, a written risk assessment, a formal penetration-test / vulnerability-scan cadence, and an annual security report) should be stood up before it is offered to a live financial-institution customer.

This GLBA Safeguards Addendum (“Addendum”) supplements the [Subscription Terms of Service](terms.html) and the [Data Processing Addendum](dpa.html) (“DPA”) between Kyroco, LLC (“Kyroco,” “Service Provider”) and a Customer that is a Financial Institution (“Customer”). It sets out Kyroco’s commitments as a service provider under the FTC Safeguards Rule (16 CFR Part 314) with respect to Customer Information that Kyroco processes on Customer’s behalf through Korium.

What this covers

Kyroco is **not itself a financial institution**. This Addendum applies where Customer is a Financial Institution and Korium receives or maintains **Nonpublic Personal Information (NPI)** / Customer Information on Customer’s behalf. It complements - and does not replace - the security measures and processing terms in the DPA, which continue to apply.

#### Contents

1. Definitions
2. Information security program
3. Safeguards
4. Use & disclosure of NPI
5. Service-provider oversight
6. Security events & notification
7. Return, disposal & audit
8. General

## 1. Definitions

“**GLBA**” means the Gramm-Leach-Bliley Act and its implementing regulations, including the FTC Standards for Safeguarding Customer Information (16 CFR Part 314, the “**Safeguards Rule**”). “**Financial Institution**” has the meaning in the Safeguards Rule. “**Nonpublic Personal Information**” (“NPI”) and “**Customer Information**” have the meanings in the Safeguards Rule, and refer to the records containing NPI that Kyroco handles or maintains on Customer’s behalf. Terms not defined here have the meaning in the DPA or Agreement.

## 2. Information security program

Kyroco maintains a written information security program with administrative, technical, and physical safeguards appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the Customer Information at issue, designed to protect the security, confidentiality, and integrity of that information consistent with the Safeguards Rule. The program is overseen by a designated **Qualified Individual** (Robert Sfeir), is based on a written risk assessment of foreseeable internal and external risks, and is reported on to Kyroco’s leadership at least annually.

## 3. Safeguards

Kyroco’s program includes the safeguards described in [Annex II of the DPA](dpa.html#a2), which are designed to align with the Safeguards Rule, including:

- **Access controls** and least-privilege authentication, with periodic review of who can access Customer Information;
- **Encryption** of Customer Information in transit and at rest;
- **Multi-factor authentication** for access to systems holding Customer Information (Korium requires passkey-based authentication);
- **Change management** and monitoring/logging of authorized activity to detect unauthorized access;
- **Testing** of key controls, comprising continuous monitoring or periodic penetration testing and vulnerability assessment (currently: continuous dependency vulnerability monitoring via Dependabot, with periodic penetration testing);
- **Secure disposal** of Customer Information when no longer needed for the Service and no later than the period required by the Safeguards Rule, unless retention is otherwise required or not technically feasible;
- **Staff security training**; and
- a written **incident response plan**.

## 4. Use & disclosure of NPI

Kyroco will use and disclose NPI / Customer Information solely to provide and support the Service on Customer’s instructions and as permitted under the Agreement, the DPA, and applicable law. Kyroco will **not** use, sell, or disclose NPI for its own purposes, and will not redisclose NPI except as permitted by GLBA’s reuse-and-redisclosure limits. Kyroco does not use Customer Content (including any NPI it contains) to train, fine-tune, or improve general-purpose or foundation AI models.

## 5. Service-provider oversight

Kyroco will cooperate with Customer’s obligation to oversee its service providers, including by (a) making available information reasonably necessary for Customer to assess Kyroco’s safeguards (such as summaries, certifications, or reports like SOC 2, where available), and (b) supporting Customer’s periodic reassessment of Kyroco’s program. Kyroco imposes comparable obligations on its own subprocessors and remains responsible for them, as described in the [Subprocessors](subprocessors.html) list and the DPA.

## 6. Security events & notification

Kyroco will notify Customer **without undue delay** after becoming aware of a security event affecting Customer Information, and will provide information reasonably available to it to enable Customer to meet its own obligations - including any obligation to notify the FTC of a “notification event” (a security breach involving the unauthorized acquisition of unencrypted Customer Information of 500 or more consumers) within the timeframe required by the Safeguards Rule. This complements the breach-notification terms in the DPA.

## 7. Return, disposal & audit

On termination, and at Customer’s choice, Kyroco will return or securely dispose of Customer Information as described in the DPA, including derived artifacts and routine backups on Kyroco’s standard cycle. Audit and information-access rights are as set out in the DPA.

## 8. General

This Addendum supplements the Agreement and the DPA; if a conflict arises with respect to the safeguarding of Customer Information, this Addendum controls to the extent required by the Safeguards Rule. All other terms of the Agreement and DPA, including limitations of liability, remain in effect. This Addendum applies only while Customer is a Financial Institution and Kyroco processes Customer Information on its behalf.

Draft prepared 2026-07-21 for legal review; precautionary. The internal program elements (the written risk assessment, formal test cadence, and annual report) must be operational before this Addendum is offered to a live financial-institution customer.

Related policies

[Data Processing Addendum](dpa.html)

The base processing terms and security measures this addendum builds on.

[Privacy Policy](privacy.html)

What personal information Kyroco controls, and your rights.
