Information Security Addendum

HOW TO EXECUTE THIS ADDENDUM:

To complete this Addendum, please email legal@digital.ai. Upon receipt of a validly completed DPA by Digital.ai, such DPA shall become legally binding.

A pdf document version of the DPA can be downloaded here for Customer Review.

1. Purpose and Scope

This Security Addendum ("Addendum") forms part of and supplements the Master Subscription Agreement between the parties (the "MSA").  It sets out the information security, data protection, and risk management obligations that Digital.ai assumes in connection with the provision of the Software and Services.  In the event of any conflict between this Addendum and the MSA, this Addendum shall govern with respect to security matters.

This Addendum reflects Digital.ai's established Information Security and Risk Management Program, which is aligned with the ISO/IEC 27001:2022 Information Security Management System ("ISMS") standard.  Digital.ai's obligations under this Addendum apply to all systems, personnel, and subprocessors engaged in the delivery of the Software and Services to Customer.

2. Definition

The following defined terms apply throughout this Addendum.  Capitalized terms not otherwise defined herein have the meaning given to them in the MSA.

 

Term Meaning
"Customer Data" Any data, information, or content provided by or on behalf of Customer to Digital.ai in connection with the Services, including Personal Information.
"Background IP" Digital.ai's pre-existing intellectual property, tools, methodologies, frameworks, and know-how, including any improvements thereto.
"DPA" Digital.ai's Data Processing Agreement, available at digital.ai/legal/, as updated from time to time.
"ISMS" Digital.ai's Information Security Management System, aligned with ISO/IEC 27001:2022.
"Personal Information" Any information relating to an identified or identifiable natural person, as defined under applicable privacy law.
"Security Incident" Any confirmed or reasonably suspected unauthorized access, use, disclosure, modification, or destruction of Customer Data or Digital.ai systems processing Customer Data.
"Software" The commercial off-the-shelf software products provided by Digital.ai under the MSA and applicable SOWs.

3. Information Security Program

3.1  Program Standard.

Digital.ai maintains a formal Information Security and Risk Management Program aligned with the ISO/IEC 27001:2022 ISMS standard.  The program encompasses security and technology policies, risk management processes, compliance controls, and continuous improvement activities applicable to Digital.ai's cloud and internal environments.

3.2  Security Policies.

Digital.ai maintains a comprehensive suite of security and technology policies governing its approach to trust and security.  These policies are reviewed and updated at least annually, or upon material organizational or technology changes, and are monitored for ongoing compliance and effectiveness.

3.3  Risk Management.

Digital.ai performs an annual risk assessment in support of its Enterprise Risk Management Program.  Identified risks are documented, prioritized, and addressed through defined remediation projects and control improvements.  Risk exposure is reviewed on a periodic basis to confirm that existing controls remain effective.

3.4  Certifications.

Digital.ai holds the following current certifications relevant to the Services provided under the MSA:

Product Certification(s)
Digital.ai Continuous Testing ISO/IEC 27001:2022; SOC 2 Type II
Digital.ai Intelligence SOC 2 Type II
Digital.ai Application Protection ISO 13485
Digital.ai Key and Data Protection ISO 13485; FIPS 140-3 (interim validation)
Digital.ai App Management ISO 13485
Digital.ai App Aware ISO 13485
GovCloud (Digital.ai Agility) FedRAMP

Digital.ai shall maintain at minimum the certifications applicable to the Software products deployed under any SOW during the term of the MSA.  Evidence of current certifications shall be made available to Customer upon written request.

3.5  Audits and Assessments.

Digital.ai conducts comprehensive security evaluations as part of its annual compliance audits (including ISO/IEC 27001:2022 and SOC 2 Type II).  Digital.ai also performs internal operational assessments in high-risk security domains.  Assessment findings are fed into a continuous improvement cycle and corrective action program.

4. Data Protection and Encryption

4.1  Encryption Standards.

Digital.ai encrypts Customer Data both at rest and in transit using industry-standard cryptographic controls.  Encryption methods meet or exceed:

  • TLS 1.2 (or higher) for all data in transit; and
  • AES-256 for all data at rest.

Encryption keys are rotated at least annually in accordance with Digital.ai’s Encryption Policy (POL-INFOSEC-14).  Key management is performed via AWS Key Management Service for cloud-hosted services.

4.2  Data Processing Agreement.

The processing of any Personal Information by Digital.ai shall be governed by Digital.ai's Data Protection Addendum (DPA), available at  https://digital.ai/data-protection-addendum/ .  To the extent of any conflict between the MSA and the DPA with respect to the processing of Personal Information, the DPA shall prevail.

4.3  Data Availability and Redundancy.

Digital.ai's cloud products leverage highly available data centres across multiple geographically diverse AWS regions, designed to minimize customer impact in the event of any disruption.  AWS, Digital.ai's primary data hosting provider, holds SOC 2 Type II and ISO/IEC 27001:2022 certifications.

4.4  Data Backups.

Digital.ai utilizes native AWS capabilities to collect daily snapshots of each service instance.  Backups are encrypted at rest and replicated to a geographically separate region.  Backup integrity is validated through annual restore testing in a staging environment, with any issues tracked to remediation.  In-region backups are retained for a minimum of eight (8) days; out-of-region replicas are retained for a minimum of three (3) days.

4.5  Data Residency.

Digital.ai processes and stores Customer Data primarily within Amazon Web Services infrastructure.  Digital.ai's primary production regions are:

  • United States: AWS us-east-1 (N. Virginia) and us-west-2 (Oregon); and
  • European Union: AWS eu-west-1 (Ireland) and eu-central-1 (Frankfurt).

Customer shall designate its preferred primary data region, among Digital.ai’s available regions, at or prior to contract execution.  Unless otherwise agreed in writing, Customer Data will be processed and stored within the designated region, subject to temporary cross-region replication for redundancy and disaster recovery purposes only.

For Customer Data that constitutes Personal Information of European Economic Area (EEA) residents, any transfer to or storage in a non-EEA region shall be subject to the Standard Contractual Clauses (SCCs) incorporated into Digital.ai's DPA, or such other approved transfer mechanism as applies under applicable data protection law.

Customers requiring data residency outside the US and EU regions may request an on-premises deployment subject to a separate SOW and applicable licensing terms.

5. Access Controls

5.1  Principle of Least Privilege.

Access to Customer Data is restricted to authorized Digital.ai personnel based on documented job responsibilities and the principle of least privilege.  All access requests require documented approval.

5.2  Multi-Factor Authentication.

Digital.ai requires multi-factor authentication (MFA/2FA) for access to corporate network resources, internal applications, cloud environments, and any systems that process Customer Data.

5.3  Access Provisioning and Revocation.

Digital.ai maintains a well-defined access provisioning and revocation process for all systems and services, using role-based access controls aligned with individual job duties.  Access is reviewed and revoked in accordance with Digital.ai’s Access Control Policy (POL-INFOSEC-16): privileged and system administrator accounts are removed immediately upon termination or role change; all other accounts are disabled within twenty-four (24) hours upon personnel offboarding or role change.

5.4  Unauthorized Access.

Unauthorized access attempts to systems processing Customer Data are treated as security incidents and managed through Digital.ai's incident response process as described in Section 9 of this Addendum.

6. Network and Infrastructure Security

6.1  Layered Network Architecture.

Digital.ai implements a layered approach to network security across its cloud environments, with controls applied at each layer.  Infrastructure is divided by zones, environments, and services.  Production and non-production environments are separated to limit lateral connectivity.

6.2  Intrusion Detection.

Digital.ai has implemented intrusion detection capabilities across both its office and production networks to detect potential compromises.  Alerts are triaged and escalated through the incident response process.

6.3  Endpoint Security.

All devices connecting to Digital.ai's network are required to meet minimum security requirements enforced through endpoint management controls, including:

  • Full-disk encryption;
  • Device locking and screen-lock policies;
  • Anti-malware software; and
  • Approved and up-to-date operating system versions and patches.

6.4  Configuration Management.

Digital.ai maintains a current baseline configuration for all production systems.  Baseline configurations are reviewed and updated at least annually, or as required upon upgrades or significant changes.  Previous configurations are retained to support rollback.  All changes to baseline configurations must follow Digital.ai's standard change management process.

6.5  Logging and Monitoring.

Digital.ai uses centralized logging and monitoring to aggregate logs from production systems, apply monitoring rules, and flag suspicious activity.  Logs are retained in accordance with Digital.ai's internal retention policies.  Monitoring alerts are triaged, investigated, and escalated through the incident response process.

7. Change Management

7.1  Peer Review.

Each change to Digital.ai's codebase or infrastructure — including code changes and infrastructure modifications — is reviewed by one or more qualified peers prior to deployment to identify potential issues.

7.2  CI/CD Pipeline.

Security fixes and vulnerability remediations for Digital.ai's cloud products are incorporated into Digital.ai's continuous integration and continuous deployment (CI/CD) pipeline following thorough testing and validation.

8. Vulnerability Management

8.1  Continuous Scanning.

Digital.ai operates vulnerability detection tools across its products and infrastructure on an ongoing basis.  Scanning includes network scans, container image scans, open-source dependency scans, and AWS configuration monitoring.

8.2  Internal Security Reviews.

Digital.ai conducts a regular internal security review program incorporating internal audits, assessments, and security testing.  Targeted code reviews — both manual and tool-assisted — are performed to identify and resolve vulnerabilities prior to customer-facing releases.

8.3  Penetration Testing.

Digital.ai engages independent third parties to conduct penetration testing on an annual basis.  All findings are reviewed, prioritized, and tracked through remediation to closure.  Upon written request, Digital.ai shall provide Customer with a summary penetration test report or letter of attestation confirming that annual testing has been completed and material findings have been remediated.

8.4  Vulnerability Remediation.

Digital.ai's vulnerability management program integrates vulnerability identification with an internal ticketing and escalation system.  Identified vulnerabilities are remediated based on a risk-based remediation schedule, prioritized by severity and potential impact.  In accordance with Digital.ai’s Technical Vulnerability Management Policy (POL-INFOSEC-11), maximum remediation timeframes by severity are: Critical – 7 calendar days; High – 30 calendar days; Moderate – 90 calendar days; Low – 180 calendar days.  Where a patch is unavailable, compensating controls will be implemented and documented.

9. Incident Response and Breach Notification

9.1  Incident Response Framework.

Digital.ai follows a structured incident response process aligned with NIST SP 800-61.  All security events are triaged upon detection and classified based on severity and impact.  Confirmed Security Incidents are investigated, contained, remediated, and documented by a dedicated cybersecurity incident response team.

9.2  Detection and Monitoring.

Digital.ai's incident response program includes comprehensive logging and monitoring of its products and infrastructure to enable rapid detection of potential Security Incidents.

9.3  Customer Notification.

In the event of a confirmed Security Incident involving Customer Data, Digital.ai shall notify Customer:

  • Without undue delay, and in any event within seventy-two (72) hours of Digital.ai first becoming aware of the Security Incident, by written notice to the Customer's designated security contact; and
  • As soon as reasonably practicable thereafter (and in any event within forty-eight (48) hours following the initial notification), with the following information: (a) a description of the nature and cause of the Security Incident; (b) the categories and approximate volume of Customer Data affected; and (c) the measures taken or proposed to contain, investigate, and remediate the Security Incident.

9.4  Cooperation.

Digital.ai shall: (a) promptly take all steps necessary to contain and remediate the Security Incident; (b) maintain complete records of all information and evidence relating to the Security Incident; and (c) co-operate with Customer and provide such assistance as Customer may reasonably require in connection with the containment, investigation, and remediation of the Security Incident.

9.5  Regulatory Disclosure.

Nothing in this Addendum shall prevent Digital.ai from making disclosures required by applicable law or regulation.  Where Digital.ai is required by law to make a public statement or regulatory notification regarding a Security Incident affecting Customer Data, Digital.ai shall use reasonable efforts to consult with Customer prior to making such disclosure, to the extent permitted by law.

10. Business Continuity and Disaster Recovery

10.1  BC/DR Program.

Digital.ai maintains Business Continuity and Disaster Recovery ("BC/DR") capabilities designed to minimize the impact on customers in the event of a disruption.  The program is supported by dedicated personnel and teams, incorporates ongoing improvements, and is subject to scheduled testing.

10.2  Service Availability.

Digital.ai shall use commercially reasonable efforts to meet the service level agreements and service level objectives ("SLA/SLO") specified in the applicable SOW.

Where the applicable SOW does not specify alternative targets, Digital.ai commits to the following service availability and recovery objectives for cloud-hosted Software products:

  • Monthly Uptime Target: 99.5% (excluding scheduled maintenance windows of which Customer is given at least 48 hours advance notice).
  • Recovery Time Objective (RTO): Digital.ai targets restoration of affected cloud services within 24 hours of declaring a disaster event and within 168 hours for testing facility loss.
  • Recovery Point Objective (RPO): Digital.ai targets a maximum data loss window of 24 hours for cloud-hosted Customer Data.

On-premises deployments are not covered by these targets.

Where Digital.ai fails to meet the monthly uptime target, Customer's sole remedy shall be service credits as defined in the applicable SOW or SLA Schedule.

11. Third-Party Risk Management

11.1  Vendor Assessment.

All third-party suppliers, contractors, and cloud service providers engaged by Digital.ai in connection with the delivery of the Services undergo a thorough Vendor Risk Assessment conducted by Digital.ai's Information Security and Compliance team prior to engagement.

11.2  Ongoing Due Diligence.

Ongoing due diligence reviews of third-party vendors are conducted upon contract renewal or annually, depending on the risk level of the engagement. Vendor contracts include security and confidentiality requirements appropriate to the risk level of the engagement.

11.3  Subprocessors.

Digital.ai's primary infrastructure provider is Amazon Web Services (AWS), which holds SOC 2 Type II and ISO/IEC 27001:2022 certifications.  A current list of Digital.ai's material subprocessors is available through Digital.ai's DPA and/or on Digital.ai’s Data Protection FAQ.

Digital.ai shall notify Customer at least thirty (30) calendar days' prior to adding a new material subprocessor or replacing an existing material subprocessor that processes Customer Data by updating its published Subprocessor List.  Such notice shall identify the subprocessor, its location, and the nature of the processing it performs.

Customer may object to a new or replacement subprocessor on reasonable data protection grounds by delivering written notice to Digital.ai within fifteen (15) calendar days of receiving Digital.ai's notification.  Digital.ai shall use reasonable efforts to accommodate the objection, which may include: (a) procuring an alternative subprocessor acceptable to Customer; or (b) providing Customer with an opportunity to transition off the affected Service. Customer's objection does not, by itself, constitute a termination right under the MSA.

12. Personnel and Security Awareness

12.1  Internal Controls.

Digital.ai's ISMS includes personnel-related security controls governing the conduct of employees and contractors with access to customer data and Digital.ai's production systems.

12.2  Security Awareness Training.

All Digital.ai employees and contractors with access to Customer Data or Digital.ai’s production systems are required to complete security awareness training upon onboarding and on an annual basis thereafter.  Training covers information security policies, acceptable use, data handling, incident reporting, and role-specific security responsibilities. Upon written request, Digital.ai shall provide Customer with written confirmation that the required training has been completed within the prior twelve (12) months by personnel with access to Customer's instance of the Software.

13. Audit and Reporting Rights

13.1  Certification Evidence.

Upon written request, Digital.ai shall provide Customer with copies of relevant compliance certifications, SOC 2 Type II reports, or comparable third-party audit reports, dated no earlier than eighteen (18) months prior to delivery, at no cost to Customer. SOC 2 reports shall be provided subject to a mutually agreed non-disclosure undertaking.

13.2  Assessments and Questionnaires.

Digital.ai shall respond in good faith to reasonable security questionnaires and due diligence requests from Customer, within a time period as the parties may agree.

14. Artificial Intelligence and Data Use Restrictions

14.1  No Use of Public AI Tools.

Digital.ai shall not input, submit, or otherwise process Customer Confidential Data or Customer Personal Information through any publicly exposed artificial intelligence, machine learning, or large language model tools or services (including third-party generative AI services) without Customer's prior written consent.

14.2  Internal AI Governance.

Digital.ai's use of any AI or machine learning tools in connection with the delivery of the Services shall be subject to Digital.ai's internal AI governance policies, which shall be made available to Customer upon written request.

14.3  No Use of Customer Data to Train AI or ML Models.

Digital.ai shall not use Customer Data, including any data derived from Customer's use of the Software or Services, to train, fine-tune, benchmark, evaluate, or otherwise improve any artificial intelligence or machine learning model — whether Digital.ai's own models or those of any third party — without Customer's prior written consent.

For the avoidance of doubt:

  • Inputs to and resultant insights from Digital.ai's AI features constitute Customer Data and are subject to this restriction;
  • Product usage telemetry that is fully aggregated and anonymized, and from which no Customer Data can be reasonably re-identified, does not constitute Customer Data for purposes of this Section; and
  • Digital.ai's internal use of AI tools to deliver the Services (e.g., RFX response generation, internal productivity tooling) is permitted under Digital.ai's AI governance policies, provided that Customer Data processed in those tools is not used for model training.

15. General Provisions

15.1  Updates to Security Program.

Digital.ai shall not materially reduce the overall level of security protections afforded to Customer Data during the term of the MSA.  Digital.ai shall notify Customer in writing of any material changes to its ISMS that are reasonably likely to adversely affect the security of Customer Data.

15.2  Relationship to MSA.

This Addendum supplements and is incorporated into the MSA.  Except as expressly modified herein, all other terms of the MSA remain in full force and effect.  To the extent of any conflict between this Addendum and the MSA with respect to security matters, this Addendum shall prevail.

15.3  Survival.

The obligations set out in Section 9 (Incident Response and Breach Notification) and Section 4.2 (Data Processing Agreement) shall survive expiry or termination of the MSA for a period of three (3) years.