ONTARIO® INFOSEC STANDARD POLICY
Date: 07/01/2026
This Ontario InfoSec Standard Policy (this “InfoSec Policy”) describes the administrative, technical, organizational, and physical safeguards Ontario maintains in connection with the applicable Software Subscription Services made available under the Ontario® Master Subscription and Services Agreement between Ontario Technologies, LLC and/or its applicable Affiliate and Customer (the “Agreement”).
This InfoSec Policy is an Ontario Policy incorporated into, and governed by, the Agreement. Capitalized terms used but not defined in this InfoSec Policy have the meanings given in the Agreement, including the definitions applicable to Customer Data, Security Incident, Software Subscription Services, Ontario Services, Documentation, Order, Statement of Work or SOW, Professional Services, One-Time Services, Personal Data, Excluded Data, Generative AI Features, AI Output, Affiliate, and Required Support.
In the event of a conflict between this InfoSec Policy and the Agreement, the Agreement will control, except to the extent this InfoSec Policy expressly governs a specific operational, security, or data-handling matter for the applicable Ontario Services, as contemplated by the Agreement.
1. Scope
- Professional Services;
- One-Time Services;
- beta, trial, pilot, sandbox, proof-of-concept, or non-production offerings;
- custom development, configuration, integration, reporting, advisory, or consulting work not included in the standard Software Subscription Services;
- training; or
- third-party software, services, hardware, connectivity, model providers, hosting environments, or systems not controlled by Ontario.
Ontario may perform portions of the Ontario Services through its Affiliates, subcontractors, cloud providers, hosting providers, model providers, and other service providers. Ontario remains responsible for the performance of the Ontario Services in accordance with the Agreement notwithstanding its use of such parties.
2. General Security Commitments
Ontario will maintain commercially reasonable administrative, technical, organizational, and physical safeguards designed to:
- protect Customer Data against unauthorized access, acquisition, disclosure, alteration, loss, misuse, or destruction;
- support the secure provision of the Software Subscription Services;
- detect, respond to, and mitigate Security Incidents;
- support business continuity and disaster recovery for production Software Subscription Services; and
- support compliance with applicable laws and contractual obligations applicable to Ontario in connection with the Ontario Services.
Ontario will process Customer Data only as permitted by the Agreement, the applicable Ontario Policies, the Documentation, and Customer’s lawful instructions as reflected through Customer’s authorized use of the Ontario Services.
Nothing in this InfoSec Policy constitutes a guarantee that the Ontario Services will be uninterrupted, error-free, or completely secure. Ontario’s obligations are subject to the exclusions, limitations, and allocation of responsibilities set forth in the Agreement, the DPA, and the applicable Ontario Policies.
3. Information Security Management
Ontario maintains a documented information security program appropriate to the nature of its business and the Ontario Services. Such program is designed to include administrative, technical, and physical safeguards to protect systems, infrastructure, and Customer Data from loss, misuse, unauthorized access, disclosure, alteration, and destruction.
Ontario’s information security governance framework includes, as applicable:
- risk management;
- security policies and standards;
- human resources security;
- asset management;
- access control;
- physical and environmental security;
- operations security;
- communications security;
- systems acquisition, development, and maintenance;
- information security incident management;
- business continuity and disaster recovery; and
- compliance activities.
Ontario management reviews the information security program at planned intervals and may update applicable policies, standards, controls, and procedures in response to operational changes, legal or regulatory developments, threat conditions, security incidents, audit findings, third-party provider requirements, or changes to the Ontario Services.
Roles and responsibilities relating to information security are assigned and documented as appropriate for Ontario personnel, contractors, and relevant third parties.
4. Data Governance and Data Handling
Ontario maintains commercially reasonable measures designed to support governance of Customer Data processed in the production Software Subscription Services. These measures may include:
- awareness of where sensitive data is stored and transmitted across relevant applications, databases, servers, and network infrastructure;
- data retention and storage procedures appropriate to business, legal, regulatory, and contractual requirements applicable to Ontario;
- backup or redundancy mechanisms designed to support business continuity and disaster recovery;
- controls designed to protect Customer Data from unauthorized use, access, loss, destruction, falsification, or improper alteration;
- procedures for secure disposal or rendering inaccessible data on storage media in the ordinary course of system lifecycle management; and
- controls intended to limit inappropriate replication or use of production Customer Data in non-production environments, except as necessary for authorized operational, security, support, maintenance, or recovery purposes and subject to appropriate safeguards.
Customer remains responsible under the Agreement for the content, quality, integrity, legality, accuracy, and permitted use of Customer Data, and shall not upload, submit, or store any Excluded Data.
5. Auditing, Logging, and Monitoring
Ontario maintains logging and monitoring measures designed to support the security and operation of the Software Subscription Services. Such measures may include, as appropriate:
- audit logs recording privileged user activities, authorized and unauthorized access attempts, system exceptions, and information security events;
- retention of logs in accordance with applicable internal policies, operational requirements, and legal or contractual obligations;
- review of logs and alerts to facilitate detection, investigation, and response to incidents;
- use of intrusion detection, endpoint detection, monitoring, or related security tooling as Ontario deems appropriate; and
- restriction of access to audit logs and security tools to authorized personnel.
Ontario may use internal monitoring tools and records to operate, secure, support, and measure aspects of the Ontario Services, including as described in the Agreement and the Ontario Support and SLA Policy.
6. Physical Security
For facilities and environments controlled by Ontario or its service providers and used to support the production Software Subscription Services, Ontario maintains commercially reasonable physical security measures appropriate to the nature of the facility and the systems involved. Such measures may include, as applicable:
- controlled facility access;
- identity or credential verification;
- surveillance or monitoring systems;
- visitor management controls;
- secure areas and physical security perimeters;
- physical protections for servers, network equipment, and storage systems; and
- asset inventory and equipment handling procedures.
Where Customer Data is hosted in third-party cloud or data center environments, physical security controls may be provided in whole or in part by the applicable hosting or cloud provider.
7. Human Resources Security
Ontario maintains commercially reasonable personnel security measures designed to support the protection of Customer Data and the Ontario Services, including, as appropriate:
- confidentiality obligations for employees, contractors, and applicable third parties;
- communication of information security responsibilities;
- security awareness and training activities appropriate to personnel roles;
- procedures addressing onboarding, role changes, and termination; and
- timely revocation or adjustment of access following termination or change in responsibilities.
Ontario personnel and contractors with access to systems or Customer Data are expected to comply with applicable security policies, procedures, and standards.
8. Access Control
Ontario maintains commercially reasonable logical access controls designed to restrict access to systems, applications, infrastructure, and Customer Data to authorized personnel with a legitimate business need for such access.
Such controls may include, as appropriate:
- processes for granting, modifying, and revoking user access;
- timely de-provisioning following termination or change in role;
- role-based access and segregation-of-duties considerations where appropriate;
- restrictions on privileged access;
- controls over access to source code, administrative interfaces, configuration utilities, and security tools; and
- periodic review or validation of access rights.
Access to Customer Data is generally restricted on a need-to-know basis and only for authorized purposes related to providing, operating, securing, supporting, maintaining, or improving the Ontario Services as permitted by the Agreement.
9. Incident Management and Security Incidents
Ontario maintains an incident management program designed to facilitate the identification, reporting, triage, investigation, containment, remediation, and post-incident analysis of security-related events.
Ontario personnel, contractors, and relevant third parties are expected to report suspected security events through designated channels in a timely manner.
Ontario shall notify Customer without undue delay after becoming aware of any unauthorized access to Customer’s account or any Security Incident affecting Customer Data, and Ontario will use commercially reasonable efforts to mitigate the effects of such Security Incident, in each case as provided in the Agreement. To the extent a Security Incident involves Personal Data processed by Ontario on behalf of Customer and subject to the DPA, the parties’ respective rights and obligations with respect to such Personal Data shall be governed by the DPA.
Where appropriate and legally permissible, Ontario may maintain procedures for evidence preservation and forensic support in connection with incidents that may require legal review or action.
Support communications relating to service-impacting issues may also be handled in accordance with the Ontario Support and SLA Policy, including applicable support channels, severity classification, and response targets.
10. Technical Security
Ontario maintains commercially reasonable technical safeguards designed to protect the Software Subscription Services and Customer Data, which may include, as appropriate:
- network security controls such as firewalls, segmentation, and traffic filtering;
- encryption or other secure transmission methods for access to systems and transmission of Customer Data where appropriate;
- malware protection and endpoint security measures;
- restrictions on diagnostic, administrative, and configuration ports;
- secure configuration baselines;
- vulnerability management processes;
- patch and update management procedures;
- controls over utility programs and privileged management accounts;
- restrictions and safeguards for portable and mobile devices accessing sensitive systems or data; and
- multi-factor authentication or other strong authentication measures for remote administrative access, where appropriate.
Ontario may apply and test patches, updates, service packs, configuration changes, and other modifications in lower or non-production environments before deployment to production, where commercially reasonable and appropriate to the nature of the change.
11. Risk Management
Ontario performs risk-based assessments of its information security program and relevant third-party dependencies at planned intervals and upon significant changes, as Ontario deems appropriate.
Risk management activities are designed to:
- identify reasonably foreseeable threats and vulnerabilities;
- assess the likelihood and potential impact of identified risks;
- determine appropriate mitigation measures based on the nature of the risk and the affected systems or services; and
- support updates to security policies, procedures, standards, and controls.
Ontario will prioritize remediation and mitigation activities using commercially reasonable judgment, taking into account severity, exploitability, business impact, operational constraints, and available compensating controls.
12. System Development, Change Management, and Maintenance
Ontario maintains commercially reasonable procedures for secure development, testing, change management, and maintenance of the Software Subscription Services.
Such procedures may include, as appropriate:
- design and development practices informed by industry-accepted security standards;
- separation of development, testing, and production environments;
- testing and approval of material production changes prior to implementation;
- documentation of changes affecting production systems, applications, databases, or infrastructure;
- quality evaluation and acceptance criteria for systems, releases, upgrades, and updates; and
- security review activities reasonably appropriate to the nature of the change.
Ontario may use automated tools, monitoring systems, and internal quality processes to support the security, performance, and reliability of the Software Subscription Services.
13. Security Architecture
Ontario maintains commercially reasonable security architecture controls designed to support the secure operation of the Software Subscription Services. Such controls may include, as appropriate:
- unique user identifiers;
- password and credential management controls;
- disabling or removal of inactive accounts within reasonable periods;
- authentication controls, including stronger authentication for administrative or remote access where appropriate;
- session timeout or re-authentication measures;
- logging of privileged activities or access to sensitive data where appropriate;
- controls restricting connections between trusted and untrusted networks;
- firewall separation between relevant environments;
- segregation of production and non-production environments; and
- controls designed to preserve the protection and isolation of sensitive data.
Ontario may also maintain commercially reasonable safeguards for wireless networks and remote access environments, including secure configuration standards, replacement of vendor default settings, encryption, and controls designed to detect or prevent unauthorized access.
14. Backup, Recovery, and Business Continuity
Ontario maintains commercially reasonable backup and recovery procedures in accordance with the relevant Ontario Policies for Customer Data contained in the production environment of the Software Subscription Services.
Backups are maintained for disaster recovery, business continuity, security, and system restoration purposes in the ordinary course of Ontario’s operations and are not intended to substitute for Customer’s own record retention, archival, business continuity, or legal compliance obligations.
Ontario maintains and implements, or causes to be maintained and implemented, commercially reasonable business continuity and disaster recovery procedures designed to support recovery from service-impacting events affecting the production Software Subscription Services.
Ontario will use commercially reasonable efforts to restore Customer Data from available backups following a service-impacting event, Security Incident, or other data loss or corruption affecting the Ontario Services, but Ontario does not warrant that any backup will be error-free, complete, or capable of restoring all Customer Data to any particular point in time. Backup restoration is subject to the nature and timing of the event, the condition and availability of backup media, and technical limitations of the affected systems.
Ontario may perform disaster recovery or backup restoration testing at planned intervals. Upon written request and subject to confidentiality, security, and third-party restrictions, Ontario may provide summary information concerning relevant testing, rather than raw test materials or detailed internal security records.
Customer acknowledges that backup copies may remain in secure backup media after deletion from the production environment and may be overwritten, deleted, or rendered inaccessible in the ordinary course of Ontario’s retention practices, subject to applicable law, legal hold requirements, and the Agreement.
15. Security Reviews and Audit Materials
Ontario conducts internal and/or third-party security reviews, assessments, certifications, or audits from time to time as Ontario deems appropriate for the Ontario Services.
To the extent Ontario obtains security audit reports, assessments, summaries, certifications, or similar materials relating to the Software Subscription Services, Ontario may make appropriate summary information or selected materials available to Customer upon written request, subject to confidentiality obligations, access controls, nondisclosure requirements, and any applicable third-party restrictions.
Nothing in this InfoSec Policy obligates Ontario to disclose information that would compromise the security of the Ontario Services, other customers, Ontario’s systems, or any third-party environment, or that Ontario is prohibited from disclosing by contract, law, or security policy.
16. Customer Responsibilities Related to Security
Customer is responsible for:
- using the Ontario Services in accordance with the Agreement, Documentation, and Ontario Policies;
- maintaining the security of Customer-controlled systems, networks, devices, credentials, configurations, and access methods;
- providing the Required Support reasonably requested by Ontario to investigate, diagnose, contain, mitigate, or remediate security or service issues;
- promptly notifying Ontario after becoming aware of any unauthorized use of any password or account or any other known or suspected breach of security relating to the Ontario Services;
- implementing reasonable internal administrative, technical, and organizational safeguards appropriate to Customer’s use of the Ontario Services; and
- reviewing, testing, and validating outputs and workflows involving any Generative AI Features, as required by the Agreement.
Ontario’s security-related obligations may be reduced, delayed, or excused to the extent Customer fails to provide required cooperation, access, information, or other Required Support, as provided in the Agreement and the Ontario Support and SLA Policy.
17. Generative AI Security
To the extent Ontario makes Generative AI Features available as part of the Ontario Services, Ontario shall maintain commercially reasonable administrative, technical, and organizational safeguards designed to support the secure provision of such Generative AI Features, including reasonable diligence in the selection and oversight of third-party model providers, where used.
Customer acknowledges that Generative AI Features may incorporate or interoperate with third-party artificial intelligence models or services, which may be subject to technical limitations, usage policies, and availability constraints outside Ontario’s reasonable control, as described in the Agreement.
Nothing in this InfoSec Policy expands Ontario’s obligations regarding model output accuracy, appropriateness, legality, or fitness for Customer’s intended use beyond what is expressly stated in the Agreement.
18. Relationship to Other Ontario Policies
This InfoSec Policy supplements, and should be read together with, the Agreement and applicable Ontario Policies, including:
- the Ontario Data Processing Agreement (DPA);
- the Ontario Support and SLA Policy;
- the Ontario Excluded Data Policy; and
- the Ontario Customer Platform Development Policy.
For clarity:
- the Ontario Data Processing Agreement (DPA) governs Ontario’s processing of Personal Data on behalf of Customer in connection with the Ontario Services;
- the Ontario Support and SLA Policy governs support channels, support obligations, severity levels, response targets, availability commitments, and support exclusions;
- the Ontario Excluded Data Policy governs prohibited data categories and related operational responses; and
- the Ontario Customer Platform Development Policy governs ownership, classification, and treatment of customer-specific items, but does not expand Ontario’s data protection obligations beyond the Agreement and this DPA.
Nothing in this Infosec Policy expands Ontario’s support, service level, warranty, indemnity, or other obligations beyond those expressly stated in the Agreement and applicable Ontario Policies.
19. Policy Changes
This InfoSec Policy may be updated by Ontario from time to time in accordance with the Agreement. For each Order, the version of this InfoSec Policy in effect as of the effective date of that Order will apply during the Initial Term of that Order, except as otherwise permitted under the Agreement.
20. Legacy Physical and Technical Control Summary
Without limiting the generality of the foregoing, Ontario’s security practices for production environments may include the following types of controls, where appropriate to the applicable environment and architecture:
- continuous or periodic monitoring for security threats and Security Incidents;
- firewalls, intrusion detection or prevention capabilities, and secure technologies to collect, store, and transmit Customer Data;
- physical security procedures for areas in which Customer Data is stored;
- restrictions on access to and copying of Customer Data on a need-to-know basis and only at authorized locations or through authorized methods;
- regular review of password, credential, and access control procedures;
- monitored primary facility access with controlled emergency access procedures;
- surveillance capabilities in relevant facilities;
- access validation and identity verification mechanisms;
- electronic authentication and log-in validation;
- account creation and provisioning only through authorized procedures; and
- server and administrative access through encrypted or otherwise secure means.
