Genius Referrals maintains a risk-based assessment security program. The framework for Genius Referrals' security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Customer Data. Genius Referrals' security program is intended to be appropriate to the nature of the Services and the size and complexity of Genius Referrals' business operations. Genius Referrals has a dedicated Information Security team that manages Genius Referrals' security program. The team facilitates and supports independent audits and assessments performed by third parties. The program covers: Policies and Procedures, Asset Management, Access Management, Cryptography, Physical Security, Operations Security, Communications Security, Business Continuity Disaster Recovery Security, People Security, Product Security, Cloud and Network Infrastructure Security, Security Compliance, Third-Party Security, Vulnerability Management, and Security Monitoring and Incident Response. Security is managed at the highest levels of the company, with Genius Referrals' Chief Information Security Officer (CISO) meeting with executive management regularly to discuss issues and coordinate company-wide security initiatives. Information security policies and standards are reviewed and approved by management at least annually and are made available to all Geniusreferrals employees for their reference.