General Statement
- Tezign (Shanghai) Information Technology Co., Ltd. ("Tezign" or the "Company") regards information security, data protection, and compliant operations as foundations of its business. We recognize the importance of data security and privacy to our customers and are committed to meeting our security and compliance responsibilities through rigorous governance and controls.
- This statement describes Tezign's independent certifications, technical and organizational measures, and continuous-improvement mechanisms for customers, partners, and other stakeholders. It explains how we work to protect user data, comply with applicable requirements, and contribute to a responsible industry ecosystem.
Independent Certifications and Compliance Credentials
Tezign maintains an integrated management framework spanning information security, cloud security, quality management, intellectual property, and AI compliance. Independent domestic and international certifications and assessments provide external assurance that relevant controls align with recognized standards.
| Certification/Qualification Name | Standard or basis | Status |
|---|---|---|
| ISO/IEC 27001 Information Security Management System | ISO/IEC 27001:2022 Information Security Management System Standard | Certified |
| ISO/IEC 27017 Cloud Security Controls | ISO/IEC 27017:2015 cloud security control standard | Certified |
| Multi-Level Protection Scheme (MLPS) Level 3 | GB/T 22239-2019 Basic requirements for network security level protection of information security technology | Valid; assessed annually |
| ISO 9001 Quality Management System | ISO 9001:2015 quality management system standard | Certified |
| GB/T 29490 Intellectual Property Management System | GB/T 29490-2013 Enterprise Intellectual Property Management standard | Certified |
| SOC 2 Type I Independent Examination | AICPA Trust Services Criteria (Security, Availability, Confidentiality, and Privacy) | Completed |
| Generative AI service filing | Interim Measures for the Administration of Generative Artificial Intelligence Services | Tezign's Creative Reasoning Model has completed the applicable filing |
| Algorithm filing | Provisions on the Administration of Algorithmic Recommendations in Internet Information Services | Seven algorithms have completed the applicable filing |
Information Security Management
1. Coverage
Tezign's information security and cloud security management systems cover the Company's business activities, information systems, information assets, and personnel. Guided by standards including ISO/IEC 27001 and ISO/IEC 27017, the systems are supported by documented policies, manuals, and operating procedures.
2. Risk management mechanism
Tezign maintains a structured information security risk-management process. Comprehensive risk assessments are conducted at least annually and when material changes occur. Identified risks are evaluated through asset identification, threat analysis, vulnerability assessment, and impact analysis, then addressed through avoidance, mitigation, transfer, or acceptance. Treatment plans are documented, tracked, and reviewed.
3. Core security control areas
Our security framework includes more than 30 control procedures across areas including:
- Access control: applying least privilege and segregation of duties, maintaining identity authentication and authorization controls, and reviewing access rights periodically.
- Data security: Classify and manage data at different levels, implement encrypted storage and transmission, establish a data backup and recovery mechanism, and standardize the data export process.
- Network security: Deploy protective measures such as firewalls, intrusion detection, and security audits, establish network security configuration baselines, and continuously monitor network anomalies.
- Physical and environmental security: Implement strict physical access control for office spaces and computer rooms, and establish equipment security management and media management systems
- Malware protection: deploying enterprise anti-malware controls and maintaining malicious-code prevention and incident-response procedures.
- Security incident management: maintaining 24/7 incident monitoring and response arrangements and documented incident classification and handling procedures to support timely response and traceability.
- Business continuity: Develop business continuity plans and disaster recovery plans, and conduct regular drills to ensure the continued operation of key businesses
- Supplier security: Establish a supplier information security assessment and continuous monitoring mechanism, and incorporate security requirements into procurement and contract management
- Personnel security: applying security controls throughout the employment lifecycle and providing regular security-awareness training.
4. Security development and change management
- Secure development: Tezign incorporates security requirements into applicable product design, development, testing, and release processes, with risk-based controls such as code review, vulnerability scanning, and pre-release verification.
- Environment and credential management: Tezign applies appropriate separation between production and test environments based on system architecture and manages keys, accounts, and other sensitive credentials through access controls or dedicated tools.
- Change management: material changes that may affect production are assessed, tested, approved, and recorded under internal procedures. Rollback or incident-response measures are prepared according to the risk of the change.
5. Security incident response and notification
Tezign maintains processes for identifying, reporting, analyzing, containing, recovering from, and reviewing security incidents. Incidents are handled according to their nature, impact, and applicable requirements. Where law or contract requires customer notification, Tezign will provide relevant information after completing necessary verification and in accordance with the applicable legal and contractual requirements.
6. Vulnerability management and problem reporting
Tezign identifies potential vulnerabilities through internal testing, third-party testing, and other channels. Findings are verified, prioritized, and remediated based on risk, scope of impact, and available mitigation or repair conditions.
7. Third-party management
Some products may rely on cloud computing, networks, open source software or other third-party technologies. Tezign conducts appropriate assessments based on the importance of third-party services, data exposure scope and security risks, and clarifies security and confidentiality requirements through contractual constraints, access restrictions or other reasonable measures.
Cloud Service Security
Tezign follows the ISO/IEC 27017 cloud security control standard and applies cloud-specific controls alongside its ISO/IEC 27001 information security management framework to protect customer data and privacy in cloud-service environments.
Tezign cloud security management covers key areas such as virtualization security, multi-tenant isolation, cloud asset configuration management, cloud service delivery and support, and regularly conducts cloud security configuration reviews and vulnerability scans to ensure the safe and stable operation of cloud infrastructure.
Data Protection and Privacy Compliance
Tezign protects personal information in accordance with applicable requirements, including the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, and the Personal Information Protection Law of the People's Republic of China. We maintain dedicated personal-information security policies and process personal information according to the principles of lawfulness, legitimacy, necessity, and good faith.
At the level of privacy compliance, we implement data classification and hierarchical protection, take enhanced protection measures for sensitive personal information, and protect the data subject's legal rights such as the right to know, the right to make a decision, the right to access and copy, the right to correct and supplement, and the right to delete.
Generative AI Service Compliance
As a provider of generative AI services, Tezign follows applicable AI-governance requirements, including the Interim Measures for the Administration of Generative Artificial Intelligence Services and the Provisions on the Administration of Deep Synthesis of Internet-based Information Services. Tezign's independently developed Creative Reasoning Model and relevant algorithm services have completed the applicable filings. Our AI service security practices include:
- reviewing the legality and authorization status of training-data sources;
- conducting security assessments and reviews of generated content to reduce unlawful or harmful outputs;
- assigning responsibility for algorithm security and maintaining algorithm and technology-ethics review mechanisms;
- labeling AI-generated content as required to support transparency and informed choice;
- maintaining user complaint and reporting channels for AI service security issues; and
- providing recurring generative AI compliance training to strengthen employee awareness of AI-related risks.
Intellectual Property Protection
Tezign maintains an intellectual property management system aligned with GB/T 29490, covering the creation, protection, use, and administration of intellectual property. We respect third-party intellectual property while protecting our own research, technology, and brand assets. Contractual terms, technical measures, and management controls are used to clarify ownership of customer-commissioned content and reduce infringement risk across relevant business activities.
Quality Management and Continuous Improvement
Tezign is certified to ISO 9001 and integrates quality management into product development, project delivery, and customer service. Continuous improvement is supported by internal audits, management reviews, corrective and preventive actions, and periodic evaluation of management-system effectiveness. Information security objectives are set and measured annually. Findings identified through monitoring, audits, and reviews are addressed through corrective action, while changes in laws, regulations, and standards are tracked to support ongoing compliance.
Security Awareness and Training
Tezign maintains a recurring information security training program tailored to different roles. Since 2021, the Company has provided organization-wide awareness training on topics including information protection, generative AI risk, cross-border data compliance, contract risk, and SOC 2 requirements. New employees receive information security training as part of onboarding, and periodic incident-response exercises reinforce a shared security culture.
Independent Audit and Assurance
In addition to internal audits and management reviews, Tezign uses independent third-party assessments to evaluate relevant security controls. Tezign has completed a SOC 2 Type I examination in which an independent accounting firm assessed the design of specified controls. MLPS Level 3 is assessed annually by an accredited evaluation body, and Tezign's ISO management systems are subject to recurring surveillance audits by certification bodies.
Other Provisions
Tezign may update this statement in response to changes in law, technology, products, or security practices and publish the revised version through the website, product pages, or another reasonable channel. An update does not retroactively alter obligations under an existing contract.
No network or information system is absolutely secure. Tezign applies safeguards proportionate to relevant risks and applicable requirements, but this statement does not guarantee uninterrupted service, the absence of data loss or vulnerabilities, or protection against every security incident. It does not expand Tezign's obligations under applicable contracts or law.