The Ivory Index

Imperial Eminence Cyberguard Corporation · The Ivory Index

Security Addendum

Tier IV — Enterprise Governance · Ref: IECC-T4-001 · Version 1.0 · Effective 14 June 2026
IECC
Document: IECC-T4-001 Version: 1.0 Effective: 14 June 2026 Governing Law: Cayman Islands Intended Jurisdiction: Cayman Islands (upon incorporation)

Article I — Purpose & Scope

This Security Addendum ("Addendum") describes the technical and organisational security measures implemented by Imperial Eminence Cyberguard Corporation ("IECC") in connection with The Ivory Index Software and associated services. It supplements the EULA, DPA, and MSA and forms part of the agreement between IECC and the Customer.

Architecture Note. The Ivory Index operates on a local-first architecture. The majority of security controls described herein apply to the local Software environment on the Customer's device. Cloud-service controls apply only where IECC operates cloud-based services under a separate Order Form.

Article II — Encryption

2.1 Data at Rest

User profile data stored at ~/.theivorry/profiles/{"{id}"}/ resides on the Customer's local device. IECC recommends full-disk encryption (e.g., macOS FileVault, Windows BitLocker) for all devices running the Software. The Software does not implement additional application-layer encryption of local profile data beyond what the host OS provides.

2.2 Data in Transit

Where the Software makes outbound network requests (e.g., optional model downloads via Ollama, institution database updates), IECC requires TLS 1.2 or higher for all connections. Self-signed certificates are not accepted. Certificate validation is enforced.

2.3 Cloud Services

Where IECC operates cloud-based services under an Order Form, data at rest is encrypted using AES-256 or equivalent. Data in transit uses TLS 1.3 where supported, with TLS 1.2 as the minimum.

Article III — Access Controls

ControlImplementation
Local Software accessOS-level user authentication; no IECC remote access to local data
IECC internal systemsRole-based access control; principle of least privilege
Cloud infrastructure (if applicable)MFA required for all privileged access; SSH key authentication; no shared credentials
Code repositoriesAccess restricted to authorised developers; branch protection on main
Production environmentsSeparated from development; access logged and audited

Article IV — Backup & Recovery

4.1 Local Software

IECC does not maintain backups of User local profile data, as such data resides exclusively on the User's device. Users are solely responsible for backing up their local data. IECC recommends regular backups of the ~/.theivorry/ directory.

4.2 Cloud Services

Where IECC operates cloud services, automated backups are performed daily. Backups are retained for 30 days (standard tier) or 90 days (enterprise tier). Recovery time objective (RTO): 4 hours. Recovery point objective (RPO): 24 hours.

Article V — Vulnerability Management

Article VI — Incident Response Overview

Security incidents affecting IECC systems are handled in accordance with the Incident Response Policy (IECC-T4-003). For incidents affecting Customer data actually held by IECC (cloud services only), IECC will notify the Customer without undue delay and in any event within 72 hours of becoming aware of the incident, in accordance with applicable data protection law.

Article VII — Third-Party Security

IECC evaluates third-party service providers and subprocessors for security posture prior to engagement. Key providers and their roles are documented in the Subprocessor Register (IECC-T4-002). IECC requires subprocessors handling Customer data to implement security measures at least equivalent to those described in this Addendum.

Article VIII — Personnel Security

Article IX — Review Cycle

IECC reviews and updates this Addendum at least annually and upon material changes to the security programme. Customers will be notified of material security changes affecting their data.

Drafted with the assistance of
Voidlex
Imperial Legal Intelligence · IECC Suite · v2.6
This document was prepared with the assistance of Voidlex, a legal document drafting tool developed by Imperial Eminence Cyberguard Corporation (IECC). Voidlex is a drafting aid only. It does not constitute legal advice, does not practice law, and does not guarantee the legal enforceability of this document in any jurisdiction. Users are strongly encouraged to seek independent legal counsel before relying on this document for commercial, regulatory, or enforcement purposes.
Governing Law — All Disputes Cayman Islands · Grand Court of the Cayman Islands
IECC Registered Operations Planned Cayman Islands registration · pre-incorporation stage
Drafting System Voidlex v2.6 · Imperial Eminence Cyberguard Corporation
TRIBUNEH
TRIBUNEH · IECC Legal Division