The Ivory Index

Imperial Eminence Cyberguard Corporation · The Ivory Index

Information Security Program

Tier V — Security Program · Ref: IECC-T5-001 · Version 1.0 · Effective 14 June 2026
IECC
Document: IECC-T5-001 Version: 1.0 Effective: 14 June 2026 Governing Law: Cayman Islands Intended Jurisdiction: Cayman Islands (upon incorporation)

Article I — Program Purpose & Governance

This Information Security Program ("Program") establishes IECC's overarching framework for protecting the confidentiality, integrity, and availability of information assets — including Customer data, proprietary software, and operational systems. It is distinct from the Security Whitepaper (technical architecture) and the Security Addendum (contractual security commitments).

1.1 Governance Structure

RoleResponsibility
Security OwnerOverall accountability for the Program; approves policy changes; escalation point for P1 incidents
Technical LeadDay-to-day implementation of security controls; vulnerability management; access reviews
All PersonnelCompliance with this Program; reporting of suspected incidents or policy violations

Until IECC reaches a headcount requiring a dedicated CISO, the Security Owner role is fulfilled by the founding technical lead. Security responsibilities will be formally delegated upon organisational scaling.

Article II — Asset Inventory

2.1 Information Asset Categories

Asset CategoryExamplesClassificationOwner
Source codeIvory Index application, build scriptsConfidentialTechnical Lead
Customer data (cloud)Support tickets, account dataRestrictedSecurity Owner
User local dataProfiles at ~/.theivorry/ (on User devices)N/A — not held by IECCUser
AI model weightsllama3.2, Ollama modelsThird-party — governed by model licencesTechnical Lead
Infrastructure credentialsCloud provider keys, signing certificatesRestrictedSecurity Owner
Legal and financial recordsContracts, invoices, correspondenceConfidentialSecurity Owner
Brand assetsLogos, marketing materialsInternalFounding team

2.2 Asset Classification Definitions

Article III — Risk Management

3.1 Risk Assessment Cycle

IECC conducts an annual information security risk assessment covering: threat identification; vulnerability assessment; likelihood and impact scoring; risk treatment decisions (accept, mitigate, transfer, avoid); and residual risk acceptance.

3.2 Risk Register

RiskLikelihoodImpactTreatment
Local device compromise leaking User dataMediumHighMitigate: recommend FDE; User responsibility disclosure
Supply chain attack on npm dependenciesLow–MediumHighMitigate: dependency scanning; lock-file integrity
Credential theft (IECC internal systems)LowHighMitigate: MFA; least privilege; regular rotation
AI model generating harmful outputMediumMediumMitigate: AUP; AI disclaimer; User review obligation
Malicious Ollama model distributionLowHighMitigate: official registry only; User model selection control
Electron XSS-to-RCE escalationLowCriticalMitigate: context isolation; node integration disabled; CSP

Article IV — Access Management

Article V — Vulnerability Management

SeverityCVSS ScorePatch Timeline
Critical9.0–10.07 days
High7.0–8.930 days
Medium4.0–6.990 days
Low0.1–3.9Next scheduled release

Vulnerability sources include: automated dependency scanning (each release); external researcher reports via legal@imperialecc.com; CVE databases; and threat intelligence feeds.

Article VI — Change Management

Article VII — Security Awareness

All IECC personnel with access to Restricted or Confidential assets receive security awareness training upon onboarding and annually thereafter. Training covers: phishing recognition; password security; incident reporting; data handling; and acceptable use of IECC systems.

Article VIII — Program Review

This Program is reviewed and updated annually, upon material organisational change, or following any P1 or P2 security incident. All updates are approved by the Security Owner and versioned. Contact: legal@imperialecc.com.

Drafted with the assistance of
Voidlex
Imperial Legal Intelligence · IECC Suite · v2.6
This document was prepared with the assistance of Voidlex, a legal document drafting tool developed by Imperial Eminence Cyberguard Corporation (IECC). Voidlex is a drafting aid only. It does not constitute legal advice, does not practice law, and does not guarantee the legal enforceability of this document in any jurisdiction. Users are strongly encouraged to seek independent legal counsel before relying on this document for commercial, regulatory, or enforcement purposes.
Governing Law — All Disputes Cayman Islands · Grand Court of the Cayman Islands
IECC Registered Operations Planned Cayman Islands registration · pre-incorporation stage
Drafting System Voidlex v2.6 · Imperial Eminence Cyberguard Corporation
TRIBUNEH
TRIBUNEH · IECC Legal Division