01

Purpose & Scope

Aevum Zenth operates across 400+ subsidiaries and 47 distinct industries. To maintain operational integrity, protect proprietary assets, and fulfill legal obligations, this policy establishes standardized protocols for how information is classified, shared, and disclosed internally and externally.

Applicability: This policy applies to all employees, contractors, board members, subsidiaries, and third-party partners authorized to access Aevum Zenth systems, facilities, or proprietary data.

⚠️ Non-compliance with this policy may result in disciplinary action, termination, civil liability, or criminal prosecution depending on severity and jurisdiction.
02

Information Classification Framework

All corporate data must be categorized according to sensitivity, regulatory impact, and business criticality. Misclassification is prohibited.

Classification Level Description Access Control Examples
Public Information approved for unrestricted external release None Annual reports, press releases, marketing materials
Internal Operational data for day-to-day business functions Employee/Partner ID required Org charts, internal procedures, non-sensitive metrics
Confidential Sensitive business, financial, or personnel information Role-based + NDA required Strategic plans, R&D data, supplier contracts
Restricted Critical assets requiring highest protection tier Need-to-know + Multi-factor auth Source code, fusion schematics, executive compensation, PII
03

Permitted Information Sharing

Information may be shared across divisions only when:

  • The recipient has an explicit business need and appropriate clearance level
  • Data is transmitted through approved Aevum Zenth secure channels (ZenthVault, encrypted email, or secure file transfer)
  • Cross-divisional data sharing agreements (CDSA) are executed for Confidential/Restricted materials
  • Metadata and access logs are preserved for audit compliance

Prohibited Sharing Practices

  • Using personal email, cloud storage, or unencrypted messaging platforms for corporate data
  • Forwarding Confidential/Restricted documents to external parties without CCO approval
  • Removing security watermarks, access controls, or audit trails from official documents
  • Sharing credentials or bypassing multi-factor authentication controls
04

External Disclosure Requirements

Any disclosure of Aevum Zenth information to external entities, media, regulators, or the public must follow strict governance:

  1. Pre-Approval: All external disclosures require sign-off from the Chief Communications Officer (CCO) and relevant division head
  2. Regulatory Filings: SEC, FCA, MAS, or equivalent jurisdictional disclosures must be routed through Investor Relations & Legal Compliance
  3. Media & Interviews: Employees are strictly prohibited from providing unsanctioned statements to journalists or analysts
  4. Conference & Publications: Academic or industry presentations involving proprietary data require Data Governance Board clearance
⚡ Selective disclosure of material non-public information to analysts, investors, or media constitutes market manipulation under SEC Rule 10b-5 and equivalent global regulations.
05

Regulatory & Legal Compliance

Aevum Zenth operates under multiple regulatory frameworks. Information handling must align with:

  • GDPR / CCPA / LGPD: Personal data processing, cross-border transfer restrictions, and data subject rights
  • SOC 2 / ISO 27001: Access control, encryption standards, and incident response protocols
  • SOX / PCAOB: Financial data integrity, audit trails, and executive certification requirements
  • Export Controls (EAR / ITAR): Dual-use technology, aerospace, and defense data restrictions
  • HIPAA / MDR: Healthcare data handling and medical device documentation standards
06

Security & Handling Standards

All information assets must be protected according to their classification level:

Control Measure Internal Confidential Restricted
Encryption (At Rest) Recommended Mandatory (AES-256) Mandatory (FIPS 140-3)
Encryption (In Transit) TLS 1.2+ TLS 1.3 + mTLS Zero-Trust Tunnel
Retention Period 2 Years 5 Years 7 Years + Legal Hold
Destruction Method Secure Delete Cryptographic Erase Physical Destruction / Degaussing
07

Breach Reporting & Incident Response

Any suspected or confirmed unauthorized access, loss, or disclosure of Aevum Zenth information must be reported immediately:

  • Internal Hotline: +1-800-AEVUM-SEC (24/7 monitored)
  • Email: security@aevumzenth.internal
  • Ticketing: ServiceNow > Security Incident > Data Breach

All employees must report within 1 hour of detection. The Office of the CISO will initiate containment, forensic analysis, regulatory notification (if required), and remediation per ISO 27035 standards.

Retaliation against good-faith reporters is strictly prohibited and violates Aevum Zenth's Whistleblower Protection Directive.

08

Contact & Policy Administration

This policy is administered by the Office of the Chief Compliance Officer (OCCO) in partnership with Global Data Governance.

Questions or Clarifications: compliance@aevumzenth.internal
Data Classification Requests: datagovernance@aevumzenth.internal
Legal Counsel: legal@aevumzenth.internal

Policy updates will be communicated via the Aevum Zenth Compliance Portal. Acknowledgment of receipt is mandatory for all personnel within 14 days of publication.

Next Review Date: January 1, 2027

Approved by Board of Directors, Committee on Governance & Risk