Think Smart Inc.

Security Annex

The security controls and operational practices behind the Services.

Last updated: December 9, 2025

← All agreements
Draft — pending review. This document is a working draft adapted for Think Smart Group Inc. and should be confirmed by legal counsel before launch.

This Security Annex (“Annex”) supplements and is incorporated into the Master Service Agreement (“MSA”) between Think Smart Group, Inc. (“TSI”) and the Customer. This Annex describes the security controls and operational practices applicable to the Services. Capitalized terms not defined in this Annex have the meanings given in the MSA and incorporated policies (SLA, AUP, Data Retention & Deletion Addendum, DPA/BAA, Third-Party Access Addendum).

1. Security Program

TSI will maintain an information security program designed to protect the confidentiality, integrity, and availability of systems and Customer/End-User data. The program will align with industry standards (e.g., CIS Controls, NIST CSF).

2. Identity & Access Management

  • Multi-factor authentication (MFA) is required for administrative access.
  • Role-based access is enforced with least privilege.
  • Time-boxed credentials are used for elevated or vendor access.

3. Network Security

  • Segmentation between tenants and environments.
  • Firewalls, intrusion detection/prevention, and DDoS protections.
  • Encrypted site-to-site and client VPN options.

4. Patching & Updates

  • Critical security patches applied on a regular schedule.
  • Standard patching and update service is part of Server Monitoring & Updates.
  • Emergency patches may be applied outside of maintenance windows when necessary.

5. Maintenance & Coordination

  • Routine maintenance windows may be scheduled to apply updates, upgrades, and other changes required to maintain security and stability.
  • Emergency maintenance may be performed outside scheduled windows as necessary to address critical security or availability risks.
  • TSI will use commercially reasonable efforts to provide advance notice of extended or disruptive maintenance.
  • Time spent during announced maintenance windows does not count as Unavailability under the SLA.

6. Monitoring & Logging

  • Centralized logging of security events and administrative access.
  • Retention of logs for at least 90 days active and 12 months archived.
  • Continuous monitoring with automated alerting.

7. Backup & Recovery

  • Nightly backups with retention as defined in the Data Retention & Deletion Addendum.
  • Backups encrypted in transit and at rest.
  • Restore requests initiated by Customer are performed per agreed SLOs.

8. Incident Response

  • Documented incident response procedures.
  • Notification to Customer without undue delay after confirmation of a security incident affecting Customer data or services.
  • Cooperation with Customer to investigate and remediate incidents.

9. Physical Security

  • Data centers are SSAE 18 SOC 2 or ISO 27001 certified or equivalent.
  • Access controlled with badging, biometrics, and 24×7 monitoring.

10. Subprocessors

TSI will use only vetted subprocessors under a written contract with equivalent security obligations. The DPA governs subprocessors for GDPR-covered data.

11. Changes to this Annex

TSI may update this Annex from time to time and will provide notice of material changes. Materially adverse changes will not take effect during a then-current Order Form term; they apply upon renewal, unless earlier required by law or to address security, legal, or system‑integrity risks. Updates will not modify commercial pricing or payment terms.

Acceptance. This Security Annex is accepted and agreed to by Customer as of the Effective Date of the Master Services Agreement into which it is incorporated.

Questions?

Prefer to ask a person?

For questions about this document or about Think Smart, reach out and we will help.