Incident/Breach Response Policy

Neurax Technologies Inc.

Effective Date: August 1, 2026

Neurax Technologies Inc. ("Neurax Host," "we," "our," or "us") is committed to maintaining the security, confidentiality, integrity, and availability of our systems and customer information. This Incident/Breach Response Policy outlines our approach to identifying, managing, investigating, and responding to security incidents and data breaches affecting our services.

1. Purpose

The purpose of this Policy is to:

Protect customer information and company assets.

Ensure timely identification and response to security incidents.

Minimize disruption to our services.

Comply with applicable legal and regulatory requirements, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable.

Promote continuous improvement of our security practices.

2. Scope

This Policy applies to:

All Neurax Host employees and contractors.

Company-managed servers, infrastructure, applications, and networks.

Customer information processed through our services.

Third-party service providers involved in delivering our services where applicable.

3. Definition of a Security Incident

A security incident is any event that threatens the confidentiality, integrity, or availability of our systems, services, or data.

Examples include:

Unauthorized access to systems or customer accounts.

Data breaches involving personal or confidential information.

Malware or ransomware infections.

Distributed Denial-of-Service (DDoS) attacks.

Unauthorized disclosure of sensitive information.

Credential theft or compromised accounts.

Service outages caused by cyber incidents.

Insider misuse of systems or data.

4. Incident Detection and Reporting

Security incidents may be identified through:

Automated security monitoring systems.

Firewall and intrusion detection alerts.

Server log analysis.

Customer reports.

Employee observations.

Third-party notifications.

Employees and contractors are required to report suspected security incidents immediately through established internal reporting procedures.

Customers who believe their account or data has been compromised should contact our support team as soon as possible.

5. Incident Response Process

When a security incident is identified, Neurax Host follows a structured response process.

Identification

We assess the incident to determine:

The nature of the incident.

Systems and services affected.

Potential impact on customers.

Whether personal information may have been compromised.

Containment

Where appropriate, we take immediate steps to limit the impact of the incident, which may include:

Isolating affected systems.

Restricting unauthorized access.

Blocking malicious traffic.

Disabling compromised accounts.

Applying temporary security controls.

Investigation

Our team investigates the incident to determine:

Root cause.

Scope of impact.

Information affected.

Timeline of events.

Appropriate corrective actions.

Recovery

Following containment, we work to restore services safely by:

Removing malicious software.

Restoring systems from secure backups where necessary.

Applying security updates and patches.

Verifying system integrity before returning services to normal operation.

Post-Incident Review

After resolving the incident, we conduct a review to:

Evaluate the effectiveness of our response.

Identify opportunities for improvement.

Update policies and procedures where necessary.

Strengthen preventive security measures.

6. Customer Notification

If a security incident results in unauthorized access to personal information and poses a real risk of significant harm, Neurax Host will notify affected customers as required by applicable law.

Notifications may include:

A description of the incident.

The information involved.

Steps taken to contain the incident.

Recommended actions customers should take.

Contact information for additional assistance.

Where required, we may also notify applicable regulatory authorities.

7. Customer Responsibilities

Customers also play an important role in protecting their accounts and data.

Customers are encouraged to:

Use strong, unique passwords.

Enable Multi-Factor Authentication (MFA) where available.

Keep software and applications updated.

Maintain independent backups of important data.

Monitor account activity regularly.

Report suspicious activity promptly.

8. Third-Party Service Providers

Neurax Host works with trusted third-party providers, including cloud infrastructure providers, payment processors, domain registrars, and technology vendors.

While we require these providers to maintain appropriate security measures, incidents affecting third-party services may be subject to their own security and notification procedures.

9. Record Keeping

We maintain records of significant security incidents, including:

Date and time of the incident.

Description of the event.

Systems affected.

Investigation findings.

Actions taken.

Customer notifications where applicable.

Corrective measures implemented.

Incident records are retained in accordance with our internal data retention practices and applicable legal requirements.

10. Policy Review

This Policy is reviewed periodically and may be updated to reflect changes in technology, legal requirements, industry standards, or our business operations. Updated versions will be published with a revised Effective Date.

11. Contact Information

If you have questions about this Incident/Breach Response Policy or wish to report a suspected security incident, please contact us:

Neurax Technologies Inc.

Email: info@neuraxhost.ca

Phone: +1 (778) 890-5444