Information Security & Confidentiality Policy

KARYU estate (the "Company"), as a professional handling highly sensitive personal information, asset backgrounds, and unreleased real estate transaction data of our investors, positions the protection of confidential information as a top priority. To proactively prevent information leaks caused by human error or external threats, we execute our business based on the following strict policy.

1. Strict Access Control & Multi-Factor Authentication (MFA)

The Company adopts an enterprise cloud platform meeting global standard security requirements for business execution. System access strictly requires Multi-Factor Authentication (MFA), structurally deterring unauthorized access by eliminating password-only authentication.

2. Prohibition of Shadow IT & Strict Data Management

The handling of business information is restricted to the cloud environment and dedicated business devices approved by the Company. Data transfers to personal emails, the use of unapproved online storage, and the saving of confidential information to external storage media such as USB drives are strictly prohibited. Furthermore, all business devices are protected by strong passwords and biometric locks. In the unlikely event of loss or theft, we implement measures to immediately erase local data via remote wipe.

3. Confidentiality & Non-Disclosure

The Company strictly complies with Non-Disclosure Agreements (NDAs) regarding all confidential information learned through our operations, including clients' asset status, investment strategies, and transaction details. We firmly prohibit the use of this information for purposes other than the agreed-upon business.

4. Incident Response & Session Termination

In the event of device loss/theft or suspected unauthorized account access, we will promptly exercise administrator privileges to execute an immediate sign-out of all sessions and password reset for the corresponding account.

5. Third-Party Risk Management

When it becomes necessary to share confidential information with external professionals (tax accountants, judicial scriveners, system maintenance, etc.) for business purposes, we require these parties to comply with information protection frameworks and confidentiality obligations equal to or greater than those of the Company.