Antavo Vulnerability Disclosure Policy

Statement

ANTAVO hereby informs all external parties that ANTAVO does not operate a public vulnerability disclosure program and does not, directly or indirectly, accept, expect, solicit, or promise or offer to accept vulnerability reports from individuals or entities outside the organization.

ANTAVO EXPRESSLY DISCLAIMS ALL LIABILITY WITH RESPECT TO VULNERABILITY REPORTS FROM INDIVIDUALS OR ENTITIES OUTSIDE THE ORGANIZATION. ANTAVO SHALL NOT BE LIABLE FOR REVIEWING, ACKNOWLEDGMENT OF, RESPONDING TO, OR TAKING ANY ACTION REGARDING UNSOLICITED SECURITY VULNERABILITY DISCLOSURES SUBMITTED THROUGH ANY CHANNEL TO ANTAVO. ANY SUCH SUBMISSIONS WILL BE CONSIDERED UNREQUESTED COMMUNICATIONS. ANTAVO SHALL NOT BE LIABLE FOR ANY DAMAGES OR LOSSES ARISING FROM SENDING VULNERABILITY REPORT BY YOU TO ANTAVO. YOU ASSUME ALL LIABILITIES, RISKS AND ALL COSTS ASSOCIATED WITH SENDING ANY VULNERABILITY REPORTS TO ANTAVO.

Should ANTAVO choose to implement a formal vulnerability disclosure framework in the future, relevant procedures and contact information will be made available via official company communication channels, including but not limited to its corporate website.

Date: September 25, 2025