Policy
PolicyPolicy

Information Security Policy

Last updated: January 1, 2026

Prodrone Co., Ltd. establishes and maintains a rigorous information security management framework to safeguard its industrial drone systems and related information. This Policy sets out the fundamental principles and measures governing information security at the Company.

Basic Policy

Prodrone Co., Ltd. (hereinafter, the "Company") positions information security as a critical management priority and implements organizational, technical, and human safeguards to appropriately protect its information assets.

It is the Company's fundamental policy to comply with applicable laws, regulations, and contractual security requirements, and to uphold the trust of its customers, partners, and society.

Information Asset Management

The Company identifies and classifies all information assets in its possession (electronic data, documents, systems, etc.) and manages them appropriately according to their level of importance.

Access to information assets is managed under the principle of least privilege based on business necessity, with appropriate authentication and authorization controls in place.

The removal, duplication, and disposal of information assets are carried out appropriately in accordance with prescribed procedures.

Access Control

Access to internal systems and networks must comply with internal operations.

User accounts will be periodically reviewed, and unnecessary accounts will be promptly deleted.

Networks will be segmented, and firewalls and other measures will be operated to prevent unauthorized access.

Encryption

Data sent and received, as well as important stored data, are protected using industry-standard encryption methods.

Communication between the drone and the ground control system is protected by a proprietary encryption protocol to prevent interception and tampering.

Vulnerability Management

Systems and software in use must be updated regularly to maintain the latest status.

Regular vulnerability assessments and penetration tests shall be conducted, and any discovered issues must be addressed promptly according to their priority.

Firmware updates must be distributed via secure communication channels, and a mechanism to detect tampering must be established.

Incident Response

In the event of a security incident, the Company promptly carries out containment, identification of the scope of impact, recovery, and measures to prevent recurrence.

An incident response team is established to respond in an organized manner based on documented response procedures.

In the event of a serious incident, the Company will promptly report to supervisory authorities, affected customers, and other relevant parties in accordance with applicable laws and regulations.

Education and Training

The Company regularly provides security awareness education to all employees.

The Company ensures thorough awareness of the Information Security Policy and related procedures, maintaining a framework in which employees can recognize and respond to security risks.

Practical exercises such as phishing simulations are conducted to continuously improve employees' security literacy.

Continuous Improvement

The Company promotes continuous improvement of its security posture based on the framework of an Information Security Management System (ISMS).

Regular internal audits and management reviews are conducted to verify and improve the effectiveness of security measures.

This Policy is reviewed as appropriate in response to changes in technology, laws and regulations, and the business environment.