We at Lyric are committed to protecting the confidentiality, integrity, and availability of the services provided and our customer data (information stored, processed, and transmitted as part of our product usage by customers). We have formulated a CyberSecurity Steering Committee (CSSC) comprising of the executive leadership team (CEO, Head of Product, Head of Engineering, and Head of Information security & privacy) who will own security vision and strategy for meeting the required compliance with industry standards and continuous improvement of the security posture. Information Security Policies are defined for the necessary and applicable processes and shall be implemented and audited at least annually. We are ISO 27001 certified and attested for SOC 2. Audit reports can be downloaded from this portal.
- Are the policies and procedures that apply the SSRM reviewed and updated annually?
- Are communications between environments restricted to only authenticated and authorized connections, as justified by the business?
- Are policies and procedures established, documented, approved, communicated, enforced, evaluated, and maintained for the classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level?
- Are risk factors associated with all organizations within the supply chain periodically reviewed by CSPs?
- Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information processing interoperability?



