Contents
1. Scope
2. Security Program and Policy Framework
2.1. Security Risk Oversight
2.2. Security Risk Management
2.3. Information Security
2.4. Physical and Environmental Security
3. Access Control
3.1. New Accounts, Roles, and Access Requests
3.2. Account Review
3.3. Account, Role, and Access Removal
3.4. Credentials
4. System Development and Maintenance
4.1. Secure Design Principles
4.2. Change Management
4.3. Penetration Testing
5. Asset Management
5.1. Physical and Virtual Asset Management
5.2. Application and System Management
5.3. Data Retention
6. Human Resources Security
6.1. Background Screening
6.2. Training
6.3. Enforcement
7. Operations Security
7.1. Network and System Security
7.2. Logging
7.3. Certificate, Credential, and Secret Management
7.4. Vulnerability Management
8. Encryption
8.1. Protection of Data in Transit
8.2. Protection of Data at Rest
9. Physical Security
9.1. Facilities
9.2. Data Centers
10. Business Continuity & Disaster Recovery
10.1. Business Continuity
10.2. Disaster Recovery
11. Incident Response
12. Vendor Management
12.1. Onboarding
12.2. Ongoing Assessment
12.3. Off-boarding
13. Compliance
13.1. Treatment of Personal Data
13.2. Disclosure of Customer Content
13.3. Customer Security and Regulatory Requirements
14. Customer Audits and Inquiries
15. Contacts
This Green Parrot Collective Pty Ltd (“Green Parrot”, “We”, “Us” or “Our”) Services Security Exhibit (the “Exhibit”) describes the security controls implemented in connection with the performance of Cloud services, technical support services or consulting services (the “Services”) delivered to customers (“Customer”, “You” or “Your”) under the relevant Cloud Services Group license and/or services agreement and the applicable order for the Services (collectively, the “Agreement”). Beta or lab/tech preview services (including Cloud Labs) and Our internal IT systems not involved in the delivery of Services are outside of the scope of this Exhibit.
1. Scope
This Exhibit describes the administrative, physical and technical security controls we employ in order to maintain the confidentiality, integrity and availability of our Services. These controls apply to our operational and Services systems and environments. Green Parrot employs ISO/IEC 27001 as the baseline for its Services security program and has obtained industry certifications and assessments for specific Services. Additional information relating to current Certifications is available on our Trust Center https://www.greenparrot.io/trust-center/certifications.
We seek to continually strengthen and improve our security practices, and so reserve the right to modify the controls described herein. Any modifications will not diminish the level of security during the relevant term of Services.
2. Security Program and Policy Framework
Green Parrot has a security program and policy framework that is established and approved by senior and executive management representing various business areas throughout the company. Policies are reviewed annually and updated as needed to current industry good practice.
2.1. Security Risk Oversight
2.1.1. The Cyber Risk Oversight Committee (CROC) governs security risk management activities. The CROC consists of cross-functional management and leadership. The executive leadership team reviews committee membership on an annual basis to confirm adequate coverage of business and operational areas.
2.1.2. The CROC meets at least quarterly and provides guidance, insight, and direction in identifying, assessing and addressing security risks in both corporate operations, as well as service delivery infrastructure.
2.2. Security Risk Management
Green Parrot utilizes a security risk management (SRM) program that identifies potential threats to Our products and services and to Our infrastructure, rates the significance of the risks associated with those threats, develops risk mitigation strategies, and partners with our Product and Engineering teams to implement those strategies. Our risk management program aligns with ISO/IEC 31000 and ISO/IEC 27005.
2.3. Information Security
Green Parrot has appointed a Chief Information Security Officer (CISO), who is responsible for security oversight and policy strategy, compliance and enforcement. Green Parrot has Information Security policies and standards to define security requirements.
2.4. Physical and Environmental Security
Green Parrot also implements physical and environmental controls to secure our facilities.
3. Access Control
We require the use of access control measures designed to ensure appropriate privileges are assigned and maintained for access to company systems, assets, data and facilities in order to protect against potential damage, compromise, or loss. We follow the Least Privilege Principle, and/or role-based security, limiting user’s access to only what is necessary to perform job functions or roles.
Managers design roles to provide adequate separation of duties, distributing tasks and privileges among multiple people in order to safeguard against fraud and error.
3.1. New Accounts, Roles, and Access Requests
Green Parrot requires a formal request for access to company systems or data. Each access request requires a minimum approval of the user’s manager to confirm the user’s role and access. Access administrators confirm that necessary approvals are obtained prior to granting access to systems or data. The principle of least-privilege is applied.
3.2. Account Review
We perform, at minimum, annual reviews of user accounts and assigned permissions for key systems and functions. Any changes are actioned promptly.
3.3. Account, Role, and Access Removal
We require user access be disabled, revoked, or removed promptly upon notification of a user’s role change (if applicable), termination, user’s conclusion of engagement, or departure from the company. Access removal requests are documented and tracked.
3.4. Credentials
• Green Parrot requires multi-factor authentication for sensitive access including remote access to our systems and enforces the following password handling and management practices:
• Passwords are rotated regularly, as dictated by system requirements we set
• Passwords must meet length and complexity requirements, including a mix of digits, special characters and upper- and lower-case letters, a minimum number of characters, and not allowing common or dictionary words
• De-activated or expired user IDs are not granted to other individuals
• Unique IDs are generated for all individuals
• We maintain procedures to deactivate passwords that have been inadvertently disclosed
• We monitor repeated attempts to gain access to the services using an invalid password and take automated actions to block repeated attempts
• Green Parrot uses practices designed to maintain the confidentiality and integrity of passwords when they are assigned, distributed and stored, such as:
o Requiring that passwords remain hashed and/or encrypted throughout their lifecycle
o Prohibiting the sharing of passwords
4. System Development and Maintenance
We maintain a Secure by Design process, which includes standards and change controls procedures designed to address security requirements of the information systems, code review and testing, and security around the use of test data. This process is managed and monitored by a specialized security team, which is also responsible for design review, threat modeling, manual code review and spot checks, and penetration testing.
4.1 Secure Design Principles
Green Parrot has adopted a formal Systems Development Life Cycle (SDLC) methodology that governs the development, acquisition, implementation, and maintenance of computerized information systems and related technology requirements.
We use a software-based system for managing Open Source reviews and approvals, which includes conducting periodic scans and audits of its software products. We have documented policies regarding the use of Open Source, as well as training for developers and their management on Open Source best practices.
4.2 Change Management
Our infrastructure and software change management process addresses security requirements and requires that software and infrastructure changes to be authorized, formally documented, tested (as applicable), reviewed, and approved prior to deployment to the production environment. Infrastructure and software changes are managed and tracked using work management systems.
The change management process is appropriately separated, and access to migrate changes to production is restricted to authorized personnel.
4.3 Penetration Testing
Penetration testing of Green Parrot systems is conducted via an independent team. Both enterprise testing and select product testing is performed annually. Issue ratings shall follow industry standard practices. We also use the Common Vulnerability Scoring System (CVSS) published by the US National Institute of Standards and Technology (NIST) for rating vulnerabilities.
5. Asset Management
5.1 Physical and Virtual Asset Management
Green Parrot maintains a dynamic inventory of the physical and virtual systems we manage and use to perform the Services (“Service Assets”). System owners are responsible for maintaining and updating their Service Assets consistent with our security standards.
Formal disposal procedures are in place to guide the secure disposal of Green Parrot and Customer data. We dispose of data when no longer required based on classification and using deletion processes designed to prevent data from being reconstructed.Our technology assets are sanitized and disposed of when they are no longer needed within their designated or assigned area. Technology assets include but are not limited to individual computing devices, multifunction computing devices, storage devices, imaging devices, and network appliances.
5.2 Application and System Management
Application and system owners are responsible for reviewing and classifying the data they store, access, dispose of, or transmit. Among other controls, employees and contractors are required to:
5.2.1 Classify Customer Content as among the highest two categories of Green Parrot confidential information, and apply appropriate access restrictions
5.2.2 Restrict the printing of Customer Content and dispose of printed materials in secure containers
5.2.3 Not store corporate or Confidential Information on any equipment or device that does not meet the requirements of Green Parrot security policies and standards
5.2.4 Secure computers and data while unattended
5.3 Data Retention
Customer Content stored as part of our Cloud Services is accessible by the Customer for a limited time period following the termination of services. Additional details are provided in the specific services documentation. Customer Content may also be retained following the completion of the services if required for legal purposes. Green Parrot will comply with the requirements of this Exhibit until such Customer Content has been permanently deleted.
6. Human Resources Security
Maintaining the security of Customer Content is one of the core requirements for all employees and contractors. Our Code of Business Conduct requires all employees to adhere to our security policies and standards, and specifically addresses the protection of confidential information, as well as personal information of customers, partners, suppliers and employees. All employees and contractors are subject to confidentiality agreements, acceptable use and privacy requirements that cover customer information. The Green Parrot Security organization also regularly communicates to employees and contractors on topics related to information and physical security in order to maintain security awareness on specific topics.
6.1 Background Screening
We currently use background screening vendors for all new hires globally and require the same for our third-party supplier personnel, except where limited by local law or employment regulations.
6.2 Training
All employees are required to take training on data protection and on company policies designed to protect the security of our confidential information, which includes the confidential information of our customers, partners, suppliers and employees. The training covers privacy practices and the principles that apply to employee handling of confidential information, including the need to place limitations on using, accessing, sharing and retaining confidential information. Members of the Engineering organization undergo specific training that consists of secure development, architecture, and coding. Contractors are also required to take specific security training.
6.3 Enforcement
All employees and contractors are required to comply with our security and privacy policies and standards. Non-compliance is subject to disciplinary action, up to and including termination of employment.
7. Operations Security
7.1 Network and System Security
Green Parrot has documented network and system hardening standards designed to ensure that networks and systems are securely configured. Required procedures under these standards include, but are not limited to:
7.1.1 Changing or disabling default settings and/or accounts
7.1.2 Controlled use of administrative access
7.1.3 Restrict service accounts for only the purpose which they were created
7.1.4 Configure logging and alert settings appropriate for auditing
We require the implementation of anti-malware software on servers and workstations, and scan the network for malicious software.
Network controls govern access to Customer Content. These include, as applicable: configuring an intermediate untrusted zone between the Internet and the internal network that includes a security mechanism to restrict access and unauthorized traffic; network segmentation to prevent unauthorized access of Customer Content; and separating web and application servers from the corresponding database servers in a tiered structure that restricts traffic between the tiers.
7.2 Logging
We collect logs to confirm the correct functioning of our services, to assist with troubleshooting system issues and to protect and secure our networks and Customer Content. Logs may include access ID, time, authorization granted or denied, diagnostic data such as trace and crash files, and other relevant information and activity.
We collect and use logs (i) for providing, securing, managing, measuring and improving the services, (ii) as requested by customer or its end-users, (iii) for billing, account management, internal reporting, and product strategy, and/or (iv) for compliance with agreements, policies, applicable law, regulation or government request. This may include monitoring the performance, stability, usage and security of the services and related components.
Customers may not block or interfere with this monitoring.
For more information on Customer Content and Log handling, please see Our Trust Center which contains several white papers on Green Parrot Cloud Services Logging.
7.3 Certificate, Credential, and Secret Management
Green Parrot maintains policies that cover the lifecycle of certificates, credentials, and secrets to ensure protection, availability, and confidentiality. Secret custodians must be documented and formally acknowledge that they accept the responsibilities as secret management personnel. Responsibilities include, but are not limited to:
7.3.1 Certificates must be issued by an approved certificate authority
7.3.2 Cryptographic keys may not be stored or transmitted in plain text and must use strong approved cryptographic protocols
7.3.3 Credentials and secrets must be rotated at least once per year and stored in an approved privileged authentication management tool
7.4 Vulnerability Management
We monitor applications and systems for vulnerabilities with automated vulnerability and port scanning on a regular basis.
Vulnerabilities identified are required to be remediated on a timeline that is based on the severity rating and the associated risk along with vendor recommendations. In cases that a patch, update or permanent mitigation is not available, appropriate countermeasures will be used to reduce the risk of exploitation of the vulnerability without undue delay.
8. Encryption
8.1 Protection of Data in Transit
Green Parrot has deployed secure transmission protocols for transmission of information over public networks that are part of the services. The services are protected by encryption and access via the Internet is protected by TLS connections.
8.2 Protection of Data at Rest
We require all workstations used to provide services to utilize full disk encryption. Customer Content may not be stored on any portable device unless it is encrypted.
Some Cloud Services encrypt certain data elements by default and may also provide other encryption features for customers to implement. Please consult the applicable Cloud Services documentation for additional details.
9. Physical Security
9.1 Facilities
We maintain the following controls designed to prevent unauthorized access to any facility:
9.1.1 Facility access is limited to authorized individuals
9.1.2 Visitors are required to register and be escorted or observed at all times
9.1.3 ID badges are required for employees, contractors, and guests and must be visible at all times when in the facility
9.1.4 Security manages and controls after-hours access to facilities
9.1.5 Security guards, intrusion detection, and/or CCTV cameras monitor building entry points, loading and shipping docks, and public access areas – (mechanisms for monitoring access may differ between facilities, depending on the facility and location)
In addition, Green Parrot facilities provide:
1. Fire suppression and fire detection systems or devices
2. Climate control systems or devices (temperature, humidity, etc.)
3. Accessible water master shutoff or isolation valves
4. Emergency exits and evacuation routes
5. Data closets located in offices are protected via badge access.
9.2 Data Centers
In addition to the controls described above, for Green Parrot owned and managed facilities, we implement additional controls at the data centers.
9.2.1 We use systems designed to protect against loss of data due to power supply failure or line interference, including global and redundant service infrastructure that is set up with disaster recovery sites.
9.2.2 Data centers and Internet service providers (ISPs) are evaluated to optimize performance regarding bandwidth, latency and disaster recovery isolation.
9.2.3 Data centers are situated in facilities that are ISP carrier neutral and provide physical security, redundant power, infrastructure redundancy and uptime agreements from key suppliers.
9.2.4 When we use third-party data centers or cloud services for the delivery of the services, we contract providers that meet or exceed the physical and environmental security requirements of our facilities.
10. Business Continuity & Disaster Recovery
10.1 Business Continuity
Green Parrot strategically plans for the continuation of business operations during adverse or disruptive situations, and designs systems to keep the services operational during the occurrence of such events.
For critical businesses, we perform a Business Impact Analysis (BIA) at least every two years, with an annual review each year. The BIA is used to create a departmental Business Continuity Plan (BCP), which identifies and documents for each department its resource requirements, recovery parameters and methods, relocation needs, and the security safeguards required throughout the process to avoid failures or gaps. Senior management of each department reviews and approves the BCP on an annual basis, or as significant organizational changes occur.
We maintain emergency and contingency plans for all of our main facilities. In the event facilities are not available, employees and contractors have the option to work remotely either at other Green Parrot facilities or the location of their choosing. Additional recovery strategies are documented in the BCPs where applicable. Our continuity program aligns with ISO 22301.
10.2 Disaster Recovery
We endeavor to minimize the impact of service or operational disruptions by implementing processes and controls designed to ensure stable and orderly restoration and recovery of our business systems and data. Green Parrot implements redundancy for all mission-critical systems, data, and infrastructure. The Disaster Recovery Plan (DRP) uses the assessment performed in the BIA mentioned above to identify and document recovery time parameters, methods, priorities, and security safeguards required throughout the process to avoid failures or gaps. The plan outlines the overall structure and approach to restoring critical systems and data, including but not limited to:
1. Roles and responsibilities of individuals or teams
2. Contact information for essential personnel or third-parties
3. Training requirements and plans for essential personnel
4. Recovery objectives, restoration priorities, and success metrics
5. Schema of full recovery and restoration
Senior management reviews and approves the DRP on an annual basis, or as significant organizational changes occur.
11. Incident Response
Green Parrot maintains a Cyber Security Incident Response Plan that details the processes for detecting, reporting, identifying, analyzing, and responding to security incidents impacting our managed networks and/or systems or Customer Content. Security Incident response training, and testing takes place at least annually. This is in accordance with NIST 800-61 Revision 2.
“Security Incident” means unauthorized access to Customer Content resulting in the loss of confidentiality, integrity or availability. If we determine that Customer Content within our control has been subject to a security Incident, the customer will be notified within the time period required by law. Our notice will describe, where known, the nature of the incident, the time period, and the potential impact on you. We maintain a record of each Security Incident.
12. Vendor Management
Green Parrot may use subcontractors and agents to perform services. Any subcontractor and agent shall be entitled to access Customer Content only as needed to perform the services and shall be bound by written agreements that require them to provide at least the level of data protection required of us by this exhibit, as applicable. We remain responsible at all times for our subcontractors’ and agents’ compliance within the terms of the agreement, as applicable.
12.1 Onboarding
Our Third-Party Risk Management Program provides a systematic approach to managing security risks posed by the use of third-party suppliers. We work to identify, analyze and mitigate security risks prior to engaging in the procurement of such third parties.
Green Parrot executes agreements with suppliers to document relevant security measures and obligations consistent with those specified in this exhibit.
12.2 Ongoing Assessment
We perform periodic, risk-based security risk assessments designed to ensure security measures remain in place throughout the supplier relationship. Changes to services provided or changes to existing contracts require a security risk assessment to confirm that the changes do not present additional or undue risk.
12.3 Off-boarding
We endeavor to notify the company’s procurement organization at least 90 days prior to the plan to end a supplier relationship or prior to a contract expiration with a supplier (unless earlier termination is required). The company’s procurement organization coordinates the termination of the existing relationships to confirm that our corporate data and assets are secured and properly handled.
13. Compliance
13.1 Treatment of Personal Data
Personal data is information that relates to an identified or identifiable individual. You determine the personal data that is included in the Customer Content. In performing the services, we act as a data processor and you remain the data controller for any personal data contained in Customer Content. We will act on your instructions regarding the processing of such personal data, as specified in the Agreement.
Further information concerning the treatment of personal data subject to the General Data Protection Regulation, including the mechanisms employed for international transfer of such data, is provided in the Green Parrot Data Processing Addendum located in the Trust Center.
13.2 Disclosure of Customer Content
We may disclose Customer Content to the extent required by law, including in response to a subpoena, judicial or administrative order, or other binding instrument (each a “Demand”).
Except where prohibited by law, we will promptly notify you of any Demand and provide you with assistance reasonably necessary for you to respond to the Demand in a timely manner. Further Details can be found within our Law Enforcement Guidelines.
13.3 Customer Security and Regulatory Requirements
The services are designed to be delivered within a larger customer IT environment, and so customers retain full responsibility for all aspects of security not expressly managed by Green Parrot including, but not limited to, technical integration with the services, user access management and controls, and all applications and networks that customers may use in conjunction with the services.
You remain responsible for determining whether your use of the services, including providing us with access to any Customer Content as part of the services, is subject to regulatory or security requirements beyond those specified in the Agreement, including this exhibit.
Customers must therefore ensure that they do not submit or store any Customer Content that is governed by laws that impose specific controls that are not included in this exhibit, which may include US International Traffic in Arms Regulations (ITAR) or similar regulations of any country that restricts import or export of defense articles or defense services, protected health information (“PHI”), payment card information (“PCI”), or controlled-distribution data under government regulations, unless specified in the Agreement and applicable Service Description and the parties have entered into any additional agreements (such as a HIPAA Business Associate Agreement) in advance as may be required for us to process such data.
14. Customer Audits and Inquiries
In response to audit requests, Customers must rely upon Our Due Diligence Package for an updated security package and information. Our Due Diligence Package was created for customer security inquiries and provides readily available security information, including a completed Shared Assessments’ Standardized Information Gathering (SIG) Lite questionnaire for Our Cloud Services. The Due Diligence Package can be downloaded from our Trust Center with an active Non-Disclosure Agreement (NDA).
15. Contacts
Function Contact
Customer Support: https://www.greenparrot.io/trust-center/support
Reporting a Security Incident & Suspected vulnerabilities in our service: Secure@cloud.com
©2025 Green Parrot Collective Pty Ltd All rights reserved. All marks appearing herein are property of Green Parrot Collective Pty Ltd and/or one or more of its subsidiaries and may be registered with the U.S. Patent and Trademark Office and in other countries. All other marks are the property of their respective owner(s).
