Security · Stage 1 IP Protection

Emergency Security Response Notice.

A partner notice on Stage 1 IP-Based Network Protection, and the authority to act decisively the moment a credible threat is detected.

Partner Notice Authority Agreement 90-Day Access Baseline

The Moment

When a threat is detected, time is the cost.

Waiting for formal approval during an active incident can materially increase risk. Stage 1 reduces the attack surface, while emergency authority lets ibCom contain genuine threats without delay.

Trusted Locations

Access is gated to known, authorised network locations (IP addresses) instead of the open internet.

Reduced Surface

A smaller, known perimeter that is faster to monitor, contain, and defend.

Rapid Response

Authority to invoke protective controls immediately when seconds matter.

Staged Roadmap

The first layer of a phased move toward identity, device, and cryptographic trust.

// Partner Notice

Important Security Update — Emergency Response & IP-Based Network Protection

Dear Partner,

As cyber security threats continue to increase in both sophistication and frequency, ibCom is implementing additional security controls designed to protect your organisation, your users, and your data.

Across industry and society, organisations are facing a sharp escalation in cyber threats — automated scanning, credential attacks, AI-assisted reconnaissance, supply-chain compromise, denial-of-service campaigns, and other malicious activity now target internet-facing systems at unprecedented scale and speed. In response, ibCom is continuing its phased security hardening program.

Stage 1 Preparation

As part of this program, entityOS has built a Stage 1 IP-Based Network Protection. Rather than allowing unrestricted access from anywhere on the internet, access to entityOS services will increasingly be restricted to trusted and authorised network locations.

To minimise disruption, we have automatically populated an initial authorised network list using IP addresses that have successfully accessed your entityOS based environment during the previous 90 days. This means that locations that have recently and legitimately accessed the system should continue to operate normally without requiring immediate action.

The initial configuration has been established using historical access IP addresses logged over the previous 90 days, and will be refreshed every 4 hours. System administrators can also add, modify, or remove authorised network IP addresses as required.

Registering additional IP addresses

You will be able to register additional IP addresses or network locations at any time. As part of the entityOS security framework, the registration process requires a pre-issued unique security code that has been securely issued to authorised administrators during onboarding. This additional verification step helps ensure that only trusted representatives can modify the approved network locations associated with your organisation.

The portal allows approved administrators to register new office locations, home offices, VPN endpoints, cloud environments, disaster recovery sites, or other trusted network connections as required. We recommend that organisations periodically review their operational locations and register any additional networks that may require future access.

If a security code has been lost, expired, compromised, or requires replacement, please contact ibCom Support. Additional verification may be required before a replacement code is issued.

Why we are doing this

Our responsibility is not only to provide software services, but also to actively protect the systems, data, identities, and communities that rely on the entityOS platform. Traditional security approaches assume that every internet-connected endpoint should be accessible from anywhere in the world. Increasingly, this assumption is no longer appropriate for critical systems and sensitive information.

By restricting access to known and trusted network locations, we significantly reduce the attack surface available to malicious actors while improving our ability to detect, contain, and respond to genuine threats. This approach forms part of our broader security strategy known as "The Moment" — the point at which a credible threat is detected and immediate protective action may be required to safeguard customers, infrastructure, and connected communities.

Emergency security response authority

Enclosed below is an Emergency Security Response Notice Authority Agreement. Its purpose is to ensure ibCom can respond rapidly to active security threats when time-sensitive action is required. In certain circumstances, waiting for formal approval may unnecessarily increase risk to your organisation, other partners, or the broader platform.

The agreement authorises ibCom to invoke emergency protective measures, including Stage 1 IP-Based Network Protection controls and related security responses, when a credible security threat is identified. These powers are intended solely for the protection of customers, infrastructure, data, and connected communities, and will be exercised in good faith and only when reasonably necessary.

Looking ahead

Stage 1 IP-Based Network Protection represents the first phase of a broader security roadmap that will progressively introduce stronger trust, identity, device, and access controls across the entityOS ecosystem. Future phases may include additional verification mechanisms, cryptographic trust controls, device-based authentication, and certificate-based access controls designed to strengthen the security and resilience of the platform.

Our objective is simple: to ensure that trusted people, trusted devices, trusted networks, and trusted communities can continue to operate safely in an increasingly hostile digital environment. If you have any questions regarding this change, please contact ibCom.

Thank you for your continued partnership and support.

Kind regards,

The ibCom Team

ibCom Pty Ltd

Register a network location

Add a trusted IP or network

Authorised administrators can register additional IP addresses at any time. A pre-issued unique security code is required.

https://ip.register.entityos.io

Lost, expired, or compromised code? Contact your ibCom representative — additional verification may be required.

Enclosed Agreement

Emergency Security Response Notice Authority

ibCom Pty Ltd

Emergency Security Response Notice Authority Agreement

Background. This Emergency Security Response Notice Authority Agreement ("Agreement") forms part of the services provided by ibCom Pty Ltd to the Partner.

The Partner acknowledges that modern cyber security threats — including automated attacks, credential compromise, malicious AI-driven activity, supply-chain attacks, denial-of-service attacks, and unauthorised access attempts — may require immediate defensive action to protect Partner systems, data, users, infrastructure, and connected entities. The Partner therefore grants ibCom the authority described in this Agreement.

1

Authority to invoke emergency security controls

The Partner authorises ibCom, at its sole and reasonable discretion, to immediately invoke Emergency Security Controls whenever ibCom reasonably determines that:

  • a security incident is occurring;
  • a security incident is likely to occur;
  • suspicious or anomalous activity is detected;
  • there is a credible threat to Partner systems, data, users, infrastructure, or connected entities;
  • regulatory, legal, contractual, or operational obligations require immediate action; or
  • emergency action is necessary to maintain the integrity, confidentiality, availability, or safety of the entityOS platform.

The Partner acknowledges that emergency action may occur without prior notice or consent.

2

Stage 1 IP protection measures

Without limitation, ibCom may immediately activate or modify Stage 1 IP security controls, including:

  • IP allowlisting and IP blocklisting;
  • geographic network restrictions;
  • AWS WAF security rules;
  • rate limiting and network segmentation;
  • temporary access restrictions and traffic filtering;
  • automated threat mitigation controls; and
  • temporary suspension of access from identified network locations.

ibCom may add, remove, or modify network access rules as required during an emergency response.

3

Service impact

The Partner acknowledges that Emergency Security Controls may interrupt access to services; prevent access from previously authorised locations; require re-registration of network endpoints; require additional authentication steps; delay integrations or API traffic; and temporarily restrict normal business operations.

The Partner agrees that protection of systems and data may take precedence over uninterrupted availability during an emergency response.

4

Notification

Where reasonably practicable, ibCom will notify the Partner of material Emergency Security Controls after activation. However, failure to provide prior or immediate notification does not invalidate the actions taken under this Agreement.

5

Good faith actions

ibCom agrees to exercise this authority in good faith and for legitimate security, safety, compliance, or operational purposes. ibCom will seek to minimise unnecessary disruption while prioritising protection of the Partner, the platform, and other connected entities.

6

Limitation of liability

The Partner acknowledges that delays associated with obtaining consent during an active cyber security incident may materially increase risk.

To the maximum extent permitted by law, the Partner releases and holds harmless ibCom from claims arising from reasonable Emergency Security Controls implemented under this Agreement, except in cases of wilful misconduct or gross negligence.

7

Survival

This authority remains in effect for the duration of the Partner's use of ibCom services and survives any temporary suspension of services.

Acceptance

Automatically authorised as per existing service agreements and clauses relating to protection of customer data.

Trusted people. Trusted devices. Trusted networks.

Protection may take precedence over uninterrupted availability.

Stage 1 is the first layer of a closed-internet roadmap moving toward identity, device, and cryptographic trust.

The Moment is the point at which a credible threat is detected and immediate protective action may be required to safeguard customers, infrastructure, and connected communities.