{"url_path":"/sec/aixn/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C **","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/835662/0001493152-26-023606-index.html","accession_number":"0001493152-26-023606","cik":"0000835662","ticker":"AIXN","issuer_name":"AiXin Life International, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/835662/0001493152-26-023606-index.html","primary_entity_key":"0000835662","primary_entity_name":"AiXin Life International, Inc."},"word_count":390,"has_tables":true,"body_markdown":"**Item\n1C.**\n**Cybersecurity\nPolicy**\n\n \n\nWe\nregularly review our cybersecurity defenses to assess our vulnerability to cybersecurity attacks from viruses, malware and more sophisticated\nand targeted cyber-related attacks such as hackers looking to demand ransomware or access our systems to obtain information and data,\nas well as our vulnerability to cybersecurity failures resulting from human error and technological errors. We rely upon internal IT\npersonnel working in conjunction with specialized outside security consultants on a day to day basis to conduct reviews and upgrade our\nsystems when determined to be necessary.\n\n \n\nOur\noverall strategy in combatting cybersecurity risks includes a variety of measures, including:\n\n \n\n●\nthe\nuse of antivirus software, virtual private networks, email security, as well as other software and system-wide measures such as multi-factor\nauthorization to prevent and detect data intrusions;\n\n \n \n\n●\ndeployment\nof updates and patches as they become available from our software suppliers and consultants and maintaining the current versions\nof major software to reduce the exposure to vulnerabilities;\n\n \n \n\n●\nthe\nuse of third-party services to conduct mandatory online training for all employees regarding identifying and avoiding cyber-security\nrisks;\n\n \n \n\n●\nthe\nreview of the security procedures used by third parties that may host or otherwise have access to our systems;\n\n \n \n\n●\n\nthe\ndeployment of third-party cyber-security experts to perform penetration testing on our internal\nand external networks and systems in an effort to identify potential vulnerabilities; and\n\n \n\nconsideration\nof the cybersecurity risks posed by interacting with current and potential third-party service providers, suppliers and customers.\n\n \n\nWe\nare not aware of any existent weakness in our systems or malware embedded in our systems that are likely to would materially affect,\nor are reasonably likely to materially affect, our operations.\n\n \n\nDay-to\nday management of cybersecurity threats is conducted by our Information Technology department in conjunction with outside service providers,\nwhich is charged with identifying and reporting threats to senior management. On a quarterly basis, cybersecurity is reviewed by our\nChief Executive Officer and Chief Financial Officer, who are expected to report to the Audit Committee.\n\n \n\n**Board\nOversight**\n\n \n\nThe\nAudit Committee of our Board of Directors, which is composed of all non-employee directors, is responsible for oversight of our efforts\nto eliminate cybersecurity risks. The Audit Committee meets regularly with our Chief Executive Officer and Chief Financial Officer and,\nin turn, reports its finding to the Board of Directors.\n\n \n\n31"}