{"url_path":"/sec/avai/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-14","source_url":"https://www.sec.gov/Archives/edgar/data/1740797/0001740797-26-000017-index.html","accession_number":"0001740797-26-000017","cik":"0001740797","ticker":"AVAI","issuer_name":"AVAI BIO, INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1740797/0001740797-26-000017-index.html","primary_entity_key":"0001740797","primary_entity_name":"AVAI BIO, INC."},"word_count":297,"has_tables":true,"body_markdown":"**Item 1C. Cybersecurity.**\n\n \n\n**Cybersecurity and Data Privacy Risks**\n\n \n\nWe are subject to cybersecurity and data privacy risks.\nCyberattacks and security vulnerabilities could lead to increased costs, liability claims, or harm to our competitive position.\n\n \n\n**Cybersecurity Risks**\n\n \n\nOur operations and the operations of our and partners\ninvolve the storage, transmission, and processing of third parties’ and our data, including personal, confidential, or proprietary\ninformation. This data is subject to privacy and security laws, regulations, and customer-imposed controls. Cybercriminals use a variety\nof methods to exploit potential vulnerabilities in our systems, products, and services. Sophisticated attacks could result in unauthorized\naccess, loss, misuse, disclosure, modification, or destruction of this data. We are committed to protecting our third parties’ and\nour data. Despite efforts, our systems, products, and services remain vulnerable to attacks.\n\n \n\n**Data Privacy**\n\n \n\nData privacy issues are becoming increasingly significant\ndue to the rapidly changing legal and regulatory landscape. Compliance with global and local data privacy laws requires ongoing investment\nin our information technology and employee training, and will continue to impact our business.\n\n \n\n**Governance and Oversight**\n\n \n\nWe should have a formal risk management program that\naddresses cybersecurity and data privacy risks. This program should include regular reporting to our senior management and Board of Directors,\nwho provide oversight and direction. We have not established an enterprise risk management framework to assess and prioritize these risks.\n\n \n\n**Incident Response**\n\n \n\nWe maintain an incident response plan that includes\npolicies and procedures for notifying affected third parties and complying with applicable laws.\n\n** **\n\n**Investments in Cybersecurity**\n\n \n\nWe will continually invest in our cybersecurity capabilities\nto protect our assets and those of our third parties. This potentially will include investment in advanced threat detection, encryption,\nand other security measures.\n\n \n\n**Recent Cybersecurity Incidents**\n\n \n\nDuring the last fiscal year, we did not experienced\ncybersecurity incidents."}