Environmental, Social and Governance (ESG) Report
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Report Preface
About the Report Data Sources
This is the fourth Environmental, Social, and Governance (ESG) Report released by 360 Security Technology Inc. Prepared in The information and data cited in this Report are sourced from of?cial documents and statistical data of 360 Security. We
accordance with the principles of objectivity, standardization, transparency, and completeness, this Report provides a solemnly af?rm that the content of the report is true, accurate, and complete, with no false records or misleading state-
comprehensive disclosure of our practices and performance in environmental protection, social responsibility, and corporate ments, and we take full responsibility for the reliability of the report's content. All data in this report are rounded results, and
governance for the year 2025. individual discrepancies are due to rounding effects.
Publication and Access
Reporting Guidelines
This report is published in electronic format and can be accessed and downloaded from the Shanghai Stock Exchange
Guideline references (http://www.sse.com.cn) or the CNINFO website (www.cninfo.com.cn).
Guidelines No. 14 of Shanghai Stock Exchange for Self-Regulation of Listed Companies — Sustainability Report (Trial) (hereinafter In case of any discrepancy, the Simpli?ed Chinese version shall prevail.
referred to as the Guidelines) issued by the Shanghai Stock Exchange (SSE)
Guidelines No. 4 of Shanghai Stock Exchange for Self-Regulation of Listed Companies — Compilation of Sustainable Development
Reports (January 2026 Revision) issued by the SSE
Regulation references:
Guidelines on Sustainability Reporting for Chinese Enterprises issued by the China Academy of Social Sciences (CASS-ESG 6.0)
Global Reporting Initiative GRI Standards 2021
United Nations Sustainable Development Goals (SDGs) 2030
Sustainability Accounting Standards Board Standards (SASB Standards)
General Requirements for Disclosure of Sustainability-related Financial Information (IFRS S1) and Climate-related Disclosures (IFRS
S2) issued by the International Sustainability Standards Board (ISSB)
Reporting Period
The reporting period of this Report spans from January 1, 2025 to December 31, 2025. To enhance comparability and
completeness, certain contents extend beyond this period.
Report Scope
This report focuses on 360 Security and covers the Company and its wholly-owned subsidiaries and controlled subsidiaries.
Unless otherwise speci?ed, the scope of this report is consistent with that of the Company's consolidated ?nancial state-
ments.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Message from the Chairman
We focus on three main business segments: Internet services, digital security, and smart hardware. By leveraging techno-
Firmly advancing the dual-track “AI + Security” strategy to contribute to logical innovation and practical applications, we have comprehensively covered primary departments and business fronts
the intelligent economy with large model services through 360 Zhinao. We have implemented applications in various scenarios such as browsers,
search, Nano AI, of?ce tools, document libraries, smart hardware, and digital security, contributing to overall business
growth. During the reporting period, we recorded operating revenue of 8.693 billion yuan, representing a year-on-year
The 2026 Government Work Report mentions “intelli- increase of 9.37%. Net pro?t attributable to shareholders of the listed company reached 263 million yuan, re?ecting a
gence” and “security” multiple times, both marking a year-on-year increase of 1.357 billion yuan. We also maintained a high level of R&D investment, with R&D expenses totaling
signi?cant increase compared with the previous year. 3.225 billion yuan, accounting for 37.11% of operating revenue.
For the ?rst time, the report introduced the concept of Guided by our mission to “make the AI world safer and better,” we have deeply integrated ESG principles into our strategy
“new forms of smart economy,” and, in conjunction with and operations, driving sustainable development through technological innovation. As a leading AI-driven digital security
the deepening of the AI Plus Initiative, explicitly called company, we have consistently placed user value at the core and compliance as the foundation, while actively ful?lling our
for accelerating the adoption of next-generation intelli- social responsibilities in safeguarding digital security.
gent terminals and agents, as well as fostering new
forms and models of AI-native business. It also outlined
Environmental responsibility: technolo- We established a ransomware protection system cover-
comprehensive arrangements in areas such as energy,
gy-driven green development ing the full lifecycle of “pre-attack, during attack, and
computing power, and data. These developments
post-attack.” In 2025, we intercepted 1.16 billion
indicate that both “intelligence” and “security” have We have actively responded to China’s “Dual Carbon”
brute-force cyberattacks, protecting over 2 million devic-
been rapidly permeating industries and sectors across strategy by deploying green computing infrastructure
es; and identi?ed 5,565 ransomware incident leads
the board. At present, China’s arti?cial intelligence and building intelligent energy and carbon management
across 48 countries and regions worldwide. We also
industry is gradually forming a coordinated “six-capabil- systems, achieving reductions in greenhouse gas (GHG)
developed an integrated intelligence system covering
ity model” encompassing power, computing power, emissions.
“vulnerabilities–patches–components.” In 2025, we
intelligence, human capital, security capability, and
responded to over 2.8 million vulnerability queries and
productivity, thereby laying a solid foundation for the
issued nearly 12,000 targeted alerts, improving remedia-
implementation of the AI Plus Initiative. National strate-
tion ef?ciency by 40% and effectively safeguarding more
gic priorities and industry trends have presented us Social responsibility: safeguarding the
than 35 million terminals and business systems.
with both a “new test” and a “new blueprint.” We have digital ecosystem with security
consistently adhered to the philosophy of “supporting
small and micro businesses wherever they are,” lever-
We have long been committed to national-level cyberse- Corporate governance: compliance-driv-
curity defense. With over two decades of practical expe- en sustainable development
aging the dual engines of “AI + Security” to safeguard
rience in cyber offense and defense, as well as indus-
the world with security and shape the future with AI,
try-leading threat perception capabilities, we have We have strengthened our corporate governance frame-
contributing our corporate strength to the development
continuously contributed to China’s digital security work by establishing effective mechanisms for checks
of the smart economy and the cultivation of new quali-
defenses. By the end of the reporting period, we had and balances of power and decision-making execution.
ty productive forces.
identi?ed a total of 60 APT organizations, accounting for We have improved internal control and risk management
included state-sponsored hacking organizations such as high-quality development through high-standard gover-
Founder of 360 Group: Zhou Hongyi
the US Central Intelligence Agency (CIA) and National nance.
Security Agency (NSA), revealing their decade-long Looking forward, we will steadfastly advance toward the
in?ltration and cyberattacks targeting China’s critical goals of carbon peaking by 2030 and carbon neutrality
infrastructure, research institutions, and government by 2060, deepen the application of AI technologies in
agencies. both security protection and green transition, and work
together with industry partners to build a secure and
sustainable digital ecosystem.
Contents
Report Preface 01 Report Scope 01
About The Report 01 Data Sources 02
Reporting Guidelines 01 Publication and Access 02
Reporting Period 01 Message from the Chairman 03
COMMITMENT
Company Pro?le 09 Due Diligence and 19
Employees 43 Corporate Governance System 89
Our Corporate Culture 09 Stakeholder Engagement
Safety and Quality Of 53 Remuneration Management 94
Our Business 09 Double Materiality 20
Products and Services Party Building Leadership 94
Our Honors For The Year 15 Assessment
Data Security and Customer 61 Anti-bribery and
Materiality Assessment Results 20
Privacy Protection Anti-corruption 96
Innovation-driven 68 Fight Against Unfair
Development Competition 98
Ethics In Science and Technology 79
ESG GOVERNANCE ENVIRONMENTAL Win-win Cooperation 80
FRAMEWORK COMMITMENT
Rural Revitalization 84
Sustainability 23 Climate Change Response 27 Social Contribution 85
Governance Framework Environmental Compliance Management 35
Sustainability Management 24 Pollutant and Waste Management 35
Mechanisms Energy Consumption 37
ESG Capability Improvement 24 Water Resource Consumption 38
Circular Economy 39
Ecosystem and Biodiversity Conservation 40 Key Performance Table 99 Report Index 101
ABOUT 360 SECURITY
COMPANY PROFILE
OUR CORPORATE CULTURE
OUR BUSINESS
OUR HONORS FOR THE YEAR
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Internet Services Business
Company Pro?le
Our internet business leverages the 360 suite of PC and mobile products as high-ef?ciency traf?c entry points. Driven by our
“the Group”) is a leader in digital security. Guided by our mission of advertising and services; an internet product segment supported by scenario-based products and AI applications; and a
“supporting small and micro businesses wherever they are,” we Nano Al Interface game value-added segment characterized by the operation of PC, web-based, and mobile games. The business effectively
have established a dual development focus on AI and security. We connects business (B-end) clients with consumer (C-end) users. Through diversi?ed models, including intelligent marketing
focus on three main business segments: Internet services, digital upgrades, membership subscription services, and integrated game operations, we continuously deepen traf?c value moneti-
security, and smart hardware. By leveraging technological innova- zation and full-chain commercial value enhancement, forming a well-structured and synergistic internet business ecosystem.
tion and practical applications, we have comprehensively covered
primary departments and business fronts with large model services
through 360 Zhinao. We have implemented applications in various
scenarios such as browsers, search, Nano AI, of?ce tools, document Our commercialization business mainly relies on the full range of 360 PC and mobile products, such as 360
libraries, smart hardware, and digital security, contributing to Browser, 360 Search, 360 Safeguard, 360 Software Manager, and Nano AI as traf?c entry points, monetizing
overall business growth. 360 Wenku Interface traf?c through internet advertising and related services. Meanwhile, we leverage our self-developed 360 Zhinao
large model and 360CV large model to comprehensively promote the intelligent upgrade of the smart business
system. We focus on aspects such as advertising creative generation, user insights, intent recognition, content
Our Corporate Culture adaptation, and conversion funnel optimization, reconstructing the full advertising value chain on the PC side
and establishing a new AI-driven paradigm for end-to-end intelligent marketing.
Commercialization business
Core values Generative Reasoning Learning Multimodal
Large Model Capability Capability Capability Processing Capability
User-?rst mindset, Capabilities Creative headline Generative User behavior & Creative image &
mission-driven approach, & copywriting intent preference understanding video generation
innovation, open collabo-
Corporate mission
ration, and integrity
To make the AI world
safer and better 360 Lingshu 360 Chuangyi
AI-Powered Ad Creatives
AI-powered advertising
data analytics
Intelligent User
Operations
Vision Advertising & Business
Operations
Platform Agents 360 Zhitou
Provide innovative
Multimodal presentation AI-powered
solutions for a safer world
& agent services intelligent ad delivery
Our Business
We closely follow national strategic development needs and continuously practice the dual-track strategy of “AI + Security.”
Upholding the mission of “making the AI world safer and better,” we have deeply advanced the “ALL IN AGENT” planning.
Driven by technological innovation and leveraging our long-standing technological advantages, extensive user base, and
ecological synergies, we ensure stable operations across our major business lines, continuously promoting the digital and
intelligent transformation and upgrading of various operations. These efforts aim to enhance core competitiveness and
actively contribute to the development of the smart economy and new quality productive forces. During the reporting period,
our main business focused on three core segments: Internet services, digital security, and smart hardware.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Our game value-added business primarily covers PC game operations, exclusive agency distribution of
We provide internet product services based on the core functionalities of our existing products, deeply align-
web-based and mobile games, as well as joint operation platforms. In the PC game segment, we focus on
ing with users' diverse needs in high-frequency scenarios such as of?ce collaboration, daily usage, and digital
operating the China-region business of World of Tanks and World of Warships, both developed by Wargaming,
life. By actively integrating AI-driven innovations, we have launched a range of value-added services tailored
leveraging our strong product reputation and re?ned operational capabilities to build a large and loyal user
to these scenarios, generating membership-based subscription revenue. Currently, we have developed a rich
Game value-added services
base. We currently operate nearly 1,000 game products, providing users with a one-stop comprehensive
and diverse product ecosystem matrix, which mainly includes 360 Wenku, 360 AI Of?ce, Nano AI, Nano Comic
service platform that integrates game downloads, content information, and interactive reviews, thereby
Drama Pipeline, and 360 Security Lobster, among other distinctive products and services. This ecosystem
continuously enhancing user experience.
covers various ?elds such as knowledge acquisition, intelligent of?ce, content creation, and intelligent assis-
tants, continuously enhancing user experience and product stickiness.
World of Tanks Graphic
Internet product business
Digital Security Business
We have long been committed to national-level cybersecurity defense. With over two decades of practical experi-
ence in cyber offense and defense, as well as industry-leading threat perception capabilities, we have continuously
contributed to China’s digital security defenses. With 20 years of offensive and defensive practical experience, we
possess domestically leading security threat intelligence data, 1.5 billion terminal user alert data, and a sample
library exceeding 3EB. Built upon national strategic requirements to “see” advanced threats, we have explored the
development of a China-speci?c digital security solution centered “threat visibility.” Currently, we widely serve
government agencies, large enterprises, critical infrastructure operators, and SMEs, providing them with compre-
hensive cybersecurity services. Our main security services and products include overseas APT capture, 360 Security
Cloud, 360 Security Large Model, 360 Large Model Safeguard, and 360 Security Agent Swarm.
Nano AI Interface
Data as a Service (DaaS) Intelligence as a Service
Tools as a 360 Security Cloud Probes as a Service
Service (TaaS)
Experts as a
Service (EaaS) Knowledge as a Service
Cloud-Native Cloud-Native Cloud-Native Cloud-Native
Platform Data Experts Probes
Lightweight
Capabilities as a Service Platform as a Service (PaaS)
Service Probes
Pipeline Interface
Government Regulators Finance Insurance Energy Transportation Education Healthcare Medical Manufacturing ......
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Security Operations Agent Matrix
Empowering 360 Security Third-Party User Self-Built
Products Security Products Systems
Security Products
Operations
Operations
Phishing Email
Analysis Agent
Incident
Investigation &
Policy & Rule
Manage-
Security Risk
Insight
Vulnerability
Manage-
Auxiliary
Operations
Threat
Intelligence
Security Report
Generation
Digital Agent Response Agent ment Agent Agent ment Agent Agent Research Agent Agent
Security
Experts Endpoint Security Local Brain Security Advanced Threat Malicious Email Security Response
Operations Expert Operations Expert Hunting Expert Detection Expert Expert
Agent Framework
Security Digital Expert Expert Role Opening Skill Knowledge Recommended Debugging
Security MCP Service Model Capabilities
creation con?guration script con?guration base selection questions & release
Knowledge Base Toolkit
Local Security Brain
Attack & defense TTPs Skill LLM Function- Knowledge Plugin Judgement Content Orchestration Sample detection tools Alert correlation Incident Log Graph Security Task Orchestration Supervision &
Orchestration Conversation call base search application engine extraction testing & analysis investigation retrieval pro?ling reporting Engine Evaluation Engine
Security Large Models
Kill chain experience library Traf?c reconstruction tools
Local Private knowledge base Intelligence query tools
External Environment Category Interface Interface JDictionary Exception Linkage Situational Analysis Asset Response Assessment
Deployment / ... Plugins con?guration management de?nition authentication management handling testing ... Task Generation Command Scheduling
Awareness Center Center Center Center
Model SaaS Engine Engine
CoE Security Large Model Big Data Security Infrastructure
Language Deepseek Large Qwen Large Other Large
Language translation Text summarization Intent recognition
Hub Data Support Knowledge Correction
Language Model Language Model Language Models
Planning Hub Goal decomposition Ethics Hub Memory Hub Common security Intelligence TTPs (Tactics,Techniques
Knowledge
Alert data Log data Asset data
Security
knowledge data & Procedures) 360 CCoE Security
Data
...... ......
Base
Code generation Analysis & Logical reasoning Sentiment analysis Large Model
Information Vulnerability Account Work order Security Expert Private domain
Cloud detection module module data data data speci?cations experience knowledge
Empowe- Solution planning memory
rment True/False ... Ethics & compliance
Goal decomposition judgement module
Smart Hardware Business
Guided by our brand philosophy of “Smart Security,” we leverage our strong technological foundation to build a smart
hardware portfolio centered on smart cameras, video doorbells, and dash cams, covering diverse application scenari-
Visualization & Display Security Situation Dashboard Workbench Cockpit
os such as home security, smart monitoring, and in-vehicle safety. Currently, we are committed to transforming from
hardware sales to a business model that combines hardware with cloud services, using hardware sales as the
Business Capabilities
Content Security Evaluation Content Security Guardrails foundation for user growth and cloud services and other value-added services as new drivers for business growth.
Guardrail alert Sensitive data Guardrail
Evaluation task Corpus security
(multi-modal detection) protection logs Additionally, we continue to deepen our technological R&D, comprehensively enhancing the AI intelligence level of our
management assessment
Computational Intervention library Risk tag
product line and improving the core competitiveness of our products.
Evaluation Risk data Dataset
report management management cost protection management management
Model evaluation Evaluation vs. guardrail Intelligent Sensitive word Guardrail
& comparison effectiveness comparison protection policies management validation lab
Safe proxy Evaluation & Text moderation Image moderation Audio moderation Video moderation
response model adjudication model model model model model
Business
Engines
Sensitive word Intervention Task scheduling Computational cost Sensitive data
matching engine response engine engine protection engine identi?cation engine
tData
Evaluation Rule & policy Intervention Sensitive Model integration Model asset
Basic
datasets library response library word library con?guration information
=
Two Major Modules on 360 Large Model Safeguard:
Content Security Assessment and Content Security Barriers
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Our Honors for the Year
We were recognized with multiple industry
Nano AI was recognized as a Our project Key Technologies We were recognized as a We won the Leading Technolo- honors, including “Technical Support Unit We were honored with the title
“2025 Typical Case for Techno- and Applications of Large-Scale leading enterprise in Beijing’s gy Innovation Award at the of CNVD,” “Special Contribution Award for of “Model Collective of Beijing”
logical and Industrial Innova- Intelligent Cybersecurity CNVD Collaboration 2024,” “Outstanding
“industry–education–evalua- national ?nals of the AI Pioneer Contribution in Vulnerability Reporting
tion among Private Enterprises” Situational Awareness Monitor- tion” integrated skill ecosystem Cup for our Large Model 2024,” “Outstanding Contribution in
by the All-China Federation of ing Systems won the First Prize for digital and intelligent Safeguard solution Vulnerability Emergency Response 2024,”
Industry and Commerce of the Hainan Provincial Science “ANVA Outstanding Organization
security (Enterprise),” “ANVA Member Unit,” and
and Technology Progress Award “CCTGA Outstanding Member Unit”
We were recognized as an
“Outstanding Support Unit” by
CNTISP
We were awarded the titles of
We were selected among the 360 AI Enterprise Browser was Our 360 Security Services Team The Party Committee of 360 “Outstanding Technical Support
“Top 20 Cybersecurity Compa- included in the 2025 Casebook was awarded the title of Group was recognized as an Unit” and “Technical Support Unit”
nies in China 2025” on Digital and Intelligent Transfor- “Outstanding Team in Annual “Advanced Primary-Level Party by the Industrial Internet of
mation of Enterprise Groups Cyber Attack and Defense Organization” We were recognized as a Vehicles Product Security Vulnera-
released at the Internet Society Exercises” “Three-Star Technical Support Unit” bility Database under the MIIT
of China CAPPVD, and received the “Original
(highest rating) by the CAPPVD
Vulnerability Certi?cate”
Materiality Assessment
DUE DILIGENCE AND STAKEHOLDER ENGAGEMENT
DOUBLE MATERIALITY ASSESSMENT
MATERIALITY ASSESSMENT RESULTS
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Due Diligence and Stakeholder Engagement Double Materiality Assessment
To ensure the comprehensiveness and accuracy of ESG issue identi?cation, we systematically identi?ed six core stakeholder In preparing this report, we conducted ESG issue identi?cation in accordance with
groups based on our industry characteristics, operational realities, and business models. Through due diligence approaches, the SSE Guidelines, while also referencing international sustainability disclosure
including regular and ad hoc interviews, surveys, and thematic communications, we have established normalized communi- standards such as the GRI Standards and the ISSB requirements. We established
cation mechanisms to fully understand stakeholder concerns and feedback, enabling us to create sustainable value in a a structured process for issue identi?cation and materiality assessment, analyz-
more targeted manner. ing ESG issues from both ?nancial materiality and impact materiality perspectives
to identify material issues to the Company and assess their actual and potential
risks and impacts on our operations.
Stakeholder Stakeholder concerns Communication channels We adopted the “double materiality” assessment framework when preparing this
report. This framework comprehensively evaluates each issue from two perspec-
Compliance with laws and regulations tives: ?nancial materiality (i.e., the impact of the topic on the Company's ?nancial
Compliance operations performance) and impact materiality (i.e., the internal and external impacts of the
Fair competition Company's activities on the environment and society). During the assessment
Climate change response Policies and guidelines process, we employed various methods such as online surveys, management
Pollution prevention and control Oversight and inspection workshops, and expert reviews, to collect and analyze stakeholder input. This
Resource Management Visits served as a robust basis for determining the double materiality of ESG issues.
Government and
Energy Consumption Information disclosure
regulatory agencies
Supply chain security
Product and service security
Employee rights and interests
Financial stability
Materiality Assessment Results
Shareholder Meeting
Information transparency
Corporate announcements Based on the results of the materiality assessment and in line with the principle of materiality, we identi?ed key ESG issues
Shareholders Risk management
Investor communication
and investors Innovation-driven development for 2025. These topics were mapped into a materiality matrix according to their impact materiality and ?nancial materiality.
High-quality products and services User feedback channels
Double materiality matrix for 360 Security
User experience Social media engagement
Customers and users Information security and privacy protection User satisfaction surveys
Issues with ?nancial Issues with both
Safety and quality of
signi?cance but no ?nancial and impact
product and service
impact signi?cance signi?cance
Data security and customer
Recruitment Employee training and communication privacy protection
Protection of employee rights and interests Employee care programs Innovation-driven development
Training and development Employee feedback channels
Employees Corporate governance system
Employees Work-life balance Employee satisfaction surveys
Financial materiality
Climate change response
Fair cooperation Supplier management Ethics in science Energy
and technology consumption Mutually bene?cial
Mutual bene?ts Supplier meetings partnerships
Remuneration ESG Governance Framework
Sustainable supply chain Industry events Circular economy management
Water resource
Suppliers and partners Supplier empowerment consumption Anti-bribery and
Technical cooperation
Pollutant and waste management anti-corruption
Social contribution
Ecosystem and biodiversity conservation
Environmental
Environmental protection Strategic cooperation compliance management Party building
Rural revitalization
Public welfare projects Media engagement Issues with neither Issues with impact
?nancial nor impact Anti-unfair competition signi?cance but no
Community and media Corporate social responsibility Community engagement signi?cance Due diligence and ?nancial signi?cance
stakeholder engagement
Impact materiality
ESG Governance
Framework
可持续发展治理架构
可持续发展管理机制
ESG能力提升
SUSTAINABILITY GOVERNANCE FRAMEWORK
SUSTAINABILITY MANAGEMENT MECHANISMS
ESG CAPABILITY IMPROVEMENT
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Sustainability Governance Framework Sustainability Management Mechanisms
To ensure the standardization and ongoing improvement of our ESG performance, we
At 360 Security, we attach great importance to the development of our ESG manage- have established sustainability management mechanisms and integrated them into
ment system. To effectively align ESG strategy with our business operations, and in our daily operations and decision-making processes. These mechanisms have
strict compliance with relevant requirements such as the Guidelines, we have estab- enabled us to effectively mitigate ESG risks.
lished a top-down ESG governance framework with clearly de?ned roles and responsi-
bilities. This framework positions the Board of Directors as the highest decision-making
body, senior management as the coordinating management body, and various
functional departments as speci?c execution units, forming a closed-loop operation Mechanism Speci?c actions
mechanism of “decision-making—management—execution” to ensure that ESG princi-
ples are fully integrated into our corporate strategy and daily operations.
We have established an internal control system related to ESG. On the environmental
front, we have formulated control details regarding energy management, waste
Governance level Organizational body Scope of responsibilities disposal, and other aspects, clarifying the speci?c responsibilities and operational
processes of each department in energy conservation, emissions reduction, and
environmental compliance. On the social front, we have clari?ed the control require-
goals, to ensure their alignment with the Company's long-term and product quality and safety, ensuring effective operations and ful?llment of social
objectives; responsibilities. On the governance front, we have issued management systems
Decision- Board of
making Directors
disclosure of material ESG issues; and ensure ef?cient and standardized internal governance.
ed major risk response plans, etc.
Senior management convenes meetings based on proposals submitted by the ESG
Information reporting Task Force to review ESG matters, with outcomes subsequently reported to the Board
mechanism of Directors.
ny's ESG policy and strategy;
Senior 2. Reviewing the Company's ESG report and the disclosure of
Manage-
Manage- The company incorporates senior management's performance in ful?lling ESG-relat-
ment material ESG issues;and Performance evaluation
ment
response plans, etc.
compliance with approval procedures; ESG Capability Improvement
directives, collecting and organizing data from various We continuously deepen our understanding and implementation of sustainability principles. By
Implem- ESG Task platforms, departments and subsidiaries, and disclosing ESG actively participating in high-level ESG forums and training programs, we have enhanced the
entation Force information to the public; and professional competencies and overall capabilities of our personnel, thereby strengthening our
and regulatory frameworks, aligning ESG practices with the
Company's ESG strategy, managing ESG risks and issues, and Honors and Awards in Sustainability
providing feedback and recommendations, etc.
Wind ESG Rating Upgraded from A to AA
Sino-Securities Index ESG Rating Upgraded from BB to BBB
Environmental Commitment
可持续发展治理架构
CLIMATE CHANGE RESPONSE
可持续发展管理机制
ENVIRONMENTAL
ESG能力提升 COMPLIANCE MANAGEMENT
POLLUTANT AND WASTE MANAGEMENT
ENERGY CONSUMPTION
WATER RESOURCE CONSUMPTION
CIRCULAR ECONOMY
ECOSYSTEM AND BIODIVERSITY CONSERVATION
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Climate Change Response Climate Strategy
Climate Scenario Analysis
Climate-related Governance
At 360 Security, we conducted climate scenario analysis with reference
In response to China’s “Dual Carbon” goals (carbon peaking by 2030 and carbon to the climate scenario models set out in the Sixth Assessment Report
neutrality by 2060), we have established a climate change management system (AR6) of the UN Intergovernmental Panel on Climate Change (IPCC).
led by the Board of Directors to advance our green and low-carbon develop- Taking into account external environmental changes affecting our
ment, while enhancing corporate social responsibility and environmental aware- operations, including ecological, economic, and social factors, we
ness. The ESG Task Force is responsible for implementation, progressively selected two pathways, SSP5-8.5 and SSP1-2.6, to assess potential
integrating climate-related considerations into our corporate management. climate-related risks and opportunities and to formulate corresponding
We recognize the profound impact of climate change on our business operations response strategies. This ensures that our operational strategy align
and value chain. Accordingly, we have incorporated climate-related issues into with the global climate transition.
our overall sustainability framework and established a climate governance
structure with clearly de?ned responsibilities and division of labor. This structure Projected
forms a coordinated three-tier system of “decision-making – management –
Scenario Reference temperature increase Scenario description
execution”: the Board of Directors serves as the leadership and decision-making
body for climate-related matters; senior management provides research,
This scenario is usually described as a future
guidance, and oversight; and the ESG Task Force, composed of ESG coordinators
scenario with high emissions, signi?cant develop-
from headquarters and various business units, is responsible for execution.
ment inequality and strong dependence on fossil
fuels. In this scenario, physical risks are relatively
Climate Governance Framework IPCC’s Shared More than 4°C
high and transition risks are relatively low. Coun-
High-emissions Socioeconomic (relative to
tries have not introduced policies to deal with
scenario Pathways pre-industrial
Responsible for analyzing climate change-related strategies and policies, climate change. Energy demand and GHG
Board of SSP5-8.5 times)
Decision-making providing leadership on climate initiatives, and ensuring alignment with the emissions continue to grow, leading to continued
Directors
Company’s long-term development objectives. warming of the global surface and an increase in
the frequency of extreme climate events and
Responsible for perform climate governance and oversight of climate-re- other phenomena.
lated matters authorized by the Board; providing overall planning and
Senior
Management deployment of climate initiatives; reviewing climate-related targets and This scenario combines a sustainable socioeco-
Management
strategies; and approving assessments of climate-related risks, opportuni- nomic background with a low radiative forcing
ties, and corresponding response measures. climate target. It is often described as a future
IPCC’s Shared Below 2°C path characterized by the synergy between
Low-emissions Socioeconomic (relative to green transition and climate action. In this scenar-
ESG Task Implement climate-related work plans and periodically report work results scenario Pathways pre-industrial io, transition risks are relatively high and physical
Implementation
Force to management. SSP1-2.6 times) risks are relatively low. This scenario aims to
achieve the long-term goals of the Paris Agree-
ment (keeping global temperature rise below 2°C
and working towards limiting it to 1.5°C).
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Climate Risks and Opportunities
Climate Magn- Impact Mitigation Climate Magn- Impact Mitigation
Type risks Description Financial impact Type risks Description Financial impact
itude Horizon measures itude Horizon measures
Disruptions to data centers may In the context of the “Dual
lead to operational downtime, Strengthen early warning Carbon” strategy, failure to
delayed core service responses, and contingency planning keep pace with the transition
Extreme weather events such and reduced customer experience based on meteorological to low-power technologies
as heavy rainfall and and market competitiveness, forecasts to mitigate may weaken the competitive-
heatwaves caused by climate thereby putting pressure on impacts on data center The arti?cial intelligence ness of existing technology Increase R&D investment
Acute Short- safety.
change may disrupt data revenue. Increased emergency and digital security roadmaps, diminish the value in low-carbon technologies
Medium
risks centers and daily operations, repair, operation and maintenance term Establish and continuously industries we operate in of prior R&D investments, and and accelerate technology
(O&M) costs may drive up O&M improve environmental risk are technology-intensive squeeze market share.
Mid- to upgrades.
affecting business continuity Technology
and operational security. costs, consume resources that emergency response plans; sectors, and under the Meanwhile, catching up with Medium long- Strengthen collaboration
would otherwise go to normal conduct regular risk risks dual carbon context, we technological iterations would with universities and
identi?cation, reviews, and term
operations, and put pressure on may face pressure to require additional resources, research institutions to
overall pro?tability. emergency drills. transition toward driving up long-term operating accelerate innovation and
Physical
low-power technologies. costs, increasing the burden application.
risks on corporate resources,
Rising temperatures lead to water
undermining the stability of
scarcity, which intensi?es the
the pro?t model, and
pressure on data center cooling
In 2025, the average Establish emergency Transition constraining future develop-
energy and water consumption,
temperature in China was response mechanisms for risks ment space.
drives up the intensity of energy
and water consumption, adds to
Chronic highest since complete Mid- to optimize data center Failure to reduce product
operational burdens and cost
risks records began in 1951. The cooling ef?ciency. carbon footprint may weaken Incorporate energy
pressures, and squeezes corporate Low long-
rise in temperature will lead Regularly inspect Growing environmental competitiveness, lead to ef?ciency and carbon
pro?t margins. Increased
to water shortages, imposing term municipal water supply Market awareness is driving customer attrition towards reduction into product
investment in equipment upgrades Mid-
higher demands on cooling systems to ensure consumer preference more energy-saving Medium design and production;
and operation and maintenance risks term
and water conservation for adequate backup water toward low-carbon and alternatives, and affect our explore the use of
required to ensure stable system
data centers. resources. energy-ef?cient products revenue stability, market renewable and recyclable
operation will further raise the
share, and long-term growth materials.
threshold for long-term resource
commitment. potential.
With the advancement of Once included in the carbon
carbon neutrality goals, emission trading pilot, enterprises
certain provinces and cities in may face carbon quota
Promote the green transition
Climate Magn- Impact Mitigation
Type opportunities Description Financial impact
China have begun to include constraints. Excess emissions
of data centers and itude Horizon measures
entities such as internet data would require purchasing Mid- to energy-intensive operations
centers in carbon emission additional allowances or investing
Low long- (e.g., the adoption of liquid
trading pilot programs. For in emission reduction projects,
cooling technologies and By leveraging our AI capabili-
example, enterprises in increasing compliance costs, term
procurement of renewable ties, we can seize the window
Beijing with annual carbon raising operational thresholds,
electricity). of opportunity for upgrading
emissions exceeding 5,000 squeezing pro?tability, and
Supported by policies from industrial digitalization to
tons are required to exerting sustained pressure on
and regulations intelligent transformation,
participate. cash ?ow.
Transition Policy promoting AI develop- expand low-carbon digital
transformation service
risks risks If we fail to effectively respond to Technology
ment, the industry is
Mid- to
experiencing unprece- scenarios, and open up new Provide digital and
the expectations of regulators,
Transition opport- dented growth avenues for value growth. By Medium long- low-carbon transition
investors, and the public, we will
enabling the green transition
face reputational risks that could opportu- unities opportunities. Leveraging term solutions for our clients.
our technological of the real economy, we can
We are subject to extensive undermine market trust, nities strengthen business synergies,
scrutiny from regulatory potentially weakening our expertise, we can
accelerate the transition enhance the market reach and
agencies, investors, ESG ?nancing bargaining power and Establish regular stakeholder
Mid- to from digitalization to pro?tability of our core
rating agencies, and the narrowing our funding channels. communication mechanisms
intelligent transforma- businesses, and inject strong
public. If we fail to respond Our brand in?uence and market Medium long- and enhance the quality and
tion. momentum into sustainable
actively and effectively, it competitiveness may also be transparency of ESG
term development.
may affect our ?nancing compromised, which could disclosures.
opportunities and sustainabil- weaken customer loyalty and the
ity performance. foundation for revenue growth,
thereby constraining our strategic Note: The time horizons for assessing risks and opportunities are de?ned as short-term (0–1 year), medium-term (1–5 years), and long-term (over 5 years).
transformation and sustainability
pace, posing potential limitations
on long-term value release.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Climate Impacts, Risks, and Opportunities GHG Reduction Measures
We place strong emphasis on the systematic management of climate-related impacts, risks, and opportunities. Following a At 360 Security, we recognize that the energy intensity of computing infrastructure has a
closed-loop approach of “identi?cation – assessment – response – monitoring – reporting,” we have established a structured material impact on climate change. To support the achievement of our carbon peaking
and science-based management process to ensure that our strategy and operations effectively address climate-related and carbon neutrality goals, we have embedded green and low-carbon principles
challenges and opportunities. throughout the entire lifecycle of data center planning and operations. Actively aligned
with China’s “East Data, West Computing” strategy, we systematically advance GHG
Conduct climate scenario analysis under SSP5-8.5 and emission reductions across two key dimensions: energy mix optimization and computing
Risk SSP1-2.6 pathways to identify climate-related impacts, ef?ciency improvement. In addition, we continue to strengthen internal energy manage-
identi?-
cation list risks, and opportunities under different scenarios, and ment and promote green of?ce practices to reduce energy consumption and emissions.
assess gaps between climate targets and current
Incorporate identi?ed
performance Deployment of green computing power
climate-related risks into Risk
assessment We signed a strategic cooperation agreement with China Mobile (Guizhou) to jointly create a green intelligent
the risk management and
framework and prioritize prioritization computing power hub for the “East Data, West Computing” initiative. Leveraging Guizhou’s abundant clean
Management
them based on severity energy resources (such as hydropower), the project provides low-carbon computing power for high-demand
Process for
scenarios including AI large model training and urban security platforms. By directing computing demand toward
Climate Impacts,
western regions rich in clean energy, we reduce reliance on fossil fuels from the source and signi?cantly lower the
Risks, and
Disclose information carbon intensity per unit of computing power.
Relevant departments Opportunities
on the identi?cation At the same time, we have integrated our proprietary intelligent computing scheduling platform with the green
Climate-
develop targeted risk related and management of computing hub to build an ef?cient infrastructure integrating computing power, algorithms, and data. Through
management and Response disclosure
climate-related risks elastic scheduling and resource pooling technologies, we maximize resource utilization, avoid idle computing
development
response measures, and opportunities waste, and promote centralized and low-carbon computing supply.
formulate mitigation
Monitoring
plans, and submit them and
oversight Senior management reviews key risk indicators
to senior management
and reports signi?cant climate-related risks to
for review
the Board of Directors on an annual basis AI-enabled building energy and carbon management
In 2025, we of?cially launched the Digital Twin-based Energy and Carbon Management Platform, establishing a
Climate Performance Indicators and Targets smart energy and carbon management system covering 230,000 square meters across our Beijing of?ce building
and the Tianjin Innovation Park. The platform integrates digital twin technology, IoT, and AI algorithms to create an
At 360 Security, we actively respond to the strategy of “carbon peaking by 2030 and carbon neutrality by 2060”. In line with
intelligent system covering the entire energy and carbon management lifecycle. It enables real-time monitoring
our corporate development strategy, we have established our “3060” carbon goals, committing to achieve carbon peaking
and autonomous regulation of cooling stations, heating systems, and power distribution systems, transforming
by 2030 and carbon neutrality by 2060.
buildings from “passive spaces” into “active systems.” Through a closed-loop management mechanism of “target
Annual GHG Emissions setting – strategy optimization – real-time monitoring – iterative improvement,” the platform effectively reduces
manual intervention and resource investment. The project was selected as a “2025 Benchmark Case for AI-En-
Indicator 2025 abled Smart Building Innovation,” providing a replicable model for low-carbon intelligent of?ce operations in the
internet sector.
Direct GHG emissions (Scope 1) 255.80 tCO2e
Indirect GHG emissions (Scope 2) 11,686.93 tCO2e
Total GHG emissions 11,942.73 tCO2e
GHG emission intensity 1.37 tCO2e per million yuan in revenue
Note: 1. Direct emissions (Scope 1) include GHG emissions from gasoline, diesel, and natural gas Indirect emissions (Scope 2) include GHG emissions
from purchased electricity.
by the Ministry of Ecology and Environment in December 2025.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Material conservation
Energy conservation
Promote digital of?ce systems, including
electronic approvals, online collaboration, and
Behavioral energy saving: Strictly enforce the principle of “turn off
cloud storage, to reduce paper consumption
lights and equipment when not in use.” Lighting, air conditioning (AC),
from the source.
and electronic devices are switched off promptly after meetings to
Establish “green recycling stations” to collect
prevent unnecessary energy consumption.
and reuse single-sided printed paper for
Precision AC control: Develop seasonal air conditioning operation
internal drafts, enabling resource recycling.
plans, establish temperature control early warning mechanisms, and
Implement the Management Measures for
utilize real-time monitoring data to optimize system performance in the
Low-Value Consumables to standardize equip-
of?ce building. During transitional seasons (e.g., March–May), natural
ment maintenance and usage, strengthen
ventilation is prioritized to reduce VRV system usage.
inspections, and extend equipment lifespan,
Elevator optimization: Implement staggered stop strategies and
tapping into the potential for cost reduction
encourage stair use for ?oors below level 7 during peak hours to reduce
from existing stock.
electricity consumption.
Encourage employees to use reusable cups to
Promotion of green commuting: Encourage employees to embrace
reduce reliance on disposable products.
low-carbon commuting, prioritize the use of new energy vehicles for
business trips, and support the construction of charging station parking
spaces to replace traditional fuel with clean energy, promoting carbon
reduction in business travel. Low-carbon transition of the data center
Adopt energy-ef?cient equipment and optimize cooling systems through natural cooling utilization and dynamic
control strategies to reduce energy consumption and carbon intensity.
Water conservation Deploy dynamic scaling technologies for operational servers, enabling demand-based allocation of computing
resources, meaning scaling up during peak demand and down during off-peak periods, to avoid idle capacity
Install water-saving aerator faucets across of?ce and public areas to and energy waste from the source.
reduce water consumption per use. Retro?t our self-built old data centers with high power usage effectiveness (PUE), gradually phasing out inef?-
Display water-saving signage in key areas such as restrooms and cient facilities and prioritizing the use of professional data centers with lower PUE to reduce energy consumption
pantries to promote conservation awareness and behavioral change per unit of computing power through infrastructure iteration and centralized deployment.
among employees.
Green landscaping for environmental regulation
Regulate temperature and humidity, absorb carbon dioxide, and release oxygen by introducing greenery in
indoor of?ce spaces and outdoor public areas. This reduces reliance on mechanical ventilation and air puri?ca-
tion systems, indirectly lowering overall energy consumption.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Environmental Compliance Management Indicator Source Treatment and emission reduction measures
At 360 Security, we consistently adhere to a green and low-carbon development philosophy and
The kitchen fumes are treated by UV photooxidation equipment and electrostatic
strictly comply with applicable laws and regulations, including the Environmental Protection Law of
?lters. To realize the accurate management and control of the kitchen fumes, we
the People’s Republic of China. We have established clear emergency response procedures and
reserve an online monitoring interface for the fume exhaust ?ue, so as to effectively
accountability mechanisms at all levels, forming a comprehensive and well-de?ned environmental Waste gases Cooking
monitor and control the fume exhaust in real-time in the future.
management system. During the reporting period, we did not experience any major environmental fumes
Return air ?lters in fresh air handling units have been upgraded to ensure ?ltration
incidents, nor were we subject to administrative penalties or criminal liabilities related to environ-
ef?ciency and indoor air quality.
mental issues.
Leveraging a Building Management System (BMS), we implemented systematic control over lighting,
AC, environmental safety, and energy usage. The system monitors energy consumption trends,
Kitchen wastewater is pretreated through a sedimentation tank to remove large
equipment operating conditions, and environmental parameters, enabling automatic anomaly alerts
particles of pollutants and suspended matters, then introduced into an oil-water
and remote regulation, thereby continuously improving energy ef?ciency and operational safety. We
also deployed an intelligent IoT-based environmental safety management system, enabling real-time Domestic isolation device to separate the oil in the wastewater, and then discharged to the
Wastewater
monitoring of temperature and humidity, as well as leak detection alerts. Through data-driven intelli- sewage outdoor grease separation tank.
The domestic sewage of our Beijing of?ce building is discharged to the municipal
gent management, we have effectively reduced environmental risks, enhanced emergency response
sewage treatment plant for secondary utilization.
ef?ciency, and created a healthy and safe working environment for employees.
We conduct regular environmental risk assessments and inspections to minimize environmental impacts.
Currently, potential risks exist in areas such as energy ef?ciency improvement, clean energy utilization, and We ensure that all solid waste complies with national disposal standards, with no
electronic waste management. In response, we have implemented an environmental and energy manage- Non-hazardous incidents of environmental pollution or damage.
ment platform, regularly evaluate energy consumption in of?ce buildings, and carry out targeted energy-sav- waste, with a Waste sorting is implemented through four-category bins with clear signage and
ing initiatives. We have also undertaken low-carbon upgrades of data centers, adopted recyclable materials Solid waste small portion guidance to enhance employee awareness.
and modular design in smart hardware to extend product lifecycles, and promoted the reuse of retired ofhazardous A small portion of hazardous waste, such as used batteries, waste ?uorescent
electronic and of?ce equipment to reduce our environmental impact. waste tubes, used toner cartridges, and waste ink cartridges, is separately collected and
transferred to quali?ed professional agencies for harmless disposal.
Pollutant and Waste Management
As a company operating in a non-heavy-polluting industry, our operations primarily
generate domestic wastewater, kitchen exhaust emissions, and solid waste. We
have established the Management Measures for Solid Waste (Hazardous Waste)
and comply with local regulations such as the Beijing Management Regulation on the
Management of Municipal Solid Waste, while adhering to the 3R principles (Reduce,
Reuse, Recycle) to continuously minimize environmental impacts.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Energy Consumption Key performance in 2025
At 360 Security, we strictly adhere to the Energy Law of the People's Republic of China, the Energy Conservation Law of the People's
Indicator 2025
Republic of China, and other relevant laws and regulations. By establishing a robust energy monitoring and energy-saving
management system, we systematically plan and implement energy ef?ciency improvement measures, actively promote
Diesel consumption 1.22 tons
the adoption of advanced energy-saving technologies, and continuously enhance energy utilization ef?ciency.
Gasoline consumption 8.57 tons
Natural gas consumption 104,475 standard cubic meters
Energy Management Measures
Electricity consumption 22,025.87 MWh
Type Speci?c measures
Total energy consumption 2,860.32 tons of standard coal equivalent (TCE)
Comprehensive energy consumption intensity 0.33 TCE per million yuan in revenue
We actively promote the digitalization of
energy management and empower our Note: The statistical scope includes 14 of?ce locations nationwide, such as our Beijing of?ce building and Tianjin Innovation Park.
carbon management platform with AI,
achieving measurement, automatic collec-
Water Resource Consumption
tion, and real-time monitoring of energy data
from key energy-consuming equipment,
thereby realizing re?ned management across
Carbon management platform
Strengthening energy multiple dimensions including energy alloca- Our water consumption is entirely sourced
monitoring and control tion, energy measurement, energy analysis, from municipal water supply systems, ensur-
and energy early warning. ing stable, compliant, and legally secured
access, with no disputes over water rights or
risks of water scarcity. We strictly comply with
We have deployed intelligent control systems for applicable laws and regulations, including the
fresh air units, Daikin VRV AC systems, and ABB Water Law of the People’s Republic of China and
intelligent lighting systems. These systems enable the National Water Saving Action Plan, while
centralized monitoring and remote control of ventila- actively promoting water conservation aware-
tion, air conditioning, and lighting equipment. Operat- ness and implementing a range of water-sav-
ing parameters and schedules are optimized based ing measures.
on seasons, time periods, and usage scenarios,
achieving precise energy management and low-ener- Intelligent Building Water Resource Management Initiatives
gy operation. Management System (BMS)
Type Speci?c measures
We have upgraded sinks in pantries and restrooms with energy-ef?cient multifunctional
Adoption of We have upgraded the intelligent lighting control system, and replaced the lighting
Water-saving aerator faucets.
energy-saving equipment and motors in the conference area of our Beijing of?ce building with more
renovation We have increased the frequency and scope of inspections for aging equipment: replacing
products energy-ef?cient alternatives.
foot valves and related components in restrooms to prevent continuous water ?ow caused
by equipment deterioration.
Development of We have developed energy-ef?cient, low-carbon data centers by adopting
low-carbon data Our data centers, through the sponge city-based improvement, have integrated low-impact
measures such as waste heat recovery, dynamic energy regulation, high-ef?ciency
Sponge city development technologies such as rooftop greening, rainwater reuse facilities, and perme-
centers cooling systems, and sustainable LID (Low Impact Development) site design.
development able paving. These measures aim to control runoff pollution and mitigate urban ?ooding,
while enabling ef?cient rainwater utilization and improving the water environment.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Key performance in 2025
Ecosystem and Biodiversity Conservation
Indicator 2025年
At 360 Security, we adhere to eco-friendly principles in our business expansion,
Total water resource consumption 139,099 tons deeply integrating digital technology into our ecological protection practices.
Through pilot initiatives such as the “AI + Zoo” smart project, we explore the
Water resource consumption intensity 16.00 tons per million yuan in revenue
application of AI in habitat monitoring and animal welfare management,
promoting the integration of ecological conservation and technological innova-
Note: The statistical scope includes 14 of?ce locations nationwide, such as 360 Beijing of?ce building and Tianjin Innovation Park.
tion. By enabling precise monitoring of natural resource dynamics, we support
sustainable resource utilization and safeguard ecosystem integrity and stabili-
Circular Economy ty. Meanwhile, we leverage internet platforms to promote biodiversity aware-
ness, enhance public understanding, and mobilize broader societal participa-
We strictly comply with relevant laws and regulations, including the Circular Economy Promotion Law of the People’s Republic of
tion in ecological conservation.
China, the Green Packaging Evaluation Methods and Rules, and the Opinions on Accelerating the Establishment of a Green Production
and Consumption Legal and Policy Framework. We continue to develop a circular economy model aimed at building a In terms of biodiversity conservation, we not only focus on species diversity but also emphasize the conservation and utilization
resource-ef?cient and environmentally friendly enterprise, promoting ef?cient resource utilization and waste reduction at of biological genetic resources to ensure the sustainability of biological resources. We incorporate the ecological impact of
the source. products throughout their lifecycle into our management framework and continuously explore environmentally friendly product
development to reduce the environmental footprint of both our operations and products.
Circular Economy Management Initiatives
Type Speci?c measures
Case:
In May 2025, 360 Group, in collaboration with Wuhan Zero Point Technology, formed a special research team to
At the smart hardware design stage, we actively integrate circular economy principles
Green design conduct ?eld investigations and strategic cooperation discussions at the Nanning Zoo. Together, we explored a
by adopting recyclable materials and modular designs to extend product lifecycles.
smart upgrade solution under the “AI + Zoo” initiative. The project aims to enhance habitat monitoring capabili-
ties, optimize animal welfare management, and establish a China–ASEAN smart zoo demonstration zone
powered by arti?cial intelligence. This collaboration represents a practical exploration of applying AI technolo-
Of?ce equipment upgrade We extend the lifecycle of servers and other of?ce equipment through upgrades and
gies to biodiversity conservation, demonstrating our commitment to leveraging technological innovation to
and renovation refurbishment, enabling reuse of retired electronic devices.
support ecological protection.
Electronics Employees are allowed to purchase used electronic devices from the Company, such
buyback program as computers, after their service life, reducing electronic waste generation.
Retired but usable materials (e.g., lighting ?xtures and batteries) are repurposed in
Reuse of other
other scenarios where feasible. Of?ce paper and packaging materials are incorporat-
materials
ed into recycling systems to promote resource circulation.
Social Commitment
可持续发展治理架构
EMPLOYEES
可持续发展管理机制
SAFETY
ESG能力提升 AND QUALITY OF PRODUCTS AND SERVICES
DATA SECURITY AND CUSTOMER PRIVACY PROTECTION
INNOVATION-DRIVEN DEVELOPMENT
ETHICS IN SCIENCE AND TECHNOLOGY
WIN-WIN COOPERATION
RURAL REVITALIZATION
SOCIAL CONTRIBUTION
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Employees
Impact, Risk and Opportunity Management
Four Corners Analysis of Employees
Taking into account our development stage and industry characteristics, potential risks in the
Governance Risk and human resources domain are primarily associated with key talent attrition, labor law compli-
opportunity
ance, organizational effectiveness, employee health and safety, and diversity and inclusion
We strictly adhere to the Labor Law of the People's Republic of China, the Labor Contract Law of the People's Republic of China, the practices. We apply a combination of quantitative indicators, such as turnover rates, number of
Law of the People's Republic of China on the Protection of Rights and Interests of Women, and the Provisions on Prohibition of Child identi?cation and labor disputes, and employee satisfaction levels, to systematically assess the impact of these
Labor, and all mandatory labor standards in the jurisdictions where we operate. We have established a systematic human assessment risks on organizational stability, operational ef?ciency, legal compliance, and corporate reputa-
resource management system covering the entire employee lifecycle, including recruitment, performance management, tion. These risks are incorporated into our ESG priority risk management framework.
career development, compensation and bene?ts, and labor relations. By continuously optimizing institutional design and
standardizing processes, we foster a fair, transparent, and ef?cient employment environment. While empowering employ- Aligned with our operational realities, we have established a full-lifecycle human resources risk
ees’ professional growth, we have also provided a solid talent foundation and organizational support for our long-term Monitoring and monitoring system covering recruitment, employment, and exit stages. Through regular employ-
management
ee surveys and other mechanisms, we dynamically track key indicators such as talent mobility,
sustainable development.
labor relations, workplace safety, and training effectiveness, supported by trend analysis. A risk
of risks and early warning mechanism has been implemented with de?ned thresholds to promptly identify
Strategy
opportunities abnormal ?uctuations or potential non-compliance, providing decision-making support to
management and enabling proactive risk mitigation.
Risk/Oppor- Financial Magn- Impact Response
tunity type Description impact itude horizon measures
We adopt differentiated management strategies based on the nature and severity of risks:
Failure to strictly comply with We establish and continuously improve
Mitigate key talent attrition risks through retention incentives, talent pipeline development, and
Labor disputes or
the Labor Law of the People's administrative penalties internal labor compliance systems and structured knowledge management systems;
Response and
Republic of China, the Labor due to non-compliance in standardized procedures to ensure full
compliance across recruitment, contracts,
Mitigate and manage legal and regulatory compliance risks through institutional frameworks,
Contract Law of the People's labor management will
standardized processes, and continuous training;
mitigation
Republic of China, and other signi?cantly increase our compensation, working hours, and termina-
Legal relevant laws and regulations in direct economic costs, tion. On this basis, we conduct regular legal
Short- Address employee health and safety risks by improving protective facilities, strengthening
measures
labor management directly erode current operating Medium training for HR personnel, proactively identify
risks term
leads to the risk of labor dispute pro?ts, and may raise and mitigate risks, systematically identify safety culture, and establishing emergency response mechanisms;
litigation and administrative subsequent compliance employment risks, and achieve both ex-ante
?nes, with serious cases prevention and in-process monitoring. We
Mitigate organizational structure and ef?ciency risks through process optimization, adoption of
management
potentially resulting in criminal investments, creating also implement internal dispute mediation digital tools, and ?exible organizational design.
liability and damaging our ongoing pressure on mechanisms to resolve issues ef?ciently and
brand image as an employer. ?nancial conditions. safeguard employees’ rights and interests.
The loss of core technical
talent may weaken R&D Indicators and Targets
Intensifying industry stability, slow product We strengthen our intellectual property (IP)
competition may lead to the iteration, hinder management system, enhance con?dentiality
Technology loss of key technical technological advance- Mid- mechanisms for core technologies, and
personnel, potentially ment, and reduce market High to long- establish competitive incentive schemes and
risks affecting product develop- responsiveness, thereby term a supportive talent development environment
Targets Progress in 2025
ment and technological undermining product to retain key personnel and ensure continu-
upgrades. competitiveness, market ous innovation.
opportunities, and 100% social insurance coverage for employees Completed
long-term value creation.
No major safety incidents Completed
AI-driven transformation
may disrupt workforce
Rapid AI-driven technological structure, impacting
evolution may create We organize internal AI competitions and
team stability and training programs to encourage employees to
Recruitment
structural pressures on operational ef?ciency,
traditional roles, leading to Short- learn and apply AI technologies. These
weakening coordination Medium
Market risks skill mismatches or job term initiatives provide opportunities for skill
between R&D and enhancement and career development,
displacement, which may operations, and
affect employee morale and enabling employees to transition from
organizational stability.
potentially affecting repetitive tasks to higher-value roles. Standardized Employment
value creation, long-term
corporate resilience, and
talent competitiveness. We uphold principles of fairness and transparency in our recruitment and hiring
We regard diversity, equity, and inclusion as processes. In accordance with our recruitment management policies, we formulate
our core values, establishing anti-discrimina-
This approach enhances tion policies and codes of conduct to solidify annual hiring plans and standardize end-to-end recruitment procedures to ensure full
innovation capacity and our cultural foundation at the institutional
By fostering a diverse and collaboration ef?ciency, compliance with fair employment laws and regulations. We advocate diversity and
level. We actively eliminate biases in
inclusive organizational improves talent recruitment, promotion, and leadership
culture, we enhance utilization and organiza- equal opportunity, strictly prohibit all forms of discrimination, and oppose forced labor,
Operational employees’ sense of Long- development processes to ensure fair
tional effectiveness, opportunities, and enhanced understanding abuse, and harassment. A rigorous age veri?cation mechanism is implemented during
Medium term
opportunities belonging and well-being, reduces resource loss and strengthened belonging through the
thereby unlocking innovation due to turnover or establishment of diverse employee resource recruitment to ensure that no individuals below the legal working age are employed. In
potential to support miscommunication, and groups and open communication platforms.
sustainable development. strengthens long-term 2025, with no incidents involving child labor, forced labor, or discrimination.
Additionally, we effectively enhance
competitiveness and employee well-being through tailored
value creation resilience. bene?ts, mental health support, and ?exible
work arrangements.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
In addition to established recruitment platforms, we actively promote an internal talent referral mechanism, encouraging Employee Compensation and Bene?ts
employees to recommend high-quality candidates and fostering a diversi?ed and collaborative talent acquisition ecosystem.
Our recruitment channels include online platforms (of?cial website, social media accounts such as Xiaohongshu), campus Compensation System
recruitment, on-site job fairs, headhunting services, university–enterprise partnerships, and internal referrals.
Following a philosophy that ensures internal equity and external competitiveness, our compensation model is built on position
value, performance contribution, and long-term incentives. Through a scienti?c job evaluation system, we align position value levels
with career development pathways, clearly de?ning compensation structures and salary ranges for each role. Employee compen-
sation is determined based on a comprehensive assessment of performance, contribution, capabilities, and competencies.
We conduct annual compensation reviews and dynamically adjust compensation based on factors such as corporate performance,
operational conditions, individual annual performance, cost-of-living indices, and market trends. Employees who have concerns
regarding performance evaluations may communicate with their supervisors or utilize formal grievance procedures to safeguard
their rights and interests.
Campus Campus Bene?ts System
Online Recruitment Channels Recruitment Presentation
Posters Posters
We provide a multi-tiered and personalized bene?ts framework to continuously enhance overall competitiveness and employee
satisfaction.
Diversity Composition
Statutory bene?ts Leave bene?ts
Diversity and inclusion are critical to building a strong and resilient workforce. We are committed to fostering an inclusive work-
place that transcends boundaries of gender, age, nationality, race, and other dimensions, providing equal opportunities and an We fully contribute to social insurance and housing We strictly adhere to the standard working hours stipulated
open environment for the growth and development of all employees. provident funds (“?ve insurances and one housing fund”) for by labor laws to ensure a balance between work and life for
all employees. our employees. We fully implement vacation bene?ts: In
We are dedicated to building a fair, just, safe, inclusive, and friendly work environment. We strictly adhere to non-discrimination
During the reporting period, our social insurance coverage addition to public holidays and statutory holidays, employ-
principles and do not differentiate based on nationality, race, gender, age, religious belief, or cultural background. We fully rate reached 100%. ees also enjoy paid annual leave as well as paid leave for
implement gender equality across areas such as equal pay for equal work, career development, and employee participation. marriage, bereavement, maternity, and childcare.
Workforce Composition Medical bene?ts
Care grants
We provide employees with personal accident insurance,
By academic quali?cation: Total number critical illness insurance, supplementary medical insurance
Employees may apply for care grants in life events such as
of employees for outpatient and inpatient care, supplementary maternity
marriage, childbirth, hospitalization, or the passing of
Number of employees with 1,068 insurance for female employees, and supplementary
master's degrees or higher By position 5,273 medical coverage for employees’ children.
immediate family members.
Number of employees with 3,561
Number of R&D personnel 3,018
bachelor's degrees Regular health check-ups Festive bene?ts
Number of salespeople 1,759
Number of employees with 542
Number of management personnel We organize annual health examinations for all employees.
associate degrees In 2025, 100% of employees received health check-up Spring Festival, we prepare exclusive surprises for employ-
services. ees.
Number of employees
with other degrees 102
Team building Employee engagement activities
To enhance communication, cohesion and coordination, we We regularly organize a wide range of interactive and
provide standardized team-building budgets, allowing recreational activities to enrich employees’ work experi-
teams to organize activities that promote collaboration and ence.
engagement.
Service awards
Other bene?ts
Employees who reach tenure milestones receive custom-
Complimentary meals (including late-night meals), ?tness ized recognition awards (currently at 5-year and 10-year
facilities, shuttle bus services, and group wedding ceremo- milestones) in appreciation of their long-term contributions.
nies.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Democratic communication
Employee Satisfaction
We strictly comply with applicable laws and regulations, including the Trade Union Law of the
People’s Republic of China and the Provisions on Democratic Management of Enterprises. We have At 360 Security, we have established a regular employee feedback research
established a democratic management system centered on the Employee Representative mechanism to capture employee needs and expectations. Through surveys,
Congress and supported by trade union organizations. Through multiple channels, such as focus group discussions, and other engagement formats, we collect feedback
Employee Representative Congress meetings, staff meetings, suggestion boxes, and employee across various management areas, including IT support, HR services, and
satisfaction surveys, we ensure employees’ rights to information, participation, expression, and administrative services. Survey results are analyzed and discussed in a timely
supervision. manner, enabling us to address identi?ed issues, continuously improve
employee satisfaction, and re?ne management strategies. This process
supports the shared growth and long-term development of both the Compa-
Democratic Communication Mechanism ny and our employees.
We hold regular Employee Representative Congress meetings to deliberate on major
corporate decisions such as the formulation and revision of rules and regulations and
welfare distribution plans, ensuring employees' rights to be informed, to participate, to
Employee express their views, and to exercise oversight.
Representative
Congress mechanism
To ensure effective communication, we have established multiple accessible channels,
including reporting and grievance email systems. Employees who are not satis?ed with the
Employee Satisfaction Survey Poster
handling outcomes by functional departments may escalate their concerns by submitting
feedback directly to the CEO via email. All grievances are addressed in a timely and impar-
Employee Care and Support
Grievance channel tial manner, and outcomes are communicated appropriately to ensure transparency and
improvement effectiveness.
Guided by a people-oriented philosophy, we are committed to creating a supportive and ful?lling workplace environment that
fosters both professional and personal well-being. We continuously carry out “Employee Home” initiatives, with a focus on
balancing employees’ work and personal lives, as well as supporting mental health. We provide targeted assistance to employ-
Labor Disputes ees facing special dif?culties or belonging to vulnerable groups.
In accordance with the Regulations of the People’s Republic of China on Settlement of Labor Disputes in Enterprises and the Rules on
the Organization and Operation of Labor Dispute Mediation Committees in Enterprises, we have established the 360 Group Labor
Dispute Mediation System and set up a dedicated Labor Dispute Mediation Committee. The committee is responsible for the
prevention and resolution of labor disputes, aiming to address con?icts at an early stage and ensure that disputes are handled
promptly, lawfully, and appropriately.
Health Consultation and Treatment Nursing room
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Employee Training and Development Key performance in 2025
Employee Training General staff training participation rate 100%
We place talent development at the core of our strategy and
continuously enhance our internal training system. Based on job
competency requirements and career development needs, we
provide a structured, multi-tiered, and diversi?ed training frame-
work to support employee growth and enable high-quality corpo-
rate development.
Employee Promotion
Leadership training
We have established a standardized position and job grading system and developed a “dual-track” career development
system. Based on business characteristics and job attributes. This framework is designed to support employees with
We continuously iterate our Star Up Certi?cation System and advanced courses, diverse skill sets and career aspirations, forming a comprehensive and well-structured promotion system.
optimizing evaluation methods to ensure more scienti?c and accurate assess-
ments of managerial capabilities. During the reporting period, we delivered
customized training sessions aligned with business needs, focusing on practical
application and problem-solving. Vertical career development
Horizontal career development
To encourage continuous professional growth,
employees may advance within their respective
To fully tap into employees' strengths and maxi-
career tracks, either the management track (M) or
Professional skills training mize each individual's value, the company has
the specialist track (S).
established horizontal development mechanisms
Management promotions are primarily based on both between the management and specialist
performance contribution, combined with a tracks and within specialist sub-disciplines,
Through regular “Tech Talk” sessions, we have established a cross-departmen-
comprehensive evaluation of leadership capabil- providing pathways for employees to transition
tal and cross-level knowledge-sharing platform. Internal and external experts,
ities, development potential, and alignment with between the M/S tracks.
as well as business leaders, are invited to share insights on cutting-edge
the Company’s core values, ensuring the overall
technologies and practical experience.
quality of the management team.
Specialist promotions are also performance-driv-
en, with a strong emphasis on professional
expertise and technical capabilities, while taking
into account alignment with the Company’s
cultural values.
General skills training
In addition to standardized onboarding programs
for new hires, we organized “Planet Gas” training
sessions. We also hosted internal AGENT compe-
titions, adopting a systematic and practice-ori-
ented approach to enhance employees’ capabili-
ties in AI-powered of?ce applications and innova-
tion.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Occupational Health and Safety
Occupational Health Management
We strictly comply with applicable laws and regulations, including the Law of the People's Republic of China on Prevention and
Control of Occupational Diseases, and continuously improve our standardized occupational health management processes to
enhance overall management effectiveness and safeguard employee well-being. We place strong emphasis on employee
health and have established dedicated health management rooms. Employees are entitled to free consultations upon
presenting their employee ID cards, where professional health advisors provide medical guidance and necessary basic
medications.
Key performance in 2025
Investment in work-related injury insurance Employee work injury insurance coverage rate
Over 4,000,000 yuan 100%
Fire Drill in 2025 Safety Awareness Poster
Key performance in 2025
Safety drill coverage rate
Safe Operations 100%
We strictly comply with relevant laws and regulations, including the Emergency Response Law of the People’s Republic of China
and the Measures for the Emergency Administration of Environmental Contingencies. We have developed internal management
rules such as the Emergency Plan for Work Safety Accidents, the Warehouse Safety Management System, the Crisis Management
Mechanism for Abnormal Visitors, the Accident Risk Identi?cation and Assessment Report, and the Emergency Plan for Food Safety in
the 360 Restaurant. We have also set up a dedicated Emergency Command Center for Work Safety, which de?nes key safety
priorities and clari?es accountability across all levels, ensuring a safe and healthy working environment. Our emergency
response plans clearly categorize incident types and establish a three-tier response mechanism, ensuring that emergency
environmental incidents are handled in a compliant manner. In addition, we conduct regular safety risk assessments and
hazard identi?cation inspections to minimize the likelihood and impact of safety incidents.
Emergency Organizational Structure
Emergency Rescue Command Department
Emergency Of?ce On-site Command Division
Rescue Security and Logistics Support Medical Treatment Technical Support
Team Guard Team Team Team Team
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Safety and Quality of Products and Services Strategy
Risk/Oppor- Magni- Impact
Description Financial impact Response measures
tunity type tude horizon
Four Corners Analysis of Product and Service Safety and Quality
We propose a dual-track
Governance Failure to effectively
As large model governance strategy of “exter-
manage these risks may
technologies rapidly nal security and platform-native
We have established a systematic product and service quality management framework, clearly de?ning roles and responsi- undermine customer
penetrate key sectors security” and launched the 360
bilities, standardizing processes, and embedding continuous improvement requirements. This ensures that the entire lifecy- trust, disrupt partnerships
such as government, Security Agent to build an
in key sectors, and
cle from R&D to delivery and after-sales service is controllable and reliable, providing a solid foundation for product safety ?nance, and energy, AI-native security protection
weaken market penetra-
and customer trust. During the reporting period, we recorded no major quality incidents. they face ?ve major Mid- to system. In practical applica-
Compliance tion. In addition, incident
security risks: long- tions, it has been deployed in
risks response and compliance High
We maintain a customer service team composed of several hundred professionals, providing user infrastructure security, term scenarios such as APT attack
Organizational remediation may
support across multiple business areas, including software technical support, hardware pre-sales and content security, data tracing, security operations, and
structure consume signi?cant
after-sales consulting, gaming services, and advertising sales. and knowledge base vulnerability protection, playing
management resources
security, agent an important role in tracing
and increase operational
security, and endpoint cyberattacks during the Asian
We have developed and continuously updated internal policies such as the User Experience White Paper, costs, constraining
Policy security. Winter Games and hacker
the User Service White Paper, and the User Operations White Paper. During the reporting period, our subsidi- long-term value creation.
framework attacks in Taiwan.
ary, 360 Fang Cloud (Hangzhou) Technology Co., Ltd., successfully obtained ISO 9001 Quality Manage-
ment System certi?cation. Our “360 Large Model Safeguard” passed comprehensive testing by the If the service experience is
National Cybersecurity Product Quality Supervision and Testing Center (Third Research Institute of the poor and user churn
Ministry of Public Security), and was awarded the Enhanced-Level Certi?cation for Large Model Security increases, it will weaken
critical period of queues, introduce AI-assisted
Evaluation Systems. the acceptance of new
transformation from online customer service;
products in the market,
traditional internet establish service response time
raise customer acquisition
services to a dual-driv- commitments; and strengthen
and retention costs, affect
Service en model of 'AI + frontline authorization and
the penetration capability Medium Short-
security', and the problem-solving capabilities
experience of core business, restrict term
competition in the AI through dedicated complaint
and the optimization of
new product market is handling specialists and
customer revenue structure and the
intense. Poor service enhanced training.
complaint release of growth poten-
experience may lead
tial, thereby posing
risks consumers to switch to
challenges to the pace of
other products and
strategic transformation
services.
and long-term competi-
Large Model Security Protection National Information Security tiveness.
ISO 9001 QualityManagement Cybersecurity Product
Barrier Capability Veri?cation Service Quali?cation—Level 3 in
System Certi?cation Certi?cation Certi?cate Security Engineering Certi?cate Favorable policies expand
market opportunities for
AI technology and security Leveraging our proprietary large
In October 2025, the
We have established a full lifecycle quality assurance system to deliver more insightful, applications, accelerate model capabilities, we imple-
Operational revised Cybersecurity
re?ned, and ef?cient service support: the penetration of our ment the dual-track “AI +
processes Law introduced
core technologies into key Security” strategy, committed to
During the initial stages of product development and launch, we conduct internal testing and provisions supporting
industries, expand new empowering the digital transfor-
public beta programs to fully capture user needs, carry out dedicated user experience initia- Policy AI development and Mid- to
business growth drivers, mation of all industries with AI.
secure applications.
tives, and accelerate product iteration; opport- enhance the market High long- Our 360 Security Agent has
The 15th Five-Year Plan
During the growth and maturity phases, we continuously monitor user feedback in real time, unities coverage and value term been deployed across 18 sectors
suggests elevating the
ensure smooth access to service channels (400 hotline, online support, email), and conduct contribution of core such as government affairs,
comprehensive
products, and strengthen energy, and ?nance to build
comprehensive analysis to identify trends and emerging issues; implementation of the
the resilience and sustain- next-generation intelligent
Throughout the entire product lifecycle, product issues that affect user experience are followed AI Plus Initiative to a
ability of the pro?t security systems.
up with a closed-loop process. Standard procedures for each stage, including problem discov- national strategy.
structure, injecting strong
ery, reporting, resolution, veri?cation, and post-mortem review, are clearly de?ned. Issues are momentum for the release
classi?ed, managed, and addressed by priority level. of long-term value.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Impact, Risk and Opportunity Management
Product Quality Management
Risk and opportunity identi?cation and assessment
We regard product quality as the cornerstone of our business. We have built a comprehensive quality management system
We have developed an “APP Full Lifecycle Security Management Platform,” embedding automated security tools into aligned with our “AI + Security” strategy, covering product R&D, large model applications, and end-to-end security protection.
R&D systems to establish a comprehensive risk identi?cation framework across secure coding, reinforcement, testing,
operations, and component management. Currently, the security management platform has been applied to APP
product security management within the Group and its subsidiaries, serving multiple business lines. Technology-driven quality enhancement
In November 2025, we released the White Paper on Large Model Security, which systematically summarized the ?ve key
risk categories faced by large model operations for the ?rst time: infrastructure, content, data and knowledge base, We continuously deepen the “ALL IN AGENT” strategy, leveraging our proprietary trillion-parameter large model 360
agent, and endpoint security. Zhinao to enable AI transformation across our product portfolio. In 2025, the latest model 360 Zhinao 3-o1.5 achieved
strong performance in third-party benchmark evaluations.
At the application level, we launched the country's ?rst Super Search Agent—the Nano AI Super Search Agent, capa-
ble of end-to-end automation, including “understanding intent—automated process planning—automated task
decomposition—autonomous tool invocation—automated execution—delivering results,” supporting multimodal
Risk monitoring and early warning mechanism
search input and multi-format result output.
During security operations, the platform integrates external vulnerability databases and threat intelligence to
enhance emergency response capabilities, supported by large-scale device monitoring and big data security analytics
for real-time threat detection.
In 2025, we launched the 360 Security Agent, using the 360 Security Large Model as its brain. Through capabilities Large model security assurance
such as task orchestration, command scheduling, and memory storage, we have developed over 100 expert-level
agents in the security ?eld, with a focus on core security scenarios such as automated threat hunting, in-depth analy-
sis and judgment, and threat attack tracing, achieving 24/7 automated monitoring. In response to risks such as content safety, privacy leakage, and mislead-
ing hallucinations during the application of large models, we independent-
ly developed the large model security guard product solution 360 Shield,
which ?rst proposed the concept of “model-controlling-model”—using the
Risk response and mitigation mechanism capabilities of large models to ensure the security of the large models
themselves. The 360 Shield features a multi-layer content guard system
With the security management platform, we implement a closed-loop vulnerability management system covering
consisting of “input risk identi?cation—large model processing for secure
detection, response, and remediation, supported by vulnerability intelligence subscriptions, crowdsourced testing,
response—secondary output detection.”In 2025, 360 Shield was selected
emergency response, and patch deployment services to minimize vulnerability threats.
in the 2024 Outstanding Typical Case for Innovation Development in the Future
Based on the dual-track governance strategy of “bolt-on security + platform-native security” proposed in the White
Industry by the Ministry of Industry and Information Technology, becoming
Paper on Large Model Security, the Company has built a full-chain security defense line: bolt-on security enables
a landmark product in the ?eld of arti?cial intelligence security.
real-time monitoring and active defense of computing hosts, software ecosystems, and input-output content through
“model-to-model governance.” Platform-native security deeply embeds security capabilities into the core components
of large models, solidifying the security foundation from the root.
Emergency response and vulnerability governance: we have established the core strategy of “supervising AI with AI,
and governing Skill with Skill.” The 360 Security Cloud team exclusively discovered the high-risk vulnerability (0Day)
AI empowering security product quality
of OpenClaw Gateway WebSocket with no authentication upgrade, promptly assisting in cutting off the risk source
across the network, and received of?cial email con?rmation from the founder of OpenClaw.
In the ?eld of digital security, we launched the 360 Security Agent, using the 360 Security Large Model as the brain,
and built over 100 expert-level intelligent agents in core scenarios such as automated threat hunting, deep analysis
Indicators and Targets and judgment, and threat attack tracing, supporting enterprises in achieving 24/7 automated, low-cost, high-precision
intelligent protection. At period end, we had identi?ed a total of 60 APT organizations, accounting for 98% of the
national total. In June 2025, we collaborated with the CNVD and other institutions to successfully identify the Informa-
Target Progress in 2025 tion, Communications and Electronic Force Command (ICEFCOM) of the Taiwan Democratic Progressive Party as the
source of cyber attacks, jointly releasing an investigation report that demonstrated our technical strength in nation-
No major quality incidents Completed al-level cybersecurity defense.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Service delivery quality management Customer Complaint Handling Process
We actively participated in the development of industry standards. In June 2025, the technical speci?cation General Product Team Customer Service / Operations Manager / VP
Capability Requirements for Large Model Application Delivery Vendors, led by the CAICT and involving 360 and companies,
was of?cially released. It clari?ed the overall capability requirements for large model application delivery vendors in
four aspects: basic capabilities, large model service capabilities, industry practice capabilities, and project quality and
risk management capabilities. In terms of commercialization, the 360 Security Large Model has been implemented in Understand user questions and needs
industries, including government affairs, energy, and ?nance, completing testing and application in the real environ-
ments of 500 users.
Customer Service Management
At 360 Security, we have always regarded user satisfaction as the core of product development, establishing a customer Provide and 360-related Non-360-related
optimize solutions inquires inquires
service system that covers all user touchpoints, dedicated to providing users with professional, ef?cient, and warm service
experiences.
Responsible Marketing
We have established a comprehensive responsible marketing management system, with close collaboration among multi-
ple departments (User Operations, Marketing, Legal, and Public Affairs departments). We regularly hold special seminars
to conduct internal self-inspections of our products, while also learning and promoting relevant laws and regulations, and
Reach agreements Unable to reach Severe problems:
analyzing industry cases to ensure that marketing activities are compliant and orderly. If users raise concerns on marketing with the user agreements; users e.g., signi?cant
content, they can provide feedback through the 360 product feedback and reporting channels, as well as various customer making complaints ?nancial loss to the
against the service user, injuries, mass
service channels, with our highest priority given to addressing these issues. Complaints related to marketing are ?agged staff; or users complaints, etc.
within our online customer service systems and prioritized for manual handling to ensure timely and appropriate resolution. requiring an
escalation
After-sales Service Management Formulate a clear
conclusion and
conduct a review if Escalate to
Optimizing Customer Service Mechanism necessary customer
service/operations
We have established a diversi?ed customer service chan- manager
nel matrix, including hotlines, online customer services,
email, and in-product feedback channels, with prominent
access points on our of?cial website and various product
Escalate to
interfaces to ensure users can easily access service YES Resolved? NO mangers/VPs
support. Currently, we have hundreds of professional
customer service personnel covering multiple business
Closed-loop resolution
areas such as technical software support, pre-sales and
after-sales hardware consulting, gaming services, and
advertising sales, responding comprehensively to various
user demands. Customer Service Access
During the reporting period, we continuously revised the User Complaint Handling Mechanism and established a comprehen-
sive complaint handling process covering reception, acceptance, veri?cation, resolution, and feedback, ensuring that user
Basic processing requirements:
complaints are responded to promptly and handled appropriately. Meanwhile, we assigned dedicated personnel to
Respect users, communicate proactively, and prioritize meeting their reasonable demands.
speci?cally handle user complaints from third-party platforms such as the Internet Information Service Complaint
Platform, the national 12315 platform, and Black Cat. The 360 Community serves as a public communication platform, Ensure timeliness and achieve closed-loop resolution for user issues.
where our staff publicly respond to user feedback and suggestions, enhancing service transparency. Analyze the root cause, draw broader insights from individual cases / Continuously identify and drive
business improvements.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
After-sales Service Management User Engagement and Brand Activities
Enhancing Service Ef?ciency We have actively innovated in user engagement by organizing the “360 User Appreciation Festival” and four major AI
competitions, where business leaders engage directly with users in of?ine settings to foster co-creation and experience
We actively embrace AI-enabled new quality productive forces, widely applying the 360 Zhinao model in scenarios such exchange. With a focus on core products such as Nano AI, 360 AI Writing, 360 Safeguard, and our browser, we have
as multimodal user voice analysis, AI customer service, and AI quality inspection, signi?cantly enhancing service ef?cien- hosted multiple of?ine “Product Exchange Sessions” to gain in-depth insights into the needs of younger user groups and
cy and depth. We have introduced AI-assisted capabilities into our online customer service system and optimized the promote collaborative product development and optimization. During the fourth session, held at universities in Beijing, we
voice queue structure of our membership service hotline, delivering a more convenient and ef?cient user experience. In engaged face-to-face with over 50 students. Product managers responded directly to user feedback on-site, forming a
addition, we have implemented over one hundred optimizations across more than ten platforms and tools, including user closed-loop interaction mechanism of “demand collection – product improvement – user validation.”
feedback platforms, VoC systems, and hotline service systems, to accelerate response times and reduce customer In the gaming sector, we held the 2025 World of Warships Day and the World of Tanks Championship International (WCI)
waiting time. Marketing-related complaints and reports are assigned elevated priority. Within our online customer in November, featuring competitions among several top international teams. Additionally, we invited users and popular
service tools, such cases are clearly ?agged and routed directly to human agents. streamers to participate on-site, enhancing communication with users.
Upgrading After-Sales Service
We have upgraded after-sales service policies for our smart hardware business by extending warranty-equivalent
services to devices within 3 months after warranty expiration, providing users with an enhanced service experience. The
customer service team conducts regular training and assessments, holding specialized training sessions for new and
existing employees throughout the year, covering areas such as business knowledge and service skills. We organized
certi?cation exams for new employees and on-the-job assessments for existing employees, continuously reinforcing the The 360 User Appreciation Festival in 2025 The 2025 Product Exchange Meeting The 2025 World of Warships Day
implementation of service standards. Our knowledge base system has been upgraded, providing solid support for the
improvement of service quality.
Customer Satisfaction Surveys
In 2025, we conducted multiple rounds of structured user research as planned, with high-frequency coverage across four core
business segments: internet services, smart hardware, gaming, and AI cloud storage, encompassing a range of ?agship
products. By continuously capturing the voice of the customer, we accurately identi?ed evolving user needs and enabled agile
product iteration and experience optimization. Our surveys achieved broad demographic coverage, including government and
public sector employees, professionals in healthcare, legal, and ?nancial industries, R&D personnel, corporate executives,
general staff, media and design professionals, educators and researchers, as well as small business operators, students, and
other user groups, forming a highly representative user feedback base.
After-sales Service Training For top-priority user feedback issues, we establish dedicated task forces to conduct in-depth analysis and drive targeted optimi-
zation initiatives. By strictly aligning with user suggestions, we actively advance improvement roadmaps to effectively respond
to user expectations.
Customer Relationship Management
Product Knowledge Popularization
Case:
In terms of product knowledge popularization, we continuously publish user guides, product updates, and new version
Our customer service team has consistently won user trust through warm and human-centered service, receiving
trial campaigns through channels such as the 360 Community, Help Center, and Product Knowledge Q&A, providing users
banners, appreciation letters, and online praises throughout the year. Our heartfelt services, such as on-site assis-
with convenient self-service access to product knowledge, and helping them better understand and use the products.
tance and helping the elderly solve technical issues, have received high praise from users.
We have established a diversi?ed user outreach system. We have set up 360 fan clubs and customer service accounts
on social platforms such as Douyin, WeChat, Bilibili, and Xiaohongshu to publish product user guides and enhance users'
understanding of 360 Security. On the 360 user community platform, we continuously update product dynamics and user
guides, and conduct new product and organize trial campaigns for new products and versions. The Help Center and
Product Knowledge Q&A provide users with self-service access to acquire product knowledge.
User Appreciation Banners Assisting Elderly Users Recognition and Gratitude from
with Technical Issues Various Government and Enterprise Clients
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Data Security and Customer Privacy Protection
Four Corners Analysis of Data Security and Customer Privacy Protection During the reporting period, we successfully
passed the Data Security Service Capability
Governance Assessment, achieving the highest level (Level II
certi?cation) in both data security development
At 360 Security, we place a high priority on data security and customer privacy protection. We strictly comply with applica- and data security assessment. This certi?cation
ble laws and regulations, including the Cybersecurity Law of the People’s Republic of China and the Personal Information provides strong institutional assurance and
Protection Law of the People’s Republic of China. We continuously enhance our information security management system technical support for our data security and
Data Security Service Capability
to ensure robust protection across all business operations. We have established and continuously re?ned a comprehensive customer privacy protection practices.
Assessment Quali?cation Certi?cate
set of internal policies and frameworks, including the 360 Group Data Security Management Policy, the 360 User Privacy Protec-
tion White Paper, the 360 Group Personal Information Protection Policy, the Data Security Training Policy, the Data Classi?cation and
Grading Policy, the Information Security Risk Management Standards, the 360 Group Cybersecurity Incident Response Plan, and the
Security Incident Operations Guidelines. These policies cover the entire data lifecycle, including collection, storage, use, trans-
mission, and disposal, clearly de?ning operational standards and compliance requirements at each stage.
We have established a governance structure that covers the entire process of decision-making, execution, and oversight,
forming a four-tier management mechanism led by the Data Security Committee, with collaborative promotion by various
departments, independent oversight by data audit institutions, and speci?c implementation by execution departments. For
mobile products, we set up a dedicated APP team to speci?cally discuss major data privacy issues. In parallel, our Informa-
tion Security Department and Data Platform Department are responsible for the full lifecycle management and mainte-
nance of business data.
Data Security Committee
Ecology and Internal Audit Marketing and
Privacy Legal Affairs Information Data
Strategic Cooper- and Supervi- Communication
Department Center Security Platform
ation Center sion Center Center Strategy
Risk/Oppor- Magn- Impact
Description Financial impact Response measures
tunity type itude horizon
Data Audit Institution
If our defense systems fail
The emergence of hacker 360 Security adopts the core
Executive Department (Business Department) to evolve in parallel, we
agents enables attackers to strategy of “using AI to combat
may face signi?cantly
train AI systems to autono- AI,” leveraging the 360 security
higher security thresholds
mously perform the full large model to upgrade
for core operations and
Organizational Structure of the Data Security Committee lifecycle of vulnerability traditional rule-based vulnerabili-
erosion of customer trust.
discovery, exploitation, and Short- to ty detection into a learning-driv-
Market Sustained increases in
cyberattacks at scale. A single High mid-t en intelligent model. We have
risks human attacker can control
defense-related
erm developed the swarm agent for
investments could place
dozens or even hundreds of vulnerability mining, enabling
pressure on competitive-
such agents, transforming automated analysis and
ness and operational
cyber confrontation from discovery of security vulnerabili-
stability, thereby constrain-
“human vs. human” to “human ties, requiring only a vulnerability
ing business expansion and
vs. machine.” ID input from operators.
long-term value creation.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Risk/Oppor- Magn- Impact Risk identi?cation
Description Financial impact Response measures
tunity type itude horizon
This will result in a mismatch
data security risk monitoring capabilities, including proactively identifying core data asset protection objects, dynami-
between security operation
cally monitoring data distribution and ?ow, intelligently analyzing and identifying security risks during the collection,
ef?ciency and response
A single model is insuf?cient sharing, transmission, and processing of data. We adopt differentiated response strategies based on risk levels and
speed to evolving attacks, We have developed multiple
to cope with the complex and
increasing the pressure on expert models, including ensure timely reporting of data security incidents.
ever-changing security
business continuity vulnerability detection and
scenarios, as vulnerability
assurance, shaking the Mid- to disposal models and alert
discovery and disposal High Risk monitoring
foundation of customer trust long-term analysis models, which operate
heavily rely on human
in product reliability, and collaboratively, forming the
experience, leading to
consequently constraining foundation (“brain”) for Based on our data classi?cation and grading framework, we implement differentiated monitoring measures for data
inef?ciency and a high
the market penetration next-generation security agents. assets of varying risk levels and have developed digitalized capabilities for data security situational awareness.
likelihood of errors.
capability of our core We also integrate national- and industry-level threat intelligence on data security to continuously re?ne and enhance
businesses, delay the our risk monitoring capabilities.
realization of strategic value.
Operational
risks
We implement data
Risk assessment and response
If data privacy and agent
With the launch of products, encryption for transmission
security risks are not
such as AI of?ce and nano AI, and processing, and do not Each business unit needs to conduct data security risk assessments based on the risks associated with their own data.
effectively managed, it may
user-input text, uploaded retain user data after The risk assessment can be divided into self-assessment and inspection assessment. The self-assessment is initiated
undermine user trust in the
images or videos, and voice
product, hinder large-scale
processing is completed. internally by the business unit to identify system vulnerabilities, aiming to implement security management and reduce
data, must be processed on We clearly de?ne authoriza- the security risks of assessed assets. The speci?c implementation process can refer to the Company's Information
deployment of core
servers, creating potential tion scopes and personal data
applications, and increase Security Risk Management Speci?cation for risk assessment. The inspection assessment is conducted by the Data
risks of data privacy leakage. Short- to sharing lists in our privacy
long-term compliance and High Security Management Committee, which commissions data auditing agencies or external risk assessment service
Issues such as prompt mid-term policies, obtaining user
technical protection costs. providers to carry out regular and sampling risk assessments. Inspection assessments mainly include, but are not
injection attacks, data consent prior to data
This could weaken product limited to, the contents of data security risk self-assessment, data security measures, data control and auditing
privacy breaches, hallucina- collection.
competitiveness and throughout the data lifecycle, emergency response measures, data integrity, availability, con?dentiality, etc.
tions, and agent loss of We have also launched the
customer retention, placing
control are becoming Large Model Safeguard to
sustained pressure on
increasingly prominent in the address risks such as attacks,
business stability and growth
application of large models. data leakage, hallucinations, Indicators and Targets
resilience.
and agent misalignment.
Target Progress in 2025
The explosive growth of the No administrative penalties due to data security incidents Completed
agent ecosystem opens new We have launched the 360
avenues for security business Security Agent to build an
The year 2025 was widely expansion, creating value AI-native security capability Information Security Assurance
regarded as the “Year of opportunities across framework. These agents have
Agents” in the industry. As government agencies, been widely deployed in To ensure effective response to sudden security incidents, we have developed the 360 Group Cybersecurity Incident Emer-
Market agents become a central enterprise, and industrial Mid- to scenarios such as APT attack gency Plan and the Security Incident Operation Guidelines, establishing a comprehensive emergency response system for
Medium
opportunities paradigm in the AI industry, sectors. It strengthens our long-term tracing, security operations, and
cybersecurity incidents. We regularly conduct emergency drills to continuously enhance our emergency response capabilities
demand for agent-focused competitive positioning vulnerability protection, and have
security solutions is rapidly within the AI ecosystem, demonstrated strong
and minimize the impact of sudden incidents on business operations. During the reporting period, we did not receive any
increasing. diversi?es sustained revenue performance in real-world administrative penalties due to data security issues.
streams, and supports applications such as cyberattack The types of data security incidents at 360 Security mainly include three categories:
long-term value growth and attribution.
business model optimization. First, incidents caused by individuals or organizations disclosing user data or internal corporate data to unauthorized
parties through any means, resulting in data leakage risks or actual leakage events;
Impact, Risk and Opportunity Management Second, incidents where individuals or organizations intentionally or unintentionally damage or delete data within
the system without authorization, affecting normal business operations;and
To effectively address the information security risks, we conduct risk assessments in accordance with our Information Security
Risk Management Standards, integrating both management and technical approaches. Based on assessment outcomes, we Third, incidents where external attackers, organizations, or individuals implement cyberattacks through illegal
implement targeted risk mitigation measures and continuous improvement initiatives to ensure that identi?ed risks are means, resulting in data leakage.
controlled within an acceptable range in a timely manner. We have established a sound prevention and response mechanism for the aforementioned types of risks.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Data Security Incident Response Mechanisms
Case: Cybersecurity Awareness Week
Type Emergency measures Containment measures Post-incident review
During the 2025 Cybersecurity Awareness Week, we launched a themed campaign titled “Welcome to Information
Upon detection of a data breach, Technical staff promptly investigate The response team organizes a Security Online — 2025 Edition.” By creatively integrating e-sports challenges with cybersecurity scenarios, we
the incident must be reported system, database, and application logs comprehensive review of established three themed zones and conducted interactive pop-up activities to promote cybersecurity knowledge
immediately to the Data Security to identify database IPs and affected systems and logs, analyzes root among employees. This initiative actively supported national cybersecurity awareness efforts and strengthened
Incident Response Team, which business operations. Relevant systems causes, and documents lessons
Data leakage organization-wide security defenses.
coordinates technical personnel to are taken of?ine or disconnected from learned.
incidents conduct inspections and prevent external networks as necessary, and
further escalation. evidence is preserved. Law enforce-
ment authorities may be involved when
required.
In the event of large-scale Data is restored from backups and Lessons learned are document-
tampering of core database data, services are resumed. Root causes are ed, root causes analyzed, and
the incident is immediately promptly investigated. If the incident is security of core database
reported to the Data Security due to external attacks, the source is systems is further reinforced.
Data tampering
Incident Response Team. Designat- analyzed through logs, and law
incidents ed database administrators or enforcement authorities may be
operations personnel verify the engaged if necessary.
issue, initiate the emergency plan,
suspend relevant services, and
notify responsible business teams.
Upon detection of data loss, the Technical personnel are mobilized to Lessons learned are document-
incident is immediately reported to restore data and services from the ed, root causes are analyzed,
Data loss the Data Security Incident most recent valid backups. and data security handling
incidents Response Team, which coordinates measures are strengthened.
relevant departments to assess the
scope and business impact.
Case: Company-wide Information Security Training
To help all employees effectively address security challenges in the AI era, we organized a company-wide training
We have established a normalized red team/blue team exercise mechanism. Through annual real-world emergency
program under the theme “Bridging Knowledge Gaps to Build a Digital Security Fortress.” In addition to training
drills, we continuously strengthen coordinated attack-and-defense capabilities and improve incident response
sessions, we conducted assessments to reinforce employees’ understanding of information security and enhance
effectiveness. These efforts enable ongoing optimization of our monitoring and protection systems, precise identi?-
overall security awareness.
cation of security risks, and overall enhancement of cybersecurity resilience.
Annual Security Emergency Drill
We place strong emphasis on fostering a cybersecurity culture. Through regular training programs, emergency drills, and
awareness campaigns, we continuously improve employees’ security awareness and defensive capabilities.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Customer Privacy Protection Innovation-Driven Development
Customer privacy protection is a critical component in safeguarding user rights and interests. We have established a system-
atic privacy protection framework through the integrated application of governance mechanisms, technical safeguards, and Four Corners Analysis of Innovation-Driven Development
compliance testing. During the reporting period, we were not subject to any administrative penalties related to customer
privacy breaches. Governance
Privacy Protection Measures Focusing on our dual strategic priorities of “AI + Security,” we have established a systematic
innovation and R&D governance framework spanning from top-level strategy and organization-
Mechanisms and technical safeguards al structure to technology development and commercialization of results. We continuously
advance frontier technologies and explore effective pathways to enhance R&D ef?ciency, with
We have established a full lifecycle management mechanism for mobile applications. Through structured processes, a focus on innovation output, talent development, and industry collaboration.
approval systems, and technical controls, we conduct compliance reviews, record-keeping, traceability, monitoring,
Driven by technological R&D, we maintain a high level of investment in innovation. By optimizing talent development mech-
and protection across the entire lifecycle of personal information.
anisms, we are committed to building a high-caliber R&D workforce that combines innovative thinking with strong technical
expertise. In the cybersecurity domain, we have built a strong “white-hat” team that operates at the forefront of global
Detection cyber defense. To date, we have over 2,000 core experts, tens of thousands of contracted community experts, and dozens
of city-level service centers across China.
The 360 Security mobile security team independently developed a compli-
ance detection engine to identify compliance risks during the operation of Key performance in 2025
Android applications. The engine features a rich set of compliance detec-
tion capabilities aligned with industry standards and regulatory require-
ments, including application permission request detection, detection of
application violations, third-party SDK compliance detection, and overseas
domain access detection in accordance with the standards set by regula- Number of R&D R&D personnel as a R&D spending R&D spending as a percentage
tory bodies such as the Ministry of Public Security and the MIIT. personnel percentage of our workforce of our operating revenue
Protection of Minors' Privacy
To stimulate innovation potential and foster a dynamic entrepreneurial culture, we have established a comprehensive incentive
We closely follow evolving requirements for the protection of minors in cyberspace in the digital era and have formulated a system that combines both ?nancial and non-?nancial rewards. Through dedicated incentive programs, we provide targeted
dedicated 360 Children’s Personal Information Protection Policy. In addition, dedicated sections on the Protection of Minors’ recognition for projects, teams, and individuals achieving breakthrough results in technological innovation and product devel-
Personal Information are included in both the 360 User Privacy White Paper and the 360 Security Cloud Privacy Policy, clearly de?n- opment. Meanwhile, we continuously organize skills competitions and innovation application contests to enhance employees’
ing rules governing the collection, use, and protection of minors’ information. We apply enhanced standards for minors’ priva- sense of achievement and recognition, cultivating a culture that values innovation and encourages creativity.
cy protection by standardizing the collection, use, storage, and processing of children’s personal information. We also provide
Strategy
clear and accessible channels for both parents and minors to exercise their rights, including access, correction, deletion, and
protection of personal information. Through these measures, we comprehensively safeguard the lawful rights and interests
Risk/Oppor- Magn- Impact
of minors. Description Financial impact Response measures
tunity type itude horizon
We continuously innovate by
If we cannot keep up with
applying the latest AI and security
The arti?cial intelligence cutting-edge technologies and
Case: Data Privacy Compliance Training on Key Requirements and digital security accurately grasp user needs, high
technologies to align with industry
trends and our own business
sectors we operate in are upfront R&D investment may not development, ensuring our core
We organized dedicated training sessions and assessments on technology-intensive and translate into sustainable user competitiveness. Leveraging our
key data privacy compliance requirements, covering topics such high-tech, characterized value, undermining the market self-developed general large model
by rapid innovation, fast foundation of advertising and Short, “360 Zhinao” with hundreds of
as core clauses and common pitfalls in drafting privacy policies, product iteration, high value-added services, weakening medium, billions of parameters, we continu-
Market ously iterate on our underlying
compliance requirements across the full lifecycle of app data R&D investment, and long user stickiness and market share, High and
risks technological capabilities. We have
monetization cycles. and affecting revenue stability. long
privacy, and identi?cation and mitigation of compliance risks released the latest model 360zhin-
Failure to keep pace with Meanwhile, continuous high-intensi- term ao3-o1.5, which performed
related to third-party SDK integration. Through these initiatives, frontier technologies and ty R&D investment may also excellently in third-party benchmark
we further strengthened employees’ awareness of data privacy user needs may lead to increase the intensity of resource evaluations. We also launched
user attrition in internet consumption, constrain transforma- AI-native products such as “Nano AI
protection and con?dentiality obligations. advertising and tion pace and long-term value Search” and “360 AI Of?ce,”
value-added services. creation, and create ongoing gradually building an application
pressure on long-term value growth. ecosystem matrix to accelerate
commercialization.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Risk/Oppor- Magn- Impact
Description Financial impact Response measures Impact, Risk and Opportunity Management
tunity type itude horizon
Failure to adapt to mobile migration During the innovation and R&D process, we have established a systematic risk management mechanism, integrating risk
With the shift to mobile may erode the foundation of our identi?cation, assessment, and mitigation measures into the project initiation phase to ensure risk prevention and control
internet, users and advertis- traditional businesses and hinder
ers have migrated to mobile resource reallocation toward growth throughout the entire R&D cycle.
platforms, impacting the areas. Increased competition and We leverage proprietary
traditional PC advertising higher entry barriers in new AI-driven large models to drive product
market, and we face the risk markets raise requirements for upgrades and enhance user Risk identi?cation and assessment
of declining revenue scale. commercialization ef?ciency and experience and commercial-
Meanwhile, in the “AI Plus” responsiveness, affecting long-term ization capabilities. AI is Prior to project initiation, R&D project leaders conduct systematic identi?cation and assessment of potential risks. Based on
wave, intensi?ed competition competitiveness and business model applied to optimize precision
increases expansion costs. If sustainability. In the “AI Plus” wave, advertising and traf?c the level of impact, risks are categorized into high, medium, and low levels, with corresponding mitigation plans developed
Tech- Mid- to
we did not respond in a increased competition and higher entry conversion, improving accordingly.
Medium long-
nology timely manner, it would barriers in new AI-driven markets raise
term
end-to-end ad management
affect our commercialization requirements for commercialization and mitigating the impact of Risk review
risks ef?ciency and competitive ef?ciency and responsiveness, affecting PC market decline.
advantage. long-term competitiveness and In digital security services,
The risk assessment results and mitigation measures are submitted as core components of the project proposal to the
In the digital security market, business model sustainability. we integrate large model
although we possess The room for value realization becomes and digital capabilities to Technology Committee, serving as key references for project evaluation and decision-making.
national-level cybersecurity constrained, the pace of new business drive business
capabilities, heterogeneous expansion and market penetration breakthroughs.
client demands limit capabilities are put to the test,
Risk monitoring and prevention
monetization of our affecting the sustainability of our
technological advantages. business model and the optimization
process of our business structure. After project approval, all subsequent R&D activities and risk management measures strictly adhere to the risk prevention
requirements speci?ed in the approval report, achieving effective integration of risk management and project execution.
In the ?elds of AI and cyberse-
curity, technical patents,
intellectual property, and R&D
achievements are important Indicators and Targets
intangible assets for the
Company. Risks such as a leak
of core technology information
or negligence in patent
We continuously strengthen Target Progress in 2025
management may lead to the IP management systems,
Loss of core technologies or key
leakage of core technology, enhance con?dentiality
personnel may weaken sustained
adversely affecting our
technological barriers, reduce ef?ciency
mechanisms for core Annual R&D investment ratio not less than 30% Completed
technological innovation and Mid- to technologies, and establish
Opera- in converting R&D investment into
new product development. High long- competitive incentive
innovation outcomes, and constrain
tional Our core technological term structures and talent R&D personnel ratio not less than 50% Completed
foundation stems from the product development and market
risks continuous innovation of our responsiveness, placing sustained
development environments
to stabilize core teams and
technical personnel, and it is pressure on long-term value creation.
ensure sustained innovation
normal for R&D personnel to be
capability.
renewed and iterated over time.
However, if situations such as
Technological Innovation Initiatives
the loss of core technical
personnel or the leakage of core
technologies occur, it will have Innovation and Technology Sharing
a material adverse impact on
our production and operations.
To foster a strong culture of innovation and continuously enhance
the professional capabilities of employees, particularly those in
The rise of AI security risks to the
R&D roles, we regularly organize “Tech Talk” knowledge-sharing
national strategic level, coupled with
policy dividends, has created more sessions, providing a platform for technical exchange and learn-
market opportunities for the application Our “AI + Security” dual
ing. During the reporting period, we actively conducted Tech Talk
National policies are promoting of security technologies, accelerated strategy aligns closely with
the digital economy and the penetration of core technologies national policy direction. We sessions covering a wide range of disciplines, including front-end
Policy Long-
cybersecurity, with AI security into key industries, deepened the Medium actively participate in development, back-end development, algorithms, cybersecurity
opportu- term
risks elevated to a strategic integration of security services with industry standard-setting to
research, testing, big data, and AI applications. These initiatives
nities level. intelligent scenarios, strengthened the strengthen our in?uence in
strategic value of core businesses amid AI security. have effectively promoted knowledge sharing, strengthened
the wave of the digital economy, and technical collaboration, and cultivated a positive and innova-
injected strong momentum into
long-term value growth. tion-driven organizational culture.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Industry-Academia-Research Cooperation Industry Exchanges
We continue to deepen Industry-Academia-Research (IAR) cooperation, maintaining close collaboration with universities, Industry exchange serves as a critical engine for corporate growth and technological advancement. In 2025, we leveraged
research institutions, and other third-party platforms, continuously strengthening technological innovation capabilities to our innovation strengths to further deepen industry-wide technical exchange and ecosystem collaboration. We actively
support high-quality industrial development. As of now, 360 has taken the lead in establishing industry-academia
fostered an open, mutually bene?cial exchange ecosystem by sharing best practices, jointly exploring frontier developments,
integration alliances, including the National Information Security Industry-Academia Integration Community, the National
Arti?cial Intelligence + Security Industry-Academia Integration Community, the Beijing New Generation Information and participating extensively in both domestic and international forums on innovation and knowledge sharing, thereby
Technology Industry-Academia Joint Community, the National Smart Security Industry-Academia Integration Community, contributing to coordinated industry development.
and the Hebei Province Digital Security and Arti?cial Intelligence Industry-Academia Integration Community, gathering
entities from government, enterprises, institutions, and universities to jointly promote the development of the indus-
try-academia integration ecosystem and talent cultivation. Case:
We hosted the Frontier AI Model Forum at the 2025 World Internet Conference, bringing together leading global
experts, scholars, and industry leaders. The forum focused on three core themes: AI model security governance,
Case: technology ecosystems, and industrial applications. Participants engaged in in-depth discussions on AI iteration,
risk mitigation, ecosystem collaboration, and industrial enablement. They shared innovative solutions and practi-
We conducted a dedicated university–enterprise
cal achievements including the “model-controlling-model” security paradigm, hardware-software co-optimiza-
collaboration visit with the Asian College and
tion, and the industrial deployment of Agentic AI, while conducting in-depth discussions on pathways for AI
African College of Beijing Foreign Studies Universi-
security, innovation, and sustainable development. The forum attracted broad participation from government,
ty. Both parties engaged in in-depth discussions on
industry, and academia, establishing a high-level platform for global AI exchange and cooperation.
key topics such as the development of AI large
models for less commonly taught languages and
collaborative research projects, exploring innova-
tive pathways for future cooperation.
Case:
The 2025 Annual Conference of the National AI + Security (Digital Secu-
rity) Industry–Education Integration Consortium was held under the
theme “Cross-Sector Synergy · Connecting the Future — Building a
New AI Security Ecosystem and Cultivating Industry–Education Talent.”
In collaboration with Lanzhou University and Jiuquan Vocational and
Case:
Technical University, we brought together stakeholders from govern-
ment, academia, enterprises, and research institutions. Guided by To further promote research on security technology and standardization develop-
industry demand and focused on talent development, the conference ment for large models in the cloud, the CAICT took the lead in establishing the Cloud
promoted deeper integration between arti?cial intelligence and digital
Large Model Security Promotion Alliance in March 2025, aiming to integrate indus-
security across the education and industrial landscape.
try resources, standardize the security development of large models in the cloud,
and promote the coordinated development of technological innovation and security
governance. At the 2025 Global Digital Economy Conference, 360 Security was
awarded a medal as one of the inaugural member organizations of this initiative.
Case:
We hosted the “Nano AI Campus Tour” at Henan Vocational College of
Logistics. The event focused on two core areas: “Digital Security and AI
Technology Lectures” and “Nano AI Video Creation Competition Call for Case:
Works,” aiming to help students deepen their understanding of both To promote the application of intelligent capabilities in the ?eld of software engineering, 360 Security collaborat-
digital security and AI, promote the precise alignment of classroom knowl- ed with over twenty leading companies in the industry to jointly compile the Measurement Speci?cation for Intelli-
edge with industry needs, and reserve professional talent for the develop- gent R&D Application E?ciency of Software, helping to establish a uni?ed measurement standard for intelligent
ment of the digital economy in Henan Province. software R&D ef?ciency in the industry, ensuring comparability of data among different enterprises.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Case:
Business segment Innovative achievements
To enhance the capabilities of large model application delivery vendors in technology, management, and services,
on June 24, the technical speci?cation General Capability Requirements for Large Model Application Delivery Our Strategic Product 360 Security Cloud
Vendors (AIIA/T 0225-2025), led by the CAICT and participated by 360 Security and other enterprises, was of?cial-
ly released.
We actively lead and participate in the formulation and revision of
international, national, and industry standards, contributing to the
overall advancement of industry development and product quality
while demonstrating leadership within the sector. During the report-
ing period, we were deeply involved in the development of three
national standards: GB/T 45288.1-2025 Arti?cial Intelligence—Large 360 Security Cloud Services
Models—Part 1: General Requirements, GB/T 45288.2-2025 Arti?cial
Intelligence—Large Models—Part 2: Evaluation Metrics and Methods, and
We continuously promoted the dual advancement of technological innovation and
GB/T 45288.3-2025 Arti?cial Intelligence—Large Models—Part 3: Service
commercialization of the 360 Security Large Model, enhancing the model's practical
Capability Maturity Assessment. We also of?cially released the Agent
capabilities and accelerating the deployment of applications for industry clients, there-
Engineer Standard and Certi?cation System, and the White Paper on
by consolidating our leading position in the ?eld of AI security integration.
Large Model Security.
In addition, research from the 360 Vulnerability Research Institute, titled “WingMuzz: Blackbox Testing of IoT Protocols via
Two-dimensional Fuzzing Schedule,” received the Distinguished Paper Award at the 40th IEEE/ACM International Conference
on Automated Software Engineering. Two research papers from the 360 AI Research Institute, focusing on multimodal gener- Digital security
ation and multimodal understanding, were accepted at ICCV 2025 (International Conference on Computer Vision).
Technological Innovation Achievements
Business segment Innovative achievements
We have established a new “A·I·P·C”
Based on “model-to-model governance,” we have developed the Large Model
intelligent marketing framework and
Safeguard, which provides enterprises and institutions with one-stop capabilities,
launched a one-stop intelligent advertis-
including model access, data management, security evaluation, task management,
ing delivery platform centered on core
and result analysis, helping identify, quantify, and mitigate security risks associated
products such as 360 Lingshu, 360
with large model applications.
Chuangyi, 360 Agent, and 360 Zhito.
Internet services
Leveraging the integration advantages of
our self-developed 360 Zhinao with several
mainstream large models, we continuously
iterate our entire line of internet products,
such as 360 AI Of?ce, Nano AI, Nano Comic
Drama Pipeline, and 360 Security Lobster. Content Security Assessment and Content Security Guardrails, 360
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Business segment Innovative achievements
The 360 Large Model Security Solution was recommended in IDC’s report Large Model Security Detection and Protection
Solutions: Vendor Recommendations and Insights.
The 360 Endpoint Security Agent was selected for inclusion in the 9th Annual Case Compendium of the Software and
Building on the 360 Security Large Model, we also
Digital security Information Service Industry published by the Internet Society of China.
innovatively launched the Security Agent Swarm.
Government and ?nancial industry solutions built on the 360 Security Agent were recognized as “Outstanding
The 360 Security Agent received authoritative certi?cations across ?ve core domains, namely security operations,
Empowering the entire hardware portfolio with AI security detection, data security, security compliance, and attack-and-defense intelligence, in IDC’s report China
technology, we continuously strengthen our indus- Security Agent Market Overview, 2025: The Momentum Is Here, the Future Is Promising.
Smart hardware try-leading position in core categories such as
video doorbells and dash cams through upgrades The 360 Security Agent was also recommended in IDC’s report China Agent Market Analysis and Vendor Recommenda-
tions, 1Q25.
in both functionality and experience.
Intellectual Property Protection
Technology Innovation Awards
Intellectual Property System Development
During the reporting period, we received the following major recognition and awards:
We were listed on the Annual Enterprise List of the “AI Product Rankings” in the 2025 China AI Annual Rankings. As a technology-driven enterprise, we regard intellectual property (IP) as a
core strategic asset and have established a systematic IP protection
system. By strengthening institutional mechanisms and setting up a
We ranked No. 1 on the Top 20 Cybersecurity Companies in China (2025) released by the Internet Society of China.
Patent Review Committee, we continue to standardize the creation,
utilization, protection, and management of IP, providing robust support for
Nano AI was included in the Annual Product List of the “AI Product Rankings” in the 2025 China AI Annual Rankings. technological innovation and commercialization. During the reporting
period, one of our subsidiaries was successfully selected as a candidate
The 360 Security Large Model was awarded the following certi?cations by the China Academy of Information and for the National Intellectual Property Demonstration Enterprise Program.
Communications Technology (CAICT): Intelligent Threat Detection Capability Certi?cation, Intelligent Security Opera-
tions Capability Certi?cation, and Intelligent Knowledge Q&A Capability Certi?cation .
Institutional guarantee
The 360 Security Large Model was selected as a typical case in the World Internet Conference Report Empowering
Global Sustainable Development through Inclusive and Equitable AI Governance.
We have formulated a series of policies and guidelines, including the Intellectual Property Management Measures, the
Patent Application Management Measures, the Patent Classi?cation Management Measures, the Patent Drafting and
The 360 Security Large Model All-in-One Appliance received the Top Recommendation in IDC’s report China Security
Response Procedures, and the Legal Compliance Guidelines for Open-Source Software.
Large Model All-in-One Market Insights and Vendor Recommendations, 2025: Large Models Sweeping the Globe, with AI and
Security Reinforcing Each Other. In this ?scal year, building on our existing governance framework for patents, trademarks, copyrights and other IPs, we
developed the 360 Group Trade Secrets Management Measures, prioritizing trade secret protection. Through six key
dimensions, namely systematic assessment, institutional design, organizational implementation, tool support, capability
The 360 Security Large Model was ranked No. 1 in multiple subsegments in IDC’s report China Large Model Security
building, and external collaboration, we have established a closed-loop governance system that is actionable, auditable,
Protection Market Overview, 2025: Building Trustworthy AI through Comprehensive Detection and Protection
and continuously improvable. This has enabled the formation of an integrated “four-in-one” IP system encompassing
patents, trademarks, copyrights, and trade secrets, laying a solid institutional foundation for long-term IP protection.
The 360 Large Model Safeguard became the ?rst to pass CAICT’s Large Model Security Protection Guardrail Capabil-
ity Evaluation and obtain certi?cation.
Management organization
The 360 Large Model Safeguard Evaluation System obtained the Large Model Security Evaluation System (Enhanced
Level) Certi?cation from the National Network and Information System Security Product Quality Inspection and We have established a Patent Review Committee, chaired by the Vice President and Chief Scientist of the Company, with
Testing Center members comprising technical experts nominated by various professional committees across different ?elds.
The 360 Large Model Safeguard ranked No. 1 in overall capability in IDC’s report Technical Assessment of Large Model
Security Evaluation Platform Vendors in China, 2025.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Intellectual Property Protection Measures IP awareness cultivation
To enhance employees' awareness of IP risks, we organize IP-related training and have established patent display
Protecting proprietary IP rights
walls to showcase core technological achievements.
We have implemented full lifecycle patent management, featuring online application review, standardized procedures,
and authoritative evaluation criteria. Through multidimensional pre-assessment of patent proposals, covering technical,
commercial, and legal value, we classify and manage innovations best suited for patent protection, thereby strengthen-
ing and expanding our patent portfolio.
We have established a “full-chain proactive rights protection mecha-
nism” covering monitoring, evidence collection, litigation, and enforce-
ment. This mechanism enables professional identi?cation and ef?cient
handling of infringement cases. Supported by a regular monitoring
system, potential infringements are promptly identi?ed, followed by
standardized evidence preservation and legal assessment, and system-
atically advanced through judicial proceedings and enforcement,
forming a sustainable and institutionalized IP rights protection capability.
Advancing the cybersecurity industry patent pool
We have introduced the Management Guidelines for External Information During the 2025 National Cybersecurity Awareness Week, we joined four other founding organizations to launch the
Release via New Media Accounts and O?cial Websites, clarifying responsibili- Cybersecurity Industry Patent Pool. This initiative aims to promote collaborative innovation through centralized patent
ties, setting standards, and optimizing processes to govern content management under the principles of “shared patents, co-developed ecosystem, and jointly strengthened security.” The
across all corporate media channels. During the reporting period, we mechanism is expected to reduce technology transaction and enforcement costs, enhance industry-wide innovation
conducted multiple training sessions and optimized approval work?ows synergy and risk response capabilities, and inject new momentum into high-quality industry development.
to strengthen ex-ante risk control in content production, effectively
reducing compliance violations and infringement incidents.
Respect for others' IP rights
We fully respect third-party IP rights and enhance employee awareness through institutional frameworks and process
controls. In addition, we have also established IP risk early warning and control mechanisms, embedding IP risk manage-
ment checkpoints into key stages such as product initiation, launch, and phase-out, thereby effectively preventing
infringement risks in our operations and R&D activities.
In the event of infringement claims, we implement a timely and effective complaint handling mechanism. Based on
different product types and IP categories, we have developed tailored handling guidelines to standardize case process-
ing. We review the legitimacy and relevance of IP claims, safeguard the legitimate rights and interests of rights holders.
We take measures such as noti?cation, deletion, blocking, or severing links against infringing content and promptly
provide feedback on the handling results to the rights holders.
AI IP compliance
In response to the intellectual property risks associated with AI products, we conduct in-depth research on cutting-edge
legal issues and keep pace with industry developments. By internalizing external regulatory requirements, we have
established a risk checklist and compliance guidelines. We formulated and published the AIGC Intellectual Property
Compliance Guidelines, covering areas such as training data compliance and generated content compliance, providing
strong IP compliance support for our cutting-edge business development.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Ethics in Science and Technology Win-Win Cooperation
The rapid advancement of AI large models is driving industrial transformation while Supplier Management
also introducing new challenges in ethical governance. As a developer of AI technolo-
gies, we consistently uphold the principle of “technology for good” and have systemati- At 360 Security, we continuously strengthen our supplier management system in accor-
cally established AI ethics guidelines. By integrating technological innovation with dance with the 360 Group Management Measures for Centralized Procurement Depart-
institutional governance, we ensure that our technology development remains funda- ment Supplier. We standardize the full lifecycle of supplier management, including
mentally oriented toward enhancing human well-being. We have obtained the ISO/IEC onboarding, quali?cation, maintenance, evaluation, and exit, while establishing and
cybersecurity company in China to achieve this certi?cation. ment quality and ef?ciency, while optimizing cost-effectiveness.
We strictly comply with applicable laws and regulations, including the Law of the
People’s Republic of China on Progress of Science and Technology, the Opinions on
Supplier classi?cation:
Strengthening the Governance of Science and Technology Ethics, and the Measures for
Science and Technology Ethics Reviews (Trial). We systematically advance large model Registered suppliers: Suppliers that have submitted basic information via the 360 Group SRM system portal and
security governance, AI content safety management, and industry standard develop- are pending review.
ment, embedding technology ethics throughout the entire lifecycle of R&D and product
Quali?ed suppliers: Suppliers whose certi?cations and supporting documentation meet requirements and have
operations. During the reporting period, we did not engage in any actions that violated
completed category classi?cation.
scienti?c ethics.
Reserve suppliers: Suppliers that have passed credit checks and completed supplier communication, on-site
inspections (if applicable), and material certi?cation (if applicable), and have passed reserve evaluation.
At the beginning of the year, we launched the DS large model safety solution, covering the entire Cooperative suppliers: Suppliers that have won procurement bids, provided products or services, and signed
process of model training, inference, and operation. With the concept of “model-to-model gover- cooperation agreements or purchase orders, including both ongoing and completed collaborations.
nance,” we safeguard large model safety. To prevent large models from falling into the trap of Suspended suppliers: Suppliers with performance issues during cooperation and unsatisfactory recti?cation
hallucinations, 360 Smart Search reduces false or inaccurate information through precise knowl- outcomes, temporarily restricted from participation until improvements are made.
edge integration, enhancing the credibility and reliability of large models and effectively reducing Blacklisted suppliers: Suppliers involved in fraudulent activities or serious misconduct, permanently disquali?ed
the likelihood of generating hallucinated content. At the same time, 360 Smart Search supports from future cooperation.
knowledge extraction and summarization based on enterprise private-domain data, providing
safer and more ef?cient business support for companies.
Supplier admission review:
At the World Internet Conference Wuzhen Summit, 360 Security of?cially released the White Suppliers are onboarded through a structured process including information submission, admission review, and
Paper on Large Model Security, systematically explaining the ?ve key risks associated with the reserve evaluation.
operation of large models for the ?rst time: infrastructure security risks (e.g., device control, Key suppliers are subject to on-site inspections based on the Supplier Assessment Form to comprehensively
supply chain vulnerabilities, denial-of-service attacks, and misuse of computing resources), evaluate their capabilities.
content security risks (e.g., non-compliance with core values, false or illegal content, large model Suppliers are required to sign the Integrity Commitment Letter and the Con?dentiality Commitment Letter, strict-
hallucinations, and prompt injection attacks); data and knowledge base security risks (e.g., data ly complying with our anti-fraud policies.
leakage, unauthorized access, privacy misuse, and IP-related risks); agent security risks (e.g.,
unclear security boundaries in plugin invocation, computing resource scheduling, and data ?ows);
and user-side security risks (e.g., permission control, API monitoring, and malicious script execu-
Supplier performance evaluation:
tion). Based on practical experience, the white paper proposes a dual-track governance strategy
of “plug-in security + platform-native security” to promote the stable development of the AI We conduct quarterly evaluations across dimensions such as pricing, quality, service, responsiveness, and quali?-
industry towards being “secure, benevolent, trustworthy, and controllable.” cations, and assign annual supplier ratings, and comprehensively assess the annual rating of suppliers each year.
Suppliers with substandard performance are subject to corrective actions or formal reviews, with continuous
To enhance employees' technological ethics literacy, we have systematically developed a technology ethics curriculum and tracking of improvement outcomes.
training system, and conducted specialized training for technical and business personnel covering modules such as ethical
principles, privacy protection, fairness, and transparency. Additionally, we regularly invite industry experts and scholars to
share cutting-edge research ?ndings and viewpoints, deepening employees' understanding of science and technology ethics Supplier oversight and elimination:
through discussions. We encourage employees to participate in AI ethics research projects, support in-depth exploration of
Misconduct can be reported through established whistleblowing channels.
ethical frontier issues, and apply research outcomes to product development practices. We insist on advancing product
research and development and the application of AI technology with a responsible attitude, ensuring that technology truly Suppliers found in violation of regulations are subject to penalties, including suspension or blacklisting.
serves human well-being.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Supply Chain Security Risk treatment:
We have established the 360 Group Supply Chain Security Management Policy and a A risk treatment plan should be developed for the speci?c risks identi?ed in the risk assessment, and risk treatment
comprehensive emergency response framework for supply chain security strategies should be selected in conjunction with the organization's business requirements and capacity constraints.
incidents, enhancing our capability to effectively respond to unexpected disrup- Key strategies mainly include:
tions. The framework comprises six core components: risk identi?cation, risk
Risk mitigation: Actions taken to reduce the likelihood of risk occurrence or mitigate the negative consequences
analysis, risk evaluation, risk treatment, risk monitoring and review, and risk
of risk. That is, implement control measures to reduce the likelihood and impact of threats, thereby lowering the
communication and documentation.
risk level, so that after reassessment, the residual risk can be accepted by the organization's risk strategy.
Risk avoidance: A decision not to enter a risk scenario or an action to withdraw from a risk scenario. This is
Risk identi?cation: achieved by choosing to abandon certain businesses or assets that may trigger risks, adopting environmental
changes, or canceling risk-related activities.
Asset identi?cation: Identify the key assets in the supply chain, as these assets have a direct impact on the Risk transfer: Sharing with another party the losses or bene?ts arising from a risk. That is, transferring all or part
organization's business functions. Any disruption or damage to these assets may result in product or service of the risk to other parties. The organization may transfer risks by purchasing insurance or sharing them with
failure or quality degradation. partners.
Threat identi?cation: Risk retention: Accepting the losses or bene?ts from a speci?c risk. When the organization's security policy
a) Threat source identi?cation: Supply chain security threats mainly arise from environmental factors, supply permits, no control measures are taken for the risk, and the potential losses from the speci?c risk are accepted.
chain attacks, and human errors. If the risk reduction strategy is selected, appropriate supply chain security risk control measures must be chosen
b) Threat type identi?cation: Typical supply chain security threats mainly include malicious tampering, counter- for the risk to ensure that, after implementation of the control measures, the residual risk is acceptable to the
feiting, supply disruptions, information leakage, regulatory violations, and other threats. organization.
Vulnerability identi?cation: Supply chain vulnerabilities are defects that can be exploited by threats at any
stage of the supply chain, including design, development, production, integration, warehousing, delivery, opera-
tion and maintenance, and disposal of products and services.
Existing security measures identi?cation: Identify the existing or planned security measures in the supply Risk monitoring and inspection:
chain and con?rm the effectiveness of these measures.
The purpose of risk monitoring and review is to ensure that the organization's risks remain within acceptable limits.
Supply chain risks are dynamic, as threats, vulnerabilities, risk likelihood, risk impact, etc. may all change as the
Company's business evolves. A risk monitoring and review plan should be established to monitor risk management
Risk analysis:
activities, periodically review control measures, and adjust scope boundaries in a timely manner.
includes likelihood analysis, consequence analysis, and risk estimation.
The likelihood analysis should be conducted from two perspectives: ?rst, the likelihood of damage to the supply
chain, such as potential impacts on the use of critical components or an increased risk of IP theft; second, the Risk communication and documentation:
likelihood of damage to products, services, systems, or components within the supply chain, such as systems
being implanted with malicious code or components being damaged by electrical surges. Risk communication and documentation are activities through which risk managers and stakeholders reach agree-
The consequence analysis focuses on identi?ed supply chain security incidents and analyzes their potential ment on how to manage risks by exchanging and/or sharing relevant risk information.
impacts. Consequence analysis is conducted based on factors such as the importance of assets, characteristics
of the threat sources that triggered the security incidents, identi?ed vulnerabilities, and the organization's sensi-
tivity to incidents as re?ected by existing or planned security measures.
Risk estimation involves assigning values to the likelihood and consequences of supply chain security risks, and
should be based on the conclusions drawn from the likelihood and consequence analyses.
Industrial Chain Collaboration
We leverage our comprehensive capabilities to strengthen collaboration with
Risk assessment:
suppliers and partners across project cooperation, technical support, resource
sharing, etc. Through these efforts, we jointly promote green transition and
Risk assessment compares the results of risk estimation with risk assessment criteria and risk acceptance criteria,
sustainable development across the industrial chain.
producing a prioritized list of risks based on the risk assessment criteria. The consequences and likelihood obtained
from risk identi?cation and analysis can also be used for risk assessment activities.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Equal Treatment to SMEs
Case:
As a strategic partner of HarmonyOS, 360 Group was invited to participate in the HarmonyOS Starlight Gala With the principles of fairness and equity in all partnerships ?rmly in
Ecological Forum. We contributed to discussions on multi-device and multi-scenario security, including application mind, we treat all partners, including small and medium-sized enterpris-
security, data security, and privacy protection. We also supported the ecosystem through open-source security es (SMEs), on an equal basis. We ensure timely payment to SME suppli-
governance, offensive and defensive security practices, and vulnerability discovery, enhancing the overall securi- ers. As of the end of the reporting period, no overdue payments to SME
ty of the HarmonyOS ecosystem. suppliers were recorded.
We also actively engage in digital poverty alleviation initiatives. Lever-
aging big data technologies, we have developed the “Digital Security
China” solution that transforms the traditional cybersecurity business
model into a Security-as-a-Service (SECaaS) model. Through our 10
billion yuan subsidy program, we have made security products and
services, serving 1.5 billion users globally and available free of charge to
SMEs and micro-enterprises.
Case:
A subsidiary of 360 Security received
The “Breaking Security, Breaking Through the Ecosystem” 360 digital security ecosystem partner conference was
recognition as an Outstanding
successfully held at ISC.AI 2025. The conference gathered over a hundred partners from across the country, and Case of Social Responsibility
we engaged in in-depth discussions with partners about new opportunities, technologies, and achievements in the among Private Enterprises in China
digital security industry in the AI era, envisioning the future development of the digital security ecosystem.
Rural Revitalization
We actively respond to China’s rural revitalization strategy, focusing on industrial develop-
ment, education, ecological sustainability, and cultural advancement. Through industrial
collaboration and educational support initiatives, we deliver targeted assistance across
multiple regions, injecting sustained momentum into rural development and contributing to
the goals of a strong agriculture, a beautiful and revitalized countryside, and prosperous
farmers. In doing so, we actively ful?ll our corporate social responsibility.
During the reporting period, we invested approximately 400,000 yuan in rural revitalization.
Case:
In 2025, we continued to focus on educational equity, striving to improve the conditions of schools in relatively under-
developed areas. We provided special funds for updating desks and chairs and enhancing the learning environment
at schools in Zhangbei County, Zhangjiakou City, Hebei Province; for purchasing teaching equipment and ensuring
teaching conditions at Chenglong School in Longnan City, Ganzhou, Jiangxi Province; and for funding students in
need at Jiu San Middle School in Weining, Bijie, Guizhou, and supplementing necessary teaching materials.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Social Contribution Case:
Corporate Responsibility
We integrate the ful?llment of social responsibility into our corporate devel- In May 2025, 360 (Yangzhou) Digital Technology Co., Ltd. co-organized a
opment strategy. Guided by our commitment to serving national priorities themed quiz event in Jiangwang Community titled “Enhancing Awareness
and strengthening our development foundation, we proactively align with and Building Cybersecurity Together.” The event was organized in engag-
major national strategies and actively contribute to key areas such as coordi- ing and educational formats to disseminate key provisions of laws such as
nated regional development and community co-building. the Cybersecurity Law and the Personal Information Protection Law.
Supporting the National Cybersecurity Strategy
We fully leverage our role as a key force in national cybersecurity defense. With our internet-wide security big data and our
self-developed security large model, we continuously conduct attribution and countermeasures against overseas cyberat- Public Welfare
tacks. In 2025, we successfully traced 270,000 overseas cyberattacks targeting the Asian Winter Games Harbin, identifying
for the ?rst time three agents of the U.S. National Security Agency and two U.S. universities. We also assisted public security We leverage our technological expertise to ful?ll our social responsibilities, empowering rural communities through technolo-
authorities in identifying hacker organizations in Taiwan and exposing their attacks on critical systems in key sectors such as gy donations and safeguarding public well-being through inclusive services. By extending the bene?ts of digital security to a
energy and transportation. To date, we have identi?ed and named 60 overseas APT groups, accounting for 98% of the total broader population, we demonstrate our commitment as a responsible corporate citizen through concrete and impactful
discovered in China. actions.
We regard emergency relief as a key component of our corporate social responsibility. Through the 360 Foundation, we
made donations to support earthquake-affected communities in Shigatse, Tibet, and ?ood-affected residents in Huairou
Tax Compliance
District, Beijing, helping them restore normal production and daily life.
We strictly comply with the Enterprise Income Tax Law of the People’s Republic of China and uphold the rule of law and compli-
ance as fundamental principles. We regard lawful and good-faith tax payment as a core responsibility of a corporate citizen.
We continuously improve our tax management system to ensure that all taxes and fees are declared and paid in full and on
time. Through standardized and ef?cient tax management, we provide strong support to national ?scal revenues and Case:
contribute to the improvement of public services and equitable allocation of social resources. In 2025, we paid a total of 506 In 2025, with the coordination and support of the Ministry of Foreign Affairs, we
million yuan in taxes and fees. donated electric tricycles adapted for mountainous terrain to Jinping County,
Yunnan Province. This project addressed long-standing challenges in agricultur-
Community Engagement al transportation, given that 99.72% of Jinping County is mountainous, resulting
We attach great importance to building harmonious relationships with the communities in which we operate. We have estab- in high costs and low ef?ciency for logistics.
lished ef?cient communication mechanisms, actively respond to community needs, and participate in community activities, The vehicles are now directly used for transporting local specialty agricultural
fostering mutual growth and coordinated development between the Company and local communities. products such as tea, tropical fruits, and fresh corn, facilitating access from
rural areas to urban markets.
Case:
To further promote the Regulations on the Protection of Minors in Cyberspace and enhance minors’ awareness of
cybersecurity and self-protection, our exhibition center welcomed many young visitors. Through immersive expe-
riences and interactive teaching, participants quickly developed a foundational understanding of cybersecurity. Case:
In June 2025, the CPC 360 Group Committee, in collab-
oration with the Aixing Dream Public Welfare Service
Center, launched a charitable initiative themed “Con-
necting Hearts, Warming ‘Starry’ Journeys.” Through a
“purchase-as-donation” model, we procured a batch
of creative cultural products handcrafted by young
people with special needs, supporting their develop-
ment and social inclusion.
Governance
CORPORATE GOVERNANCE SYSTEM
REMUNERATION MANAGEMENT
PARTY BUILDING LEADERSHIP
ANTI-BRIBERY AND ANTI-CORRUPTION
FIGHT AGAINST UNFAIR COMPETITION
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Corporate Governance Mechanism Board of
We continue to advance board diversity by incorporating factors such as gender, age, educational
Directors background, professional expertise, and work experience into the director nomination process. Currently,
Four Corners Analysis of Corporate Governance board members possess expertise across ?nance, management, accounting, and law, forming a well-struc-
tured and complementary governance team. Leveraging their unique cultural perspectives, professional
Governance expertise, and practical experience, the directors fully express their views in decision-making, achieving
We strictly comply with the Company Law of the People’s Republic of China, the Securities Law of the People’s Republic of China, the coordination, cooperation, and effective checks and balances, thereby collectively stimulating the Board's
Code of Corporate Governance for Listed Companies in China, and the Rules Governing the Listing of Stocks on Shanghai Stock innovative vitality and governance effectiveness.
Exchange, and continuously re?ne our internal governance mechanisms. We have further optimized our governance struc-
Performance of Independent Directors During the Reporting Period
ture, including the Board of Shareholders, the Board of Directors, and the Audit Committee.
We have established a governance structure characterized by mutual checks and balances, clearly de?ning the boundaries
of authority and responsibilities among the Board of Shareholders, the Board of Directors, and management. This frame- Number of independent directors Number of
work ensures scienti?c decision-making, effective execution, and robust oversight, thereby preventing the abuse of power as a proportion of the number independent
and safeguarding the interests of all stakeholders. of Board members directors
The Board of Shareholders, as the highest power authority of the Company, is composed of all sharehold- 60% 3
Board of
Shareh- ers and has the decision-making authority over the Company's operational policies and investment plans.
olders We strictly follow statutory procedures for convening and conducting general meetings and regularly hold
annual and extraordinary general meetings to ensure that shareholders’ rights to information, participa-
tion, and voting are fully protected. The Audit Committee has effectively assumed the responsibilities previously held by the Supervisory
Audit
Committee Board and ful?lls its oversight duties diligently. Through continuous review of ?nancial statements,
Board of The Board of Directors is elected by the Board of Shareholders and is accountable to it, serving as the core
related-party transactions, internal controls, and the performance of directors and senior management,
Directors decision-making body for the Company's operations and development, formulating strategies and policies.
we strengthen ongoing and post-event supervision, improve risk control mechanisms, and continuously
The Board of Directors has three specialized committees: the Audit Committee, the Nomination and
enhance corporate governance and compliance management, thereby ensuring stable operations.
Compensation Committee, and the Strategy Committee. Each specialized committee strictly follows its
division of responsibilities to conduct in-depth research and prudent deliberation on relevant matters, Our management team is responsible for day-to-day operations within the authority delegated by the
providing solid support for the Board of Directors' scienti?c decision-making. Manage-
ment Board. The management team includes the General Manager, the Board Secretary, and the Chief Finan-
cial Of?cer, all of whom are appointed and removed by the Board. All senior management members
Board Effectiveness Evaluation diligently ful?ll their ?duciary duties and faithfully implement Board resolutions, driving standardized
operations and sustainable development.
The Board of Directors consists of 5 directors (including independent directors), with 1 chairman and 3
independent directors. In August 2025, the Board of Directors deliberated and approved the proposal to
abolish the Supervisory Board and amend the Articles of Association and related policies. The functions of
the former Supervisory Board have been assumed by the Audit Committee. This restructuring streamlined
governance layers, strengthened oversight functions, and enhanced both decision-making ef?ciency and
supervisory effectiveness.
Meetings held by the Proposals reviewed by the Meetings held by Proposals reviewed
Board of Shareholders Board of Shareholders the Board of Directors by the Board of Directors
Board of
Directors 3 independent directors
Board Independence and Diversity
Meetings held by the Proposals reviewed by the Unapproved proposals by the Board
We place great importance on the key role of independent directors in corporate governance, fully leverag- Supervisory Board Supervisory Board of Shareholders, the Board of Directors,
(before cancellation) (before cancellation) and the Supervisory Board
ing their professional advantages to continuously enhance governance effectiveness. During the reporting
period, all independent directors attended all board meetings, either in person or via telecommunication, 3 20 0
and exercised independent judgment in reviewing proposals. Their professional insights, informed by
industry trends and Company operations, provided strong support for sound decision-making.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Strategy
Internal Our internal audit function reports directly to the Audit Committee of the Board, ensuring a high degree
Risk/Oppor- Magn- Impact audit of independence and authority. This structure effectively prevents external interference and ensures
Description Financial impact Response measures
tunity type itude horizon objectivity and impartiality in audit activities. Through regular special audits and compliance audits, we
accurately identify potential risks in business operations and management processes.
Imbalanced Board of Directors
structure: Unreasonable An imbalanced Board
composition of Board members structure and ineffective
(e.g., in terms of the proportion decision-making mecha- Ensure complementary profession- We consistently regard compliant operations as the cornerstone of sustainable development. Guided
nisms will weaken the Risk
of independent directors, al backgrounds among Board
scienti?c rigor and members (strategy, ?nance,
Manage- by internal policies such as the Guidelines for Evidence Collection Management of the Legal A?airs Center, the
professional backgrounds) may
Board of undermine the quality of forward-looking nature of technology, etc.), and guarantee ment Entity Certi?cation Management Policy and Guidelines, and the Guidelines on the Management of Seals in
decision-making and effective- strategic decisions, affect the substantive proportion and
Directors ness of oversight. resource allocation voice of independent directors.
Remote Locations, we have established clear compliance objectives and implemented systematic and
ef?ciency and execution
and Ineffective decision-making
pace, and constrain the
Strictly implement the Board of standardized management measures to effectively mitigate compliance risks and create long-term
mechanisms: Lack of robust Directors Rules, with major
decision- rules of procedure and organization's ability to High Short- decisions subject to prior review value for shareholders, customers, and society.
respond to market changes. to mid-
making decision-making processes may
Unclear or frequently
and consultation by specialized We adhere to fundamental risk management principles aligned with national laws and regulations,
lead to errors or overly term committees.
govern- centralized decisions in major changing strategic Major investment projects must integrating internal governance requirements to accurately identify potential risks in operations and
matters such as investment and directions may lead to undergo mandatory and thorough
ance misallocation of key conduct structured risk materiality assessments. The company implements a “source control” mecha-
?nancing. feasibility studies with external
risks Strategic planning and resources, squeeze the expert reviews, and establish an nism, dynamically monitoring areas that may pose risks, striving to eliminate identi?ed risk hazards
management risks: Unclear or growth space of core accountability mechanism for
businesses, dilute the value from the root. In addition, our legal department prepares annual compliance reports tailored to differ-
frequently changing strategic decision-making errors.
direction, or lack of an effective of prior investments, and ent business lines, providing in-depth risk analysis and targeted mitigation recommendations. These
strategic implementation and impact long-term competi-
tiveness and the foundation reports serve as key references for managing similar risks. In terms of risk disposal methods and
evaluation system, may affect
of sustainability.
long-term development. approaches, we de?ne clear risk thresholds, establish detailed risk guidelines, and standardize opera-
De?ciencies in internal control Establish a closed-loop accountabil- tional practices, thereby enhancing overall risk management capabilities.
systems: Inadequate or poorly If internal control de?cien- ity mechanism by improving
implemented internal control cies and compliance risks systems, embedding processes,
systems may lead to distorted are not effectively strengthening auditing and
Internal ?nancial reports, asset losses, or managed, they may weaken information-based controls,
operational inef?ciencies. the foundation for value ensuring effective implementation
control Risk identi?cation paths Risk assessment dimensions
Compliance and information creation, increase operation- of systems and manageable risks.
Mid-
and disclosure risks: Failure to ful?ll al management complexity, High
term
Enforce rigorous review
information disclosure and undermine governance procedures, improve governance
compliance obligations in a timely, accurate, effectiveness and market mechanisms, and utilize informa- Business interviews Frequency of risk occurrence
risks and complete manner may lead trust, thereby exerting tion systems and contingency
Monitoring and coordinated handling of Risk losses
to regulatory penalties and pressure on stable measures to ensure timely,
reputational damage. operations and long-term accurate, and complete information litigation, customer complaints, and adminis-
value creation. disclosure, thereby mitigating
regulatory and reputational risks.
trative penalties
Risks and disputes arising from product
compliance and contract performance
Impact, Risk and Opportunity Management
Analysis of national legislation and regulatory
We regard governance and internal control compliance as the cornerstone for development, continuously optimizing our manage- policies relevant to core business operations
ment structure and operational mechanisms. By effectively responding to risks, we enhance governance ef?ciency, achieving a Sources of risks arising from other operations
leap from passive risk control to value creation, thereby solidifying our core competitiveness through high-level governance.
Internal In accordance with the Basic Norms for the Internal Control of Enterprises and its supporting guidelines,
Control we have established and continuously improved our internal control system. We have updated our Risk data monitoring Risk mitigation measures
Manage- Internal Audit Policy and strengthened ongoing monitoring and control activities. Based on regular daily
ment and special supervision, we conduct periodic evaluations of the effectiveness of internal controls, prompt-
Process monitoring and auditing Improve existing policies to
ly rectifying any identi?ed de?ciencies to ensure the effective operation of the internal control system.
Routine advisory and consultation support address control gaps
Internal Control Objectives Policy development and communication Enhance management process-
Comply with national laws, regulations, and Risk awareness training and management es with mandatory controls
Internal Control Measures
other relevant provisions Complaint and whistleblowing channels Strengthen incentive and
Separation of incompatible duties and controls
Safeguard corporate assets accountability mechanisms
Authorization and approval controls
Ensuring truthful, accurate, complete, and fair with clear responsibility
Accounting system controls
information disclosure
Budget controls assignment
Improve operational ef?ciency and effectiveness
Operational analysis controls and performance evaluation controls
Promote the realization of development strate-
Information security control measures, etc.
gies, etc.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Investor Relations
Case: We are committed to the core principles of “respecting, rewarding, and protecting investors,” and
adhere to the guiding principles of compliance, fairness, proactiveness, and integrity. We actively
We leverage the “360 Legal Academy” platform to embed compliance into business scenarios, focusing on
establish diversi?ed communication channels, including earnings brie?ngs, strategy meetings,
preventive compliance guidelines and practical case analysis. This initiative enhances employees’ risk awareness
reverse roadshows, and the SSE e-interactive platform, to facilitate shareholder engagement and
and reduces the likelihood of non-compliant behavior.
enhance communication with both existing and potential investors. These efforts strengthen inves-
tor understanding and recognition of the Company, helping to build a stable and high-quality inves-
tor base while enhancing corporate governance effectiveness and overall enterprise value.
We attach great importance to delivering reasonable returns to investors. Taking into account our current operating condi-
tions, future development strategies, and the need to ensure sustainable operations, we implement cash dividend distribu-
tions in strict accordance with the pro?t distribution policy set out in the Articles of Association, sharing the results of our
development with investors. Since our restructuring and relisting in 2018, we have conducted multiple cash dividend distri-
butions. By the end of 2025, the total amount of cash dividends we distributed was approximately 5.034 billion yuan, of
which the total amount of dividends paid was approximately 3.535 billion yuan, and the total amount spent on share repur-
chases was approximately 1.499 billion yuan. In 2025, we conducted 2 cash dividend distributions. On May 30, 2025, we
distributed a cash dividend of 1 yuan (tax inclusive) for every 10 shares, and on September 30, 2025, we distributed another
cash dividend of 1 yuan (tax inclusive) for every 10 shares, totaling approximately 1.4 billion yuan in cash dividends.
Remuneration Management
Indicators and Targets In accordance with the Company Law and the Articles of Association, we have established the Remuneration Management
Policy for Directors and Senior Management, providing a comprehensive framework for remuneration governance. This
policy ensures fairness and reasonableness in remuneration allocation and serves as a robust institutional foundation for
Targets Progress in 2025 improving corporate governance and supporting the Company’s long-term, stable development.
Proportion of independent directors exceeding 33% Completed
No regulatory penalties for information disclosure violations Completed
Party Building Leadership
The CPC 360 Group Committee consistently adheres to the guidance of Xi Jinping Thought on Socialism
with Chinese Characteristics for a New Era, ?rmly upholding the Company’s strategic positioning as a
“national team in digital security and AI.” It deeply integrates Party building into the Company’s techno-
Information Disclosure and Investor Relations Management
logical innovation and security mission, leveraging high-quality Party building to drive high-quality
corporate development.
Information Disclosure
We strictly comply with internal policies such as the Information Disclosure Management Policy and the Management Policy for
Deferred and Exempted Information Disclosure, and ful?ll our information disclosure obligations in accordance with applicable Strengthening political leadership and implementing national strategic priorities
laws and regulations. We place strong emphasis on the management of insider information, strictly controlling the registra-
Our Party Committee has thoroughly studied and implemented the guiding principles of the 20th National Congress of the
tion and administration of insiders and internal information users to uphold the principles of fairness and transparency in
CPC and the subsequent plenary sessions, making the national strategic deployments of “accelerating the development of
information disclosure and effectively protect the legitimate rights and interests of investors.
new quality productive forces” and “achieving high-level technological self-reliance and strength” the core tasks for the year.
The founder of the group, Zhou Hongyi, published a theoretical article titled “Reshaping Productivity with Agents and
Summary of information disclosure in 2025: Safeguarding Innovation with a Security Foundation,” integrating the overall national security concept into the top-level
design of corporate strategy, promoting the coordinated development of technological innovation and security assurance.
Ad hoc announcements Regulatory penalties related to Our Party Committee, in collaboration with New Security (a publication under People’s Daily), has established a “Party Build-
Periodic reports disclosed: 4
disclosed: 101 information disclosure: None ing + Security + Technology” integrated communication matrix, further enhancing Party members’ and of?cials’ political
judgment, comprehension, and execution capabilities.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Focusing on strategic transformation and driving innovation through Party building
In 2025, the Group have deeply advanced the “ALL IN AGENT” planning, fully entering the ?eld of agents. The Party Commit-
tee implemented the “Red Engine” project, establishing the “AI + Security” Party Member Vanguard Team, which plays a
pivotal role in tackling key technologies, product implementation, and ecological construction. With the support of the Party
Committee, the Group launched an enterprise-level platform covering L2-L4 agents, promoting the deep integration of AI
with various industries. The Party Committee also promoted the establishment of a “Party Building + Security Governance”
mechanism and formed a “Large Model Security Task Force,” embedding security reviews and ethical assessments through-
out the entire lifecycle of agent development to ensure that technology consistently serves national and societal interests.
Municipal Organization Department’s research
The “AI + Security” Party Member Vanguard Team visit on Party building at 360 Group
The Department of Hong Kong, Macao, and
Taiwan Affairs of the Ministry of Foreign Affairs
jointly held a themed Party Day activity with the
Party Committee of 360 Group
The CPC 360 Group Committee collaborated with
Capital Normal University to carry out joint Party
building activities
Anti-Bribery and Anti-Corruption
We consistently regard integrity governance as the cornerstone of our steady and sustainable development. By strength-
Strengthening security foundations and ful?lling the mission
of “Serving the nation through technology” ening institutional frameworks, enhancing internal controls, standardizing external cooperation, and improving
whistleblowing mechanisms, we have built a comprehensive integrity ecosystem in which “corruption is deterred, prevent-
The Party Committee spearheaded the “Red Talent Program,” focusing on ed, and discouraged,” thereby fostering a transparent, compliant, and well-regulated business environment.
cultivating interdisciplinary young professionals pro?cient in both technology
and Party affairs. It has established Party responsibility zones and demonstra-
Improving the Integrity Governance System
tion posts across ?elds such as AI, big data, and cybersecurity, building a
“digital security force” led by Party-member technical experts. To date, the
We place great importance on the development of integrity-relat-
Anti-APT Party Member Group has developed a globally leading cybersecurity big data system, with
ed systems. We have established a series of policies and regula-
Commando Team eight core indicators ranking ?rst domestically.
tions, including the Internal Audit Policy, the Anti-Fraud Management
Policy, the Measures for the Administration of Personnel in Key
Enhancing organizational development and consolidating the foundations of Party building Positions, the Regulations on the Acceptance and Handling of Gifts, the
Whistleblower Protection and Reward Policy, and the Policy on the
The Party Committee strictly implements foundational Party governance mechanisms such as the “Three Meetings and One Management of Permanently Disquali?ed Suppliers. These frame-
Lecture” system and themed Party Day activities. It continues to carry out patriotism education and thematic education works cover key areas such as employee conduct, supplier
initiatives, integrating Party member education and management with the evolving demands of the times. management, and internal auditing.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Strengthening Internal Integrity Controls Training and Awareness Programs
To effectively prevent and combat fraudulent activities, we have established an We regularly conduct integrity-themed publicity, focusing on the interpretation of integrity policies, popularizing integrity
Ethics Committee as the sole independent department responsible for fraud knowledge, case-based warnings, and updates on major integrity-related meetings and initiatives, thereby continuously
investigations, reporting directly to management. When departments discover strengthening company-wide integrity education. Targeted training programs are delivered to different groups, including
suspected fraudulent activities during daily management and inspections, they management, new employees, and various business units, through both online and of?ine channels. These initiatives commu-
should promptly report to the Ethics Committee via the dedicated email (jubaox- nicate the Company’s integrity policies and enhance employees’ understanding of relevant systems. Through diverse forms of
in@360.cn). engagement, we continuously reinforce employees’ awareness of integrity and compliance, fostering a clean, ethical, and
Any violation of the Anti-Fraud Management Policy by employees constitutes a professional working environment.
disciplinary offense. Depending on the severity, disciplinary actions may include
verbal warnings, written warnings, public criticism, or termination of employ-
Fight Against Unfair Competition
ment. In addition, we promote a culture of integrity through company-wide email
noti?cations and internal case-based alerts, fostering a working environment jubaoxin@360.cn
where employees are intrinsically motivated to uphold ethical standards.
We strictly comply with the Law of the People’s Republic of China Against
Unfair Competition and the Anti-Monopoly Law of the People's Republic of
Ensuring Integrity in External Cooperation China, and have developed the 360 Group Anti-Monopoly Compliance
Manual, embedding the principle of fair competition throughout all
We signed the Business Integrity Agreement with all partners, clearly de?ning both parties' commitment to uphold business integ- business operations. We adopt a zero-tolerance stance toward any
rity standards and completely eliminate commercial bribery, thereby building a solid integrity defense. In accordance with the conduct that undermines fair market competition, actively combating
Policy on the Management of Permanently Disquali?ed Suppliers, any supplier involved in fraudulent activities will be placed on a unfair competition and monopolistic practices, safeguarding a healthy
“permanently disquali?ed supplier” list, prohibiting all departments from engaging in any form of cooperation with such and orderly market environment, and contributing to the sustainable
entities. In exceptional circumstances where cooperation is deemed necessary, special approval and ?ling procedures must be development of the industry. The 360 Group Anti-Monopoly Compliance
completed. Manual systematically covers key areas, including updates on anti-mo-
nopoly regulations, merger control, monopoly agreements, abuse of
Improving the Whistleblower Protection Mechanism dominant market position, and practical compliance guidance, providing
a solid institutional foundation for antitrust compliance management.
We encourage all employees and partners to actively report fraudulent activities. Dedicated reporting channels, including a
In practice, the Legal and Compliance Department conducts a comprehensive review of historical transactions to identify
reporting email and hotline, have been established, and veri?ed reports are eligible for rewards. The Ethics Committee prioritiz-
potential risks of failure to ?le merger control noti?cations as required by law. With the support of external professional
es con?dentiality during fraud investigations, and implements strict control processes for report acceptance and investigation,
advisors, such risks are assessed by category and recti?cation measures are implemented accordingly. In the proposed invest-
ensuring the personal information and reporting materials of whistleblowers are kept con?dential. For real-name reports, the
ment and merger transactions, we perform ex-ante analyses of merger control ?ling obligations, with assessment results
Committee has established a special “protection list,” with designated personnel responsible for communication, rewards, and
serving as a key basis for internal approval. During contract review, particular attention is paid to the risk of monopoly agree-
protection. Any breach of con?dentiality obligations will result in strict disciplinary action, and where criminal conduct is
ments. Standard-form contracts, joint procurement agreements, and joint sales agreements are subject to enhanced ex-ante
involved, legal liability will be pursued in accordance with the law.
review. For product lines with competitive advantages, we strengthen the identi?cation and prevention of potential self-pref-
erencing or exclusionary conduct. All such matters must be reviewed by the Legal and Compliance Department. In addition,
antitrust compliance has been incorporated into departmental and employee performance evaluation systems to reinforce
Reporting Channels: accountability.
In terms of publicity and training, we promote the antitrust compliance
Email: Online: through multiple internal channels, including our intranet, announcements,
and email communications, requiring all employees to complete online video
Submit reports to jubaoxin@360.cn Follow the of?cial WeChat account “360 Ethics
training to ensure broad-based awareness of antitrust principles. For key
Committee” and submit reports as instructed
departments and personnel in critical positions, we organize specialized
training to further enhance understanding and execution. In 2025, the Legal
Compliance Department conducted a series of thematic training sessions on
Mail: In-person: anti-unfair competition, combining both online and of?ine formats, across
Send correspondence to “Block B, 360 Building, No. 6 Make an appointment and submit reports at designat- multiple business segments, including internet and gaming operations. These
Jiuxianqiao Road, Chaoyang District, Beijing” (Recipient: ed reception locations initiatives have continuously enhanced legal risk awareness among our
Ethics Committee) business units and effectively mitigated risks related to unfair competition.
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Key Performance Table
Indicator Unit 2025 Indicator Unit 2025
Environmental Social
Direct GHG emissions (Scope 1) tCO2e 255.80 Employee work injury insurance coverage rate % 100
Indirect GHG emissions (Scope 2) tCO2e 11,686.93 Safety drill coverage rate % 100
Total GHG emissions tCO2e 11,942.73 R&D personnel as a percentage of our workforce % 57.23
GHG emission intensity tCO2e per million yuan in revenue 1.37 R&D spending as a percentage of our operating revenue % 37.11
Diesel consumption tons 1.22 Funding for rural revitalization yuan About 400,000
Gasoline consumption tons 8.57
Governance
Natural gas consumption Standard cubic meters 104,475
Meetings held by the Board of Shareholders / 3
Electricity consumption MWh 22,025.87
Unapproved proposals by the Board of Shareholders,
/ 0
Total energy consumption TCE 2,860.32 the Board of Directors, and the Supervisory Board
Comprehensive energy consumption intensity TCE per million yuan in revenue 0.33 Meetings held by the Board of Directors / 6
Total water resource consumption tons 139,099 Meetings held by the Supervisory Board (before cancellation) / 3
Water resource consumption intensity tons per million yuan in revenue 16.00 Number of independent directors / 3
Proportion of independent directors % 60
Social
Periodic reports disclosed / 4
Total number of employees / 5,273
Ad hoc announcements disclosed / 101
Number of employees with master's degrees or higher / 1,068
Number of employees with bachelor's degrees / 3,561
Number of employees with associate degree / 542
Number of employees with other degrees / 102
Number of R&D personnel / 3,018
Number of salespeople / 1,759
Number of management personnel / 496
General staff training participation rate % 100
Investment in work-related injury insurance yuan over 4,000,000
ABOUT 360 SECURITY MATERIALITY ASSESSMENT ESG GOVERNANCE FRAMEWORK ENVIRONMENTAL COMMITMENT SOCIAL COMMITMENT GOVERNANCE COMMITMENT 2025 Environmental, Social and Governance (ESG) Report
Report Index
Guidelines No. 14 of Shanghai Stock Guidelines No. 14 of Shanghai Stock
Contents Exchange for Self-Regulation of Listed Compa- GRI Standards 2021 Contents Exchange for Self-Regulation of Listed Compa- GRI Standards 2021
nies — Sustainability Report (Trial) nies — Sustainability Report (Trial)
Report Preface Article 6 2-2 / 2-3 Social Commitment
Message from the Chairman / 2-6/2-22 2-7/2-23/2-24/201-1
About 360 Security /201-3/401-1/401-2/403-1
Employees Article 49, 50
Company Pro?le / 2-1 /403-2/403-3/403-5/403-9/404-1
Our Corporate Culture / / /404-2/405-1/406-1
Our Business / 2-6 2-23/2-24/2-25/2-26/416-1
Safety and Quality of Products and Services Article 47
Our Honors for the Year / / /416-2/417-1/417-2/417-3
Data Security and Customer Privacy Protection Article 48 2-23/2-24/418-1
Materiality Assessment
Innovation-Driven Development Article 41, 42 2-4/2-23/2-24
Due Diligence and Stakeholder Engagement Article 9, 53 3-1/2-14/2-23/2-29
Ethics in Science and Technology Article 43 2-23/2-24
Double Materiality Assessment Article 5 3-1
Win-Win Cooperation Article 45, 46 2-23/2-24/2-25/308-2/414-1
Materiality Assessment Results Article 5 3-1/3-2/3-3
Rural Revitalization Article 39 201-1/203-1/203-2
ESG Governance Framework
Sustainability Governance Framework Article 12 2-9 2-4/2-23/2-24/201-1/203-1/203-2
Social Contribution Article 40
Sustainability Management Mechanisms Article 12 2-11/2-12/2-13/2-18 /413-1/413-2/415-1
ESG Capability Improvement Article 12 2-17 Governance Commitment
Environmental Commitment 2-9/2-13/2-16/2-23/2-24
Corporate Governance Mechanism Article 51
/2-29/207-1/207-2
Climate Change Response Articles 21 to 27 2-4/2-23/2-24/201-2/305-1/305-2/305-4
Remuneration Management / 2-19/2-20/2-23/2-24
Environmental Compliance Management Article 33 2-23/2-24 Party Building Leadership / /
Anti-Bribery and Anti-Corruption Article 55 2-23/2-24/2-26/205-2
Pollutant and Waste Management Articles 30 and 31 2-4/2-23/2-24/303-2/306-1/306-2/306-3
Fight Against Unfair Competition Article 56 2-23/2-24
Key Performance Table / /
Energy Consumption Articles 34 to 35 2-4/2-23/2-24/302-1/302-3/302-4/302-5
Report Index / /
Water Resource Consumption Article 36 2-4/2-23/2-24/303-5
Circular Economy Article 37 2-23/2-24/301-1/301-2
Ecosystem and Biodiversity Conservation Article 32 304-3