v3.26.1
Cybersecurity Risk Management, Strategy, and Governance Disclosure
12 Months Ended
Jun. 30, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

ITEM 1C. CYBERSECURITY

Cybersecurity Risk Management and Strategy

We recognize the importance of information security practices designed to protect the confidentiality, integrity, and availability of company information and the personal information that we process. Cybersecurity risk management is an integral part of our overall enterprise risk management efforts, using a framework based on applicable regulations, industry standards, and recognized best practices. Through this framework, we devote significant resources to identifying, monitoring, assessing, and responding to cybersecurity threats and incidents, including those associated with our use of third-party software, applications, services, and cloud infrastructure.

Our Cybersecurity Program includes multiple policies, procedures, and other components designed to identify, analyze, and respond to cybersecurity risks, including a layered system of preventative and detective technologies and controls designed to detect, mitigate, and contain cybersecurity threats. We maintain a Written Information Security Plan that outlines internal controls and procedures designed to protect our information systems. Our policies are commensurate with companies in our industry of similar size and sophistication, and are informed by the sensitivity of our data processing activities, and include business continuity, disaster recovery, and incident response. We also have access through our insurer to computer forensics firms and specialized legal counsel in case of a cybersecurity incident, and maintain cybersecurity insurance to assist in the cost of recovery, though such coverage may not be sufficient to cover all costs resulting from such incidents.

We leverage qualified third-party consultants, advisors, counsel, and other experts to inform, audit, and update our Cybersecurity Program throughout the year, including security assessors who identify vulnerabilities through internal and external penetration tests and cybersecurity maturity assessments. We perform risk assessments annually, or more frequently if circumstances require, and may also be subject to examinations or disclosures by applicable regulators. We conduct annual cybersecurity training for employees to enhance awareness of how to detect and respond to cybersecurity threats, periodic phishing training and testing campaigns, and periodic table-top exercises to simulate a response to a cybersecurity incident.

Our designated IT team members monitor cybersecurity threats in real time for the Company at the enterprise level, with the assistance of third-party threat detection and monitoring software, as well as at the subsidiary level by experienced IT professionals. These individuals report cybersecurity incidents immediately to designated senior members of our IT and Legal Departments, who follow approved incident response and reporting protocols.

We also maintain a formal Vendor Management Program that provides oversight of cybersecurity risks related to our vendor relationships. During vendor onboarding, we perform risk-based due diligence, with heightened requirements for vendors that access confidential enterprise information, personal data or our information systems. This Vendor Management Program includes specific cybersecurity requirements for our vendors, as well as ongoing monitoring, assessment, and contract review. The Vendor Management Program is overseen by members of the Company's IT and Legal Departments.

We also maintain a formal Generative Artificial Intelligence ("GAI") Policy and Program that provides oversight of cybersecurity, privacy, and contractual risks related to enterprise use of GAI. All GAI tools and use cases must be submitted for review and approval by the Company’s AI Review team, comprised of members of the Company's IT and Legal Departments.

The Gold.com General Counsel, Chief Privacy Officer ("CPO"), IT leadership, and other representatives from the Company and its subsidiaries, including top-level management, ensure enterprise-wide implementation and consistent application of the Company’s data security, privacy, vendor management, and artificial intelligence policies and procedures.

To date, we have not identified any risks from cybersecurity threats, including from any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, the sophistication of and risks from cybersecurity threats and incidents continue to increase, and our preventative actions may not successfully protect against all cybersecurity threats and incidents. For more information on the risks that we face from cybersecurity threats, see “Risk Factors – Risk Factors of General Applicability—Legislatures and regulators continue to scrutinize cybersecurity management and incident reporting.” in Part 1, Item 1A of this report.

Cybersecurity Governance

The Board has overall responsibility for risk oversight and has delegated oversight of our Cybersecurity Program, including enterprise-wide risk assessment and management, to the Company and subsidiary IT and Legal Departments. These Departments oversee and approve all Company policies and procedures related to cybersecurity and ensure that significant cybersecurity issues or concerns are reported to the Board and Gold.com's CEO and disclosed to the public, individuals, or regulators where required by law.

The Company IT leadership and CPO directly oversee information technology and information security risks through regular quarterly meetings and related risk assessments. Under the Company’s Incident Response Plan, if a cybersecurity threat is identified, it is escalated to our IT leadership and CPO. Once the threat has been analyzed, our IT leadership and CPO will inform our General Counsel or her delegate, who will then report the incident, as appropriate, to our CEO, President, CFO, impacted subsidiary management, and to the Board, either at the next scheduled meeting or on a current basis, depending on the severity of the incident. Each quarter, the enterprise CPO presents legal and regulatory updates concerning cybersecurity, security incident response and notification, privacy, and artificial intelligence. Gold.com’s CPO is certified by the International Association of Privacy Professionals as an EU, US, and management privacy professional, as well as an artificial intelligence governance professional. Our CPO has over a decade of privacy, data protection, and information management experience.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We recognize the importance of information security practices designed to protect the confidentiality, integrity, and availability of company information and the personal information that we process. Cybersecurity risk management is an integral part of our overall enterprise risk management efforts, using a framework based on applicable regulations, industry standards, and recognized best practices.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] we have not identified any risks from cybersecurity threats, including from any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. However, the sophistication of and risks from cybersecurity threats and incidents continue to increase, and our preventative actions may not successfully protect against all cybersecurity threats and incidents. For more information on the risks that we face from cybersecurity threats, see “Risk Factors – Risk Factors of General Applicability—Legislatures and regulators continue to scrutinize cybersecurity management and incident reporting.
Cybersecurity Risk Board of Directors Oversight [Text Block] The Board has overall responsibility for risk oversight and has delegated oversight of our Cybersecurity Program, including enterprise-wide risk assessment and management, to the Company and subsidiary IT and Legal Departments. These Departments oversee and approve all Company policies and procedures related to cybersecurity and ensure that significant cybersecurity issues or concerns are reported to the Board and Gold.com's CEO and disclosed to the public, individuals, or regulators where required by law.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] We also maintain a formal Generative Artificial Intelligence ("GAI") Policy and Program that provides oversight of cybersecurity, privacy, and contractual risks related to enterprise use of GAI.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] All GAI tools and use cases must be submitted for review and approval by the Company’s AI Review team, comprised of members of the Company's IT and Legal Departments.
Cybersecurity Risk Role of Management [Text Block] Each quarter, the enterprise CPO presents legal and regulatory updates concerning cybersecurity, security incident response and notification, privacy, and artificial intelligence.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Once the threat has been analyzed, our IT leadership and CPO will inform our General Counsel or her delegate, who will then report the incident, as appropriate, to our CEO, President, CFO, impacted subsidiary management, and to the Board, either at the next scheduled meeting or on a current basis, depending on the severity of the incident.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] We leverage qualified third-party consultants, advisors, counsel, and other experts to inform, audit, and update our Cybersecurity Program throughout the year, including security assessors who identify vulnerabilities through internal and external penetration tests and cybersecurity maturity assessments.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Under the Company’s Incident Response Plan, if a cybersecurity threat is identified, it is escalated to our IT leadership and CPO. Once the threat has been analyzed, our IT leadership and CPO will inform our General Counsel or her delegate, who will then report the incident, as appropriate, to our CEO, President, CFO, impacted subsidiary management, and to the Board, either at the next scheduled meeting or on a current basis, depending on the severity of the incident.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true