v3.26.3
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Apr. 30, 2026
Cybersecurity Risk Management, Strategy, and Governance [Abstract]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Cybersecurity risk 

Cybersecurity risk is the risk of harm or loss resulting from misuse or abuse of technology or the unauthorized disclosure of data.

 

Overview

 

To preserve the confidentiality, integrity, and availability of our information systems, and to safeguard our assets, data, intellectual property, and network infrastructure, while meeting regulatory requirements, it is crucial to effectively manage cybersecurity risk. To achieve this, we have implemented a comprehensive cybersecurity risk management framework, which is integrated into our overall enterprise risk management system and processes and is internally managed.

 

Our IT staff is tasked with assessing, identifying, and managing cybersecurity threats and is responsible for:

 

  ● risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, and services and to our broader enterprise IT environment;
     
  ● development of risk-based action plans to manage identified vulnerabilities and implementation of new protocols and infrastructure improvements;
     
  ● cybersecurity incident investigations;
     
  ● monitoring threats to sensitive data and unauthorized access to our systems;
     
  ● applying access control measures to critical IT systems, equipment, and devices, which measures are designed to prevent unauthorized users, processes, and devices from accessing IT systems and data;
     
  ● developing and executing protocols to ensure that information regarding cybersecurity incidents is shared promptly with the Board, as appropriate, to allow for risk and materiality assessments and to consider disclosure and notice requirements; and
     
  ● developing and implementing training on cybersecurity, information security, and threat awareness.

 

There were no cybersecurity incidents during the financial year ended April 30, 2026, that resulted in an interruption to our operations or known losses of any critical data or that otherwise had a material impact on our business strategy, financial condition, or results of operations. However, the scope and impact of any future incident cannot be predicted. See Item 1A, “Risk Factors,” for more information on how material cybersecurity attacks might impact our business.

 
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Board of Directors Oversight [Text Block] Governance and oversight 

Our Board acknowledges the significance of robust cybersecurity management programs and actively participates in overseeing and reviewing our cybersecurity risk profile and exposures. At Rafael AI, where our business has particular cybersecurity requirements, we have in-house security engineers responsible for end-to-end internal governance over corporate cybersecurity, data security, and AI-model-related security. Professional third-party security vendors are retained to support the delivery of cybersecurity-related activities. Given the size and nature of our other operations, we currently do not maintain a separate cybersecurity department or a dedicated cybersecurity management function covering our other businesses. We do, however, contract with a third-party cybersecurity company for support on an as-needed basis, and the Board and management consider cybersecurity risks in connection with their overall assessment and oversight of operational and business risks.

 
Cybersecurity Risk Role of Management [Text Block] Our Board acknowledges the significance of robust cybersecurity management programs and actively participates in overseeing and reviewing our cybersecurity risk profile and exposures.