A Dark Vector Cognition product

Item 9A. Controls and Procedures

4K characters. Original on sec.gov · Markdown

Item 9A. Controls and Procedures

Evaluation of Disclosure Controls and Procedures

Our management, with the participation of our chief executive officer and chief financial officer, evaluated the effectiveness of our disclosure controls and procedures pursuant to Rule 13a-15(b) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”). In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives. In addition, the design of disclosure controls and procedures must reflect the fact that there are resource constraints and that management is required to apply its judgment in evaluating the benefits of possible controls and procedures relative to their costs.

Based on our evaluation, our chief executive officer and chief financial officer concluded that, as of July 31, 2026, our disclosure controls and procedures are designed at a reasonable assurance level and are effective to provide reasonable assurance that information we are required to disclose in reports that we file or submit under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in Securities and Exchange Commission (“SEC”) rules and forms, and that such information is accumulated and communicated to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding required disclosure.

Management’s Annual Report on Internal Control over Financial Reporting

Our management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in Rule 13a-15(f) under the Exchange Act. Our management assessed the effectiveness of our internal control over financial reporting as of July 31, 2026, based on the framework set forth by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”) in Internal Control - Integrated Framework (2013 framework). In accordance with guidance issued by the SEC staff, companies are permitted to exclude acquisitions from their assessment of internal control over financial reporting for the first fiscal year in which the acquisition occurred. Our assessment of the effectiveness of our internal control over financial reporting as of July 31, 2026 excluded CyberArk, which we acquired on February 11, 2026. We have included the financial results of CyberArk in our consolidated financial statements since the date of acquisition, which constituted 2% of total consolidated assets, less than 1% of total consolidated net assets, and 6% of total consolidated revenue as of and for the year ended July 31, 2026. Based on that assessment, management concluded that, as of July 31, 2026, our internal control over financial reporting was effective.

The effectiveness of our internal control over financial reporting as of July 31, 2026 has been audited by Ernst & Young LLP, the independent registered public accounting firm that audits our consolidated financial statements, as stated in their attestation report which is included in Part II, Item 8 of this Annual Report on Form 10-K.

Changes in Internal Control over Financial Reporting

There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) under the Exchange Act that occurred during the fiscal quarter ended July 31, 2026 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

- 104 -

Previous: Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure · Next: Item 9B. Other Information