1. Purpose & Scope
This Code applies to all who act on behalf of Benegon Enterprises LLC worldwide. It complements our Human Rights Policy, Conflict Minerals Policy, Supplier Code, Data Protection, and Security standards. When local law sets a lower standard than this Code, we follow this Code; when the law is stricter, we follow the law.
2. Our Core Principles
- Integrity: Do the right thing, even when no one is watching.
- Respect: Treat people with dignity, value diverse perspectives, and foster inclusion.
- Safety & Security: Build products that are safe, reliable, and secure.
- Privacy: Handle data responsibly and minimize collection.
- Accountability: Own outcomes, report issues, and fix root causes.
- Transparency: Communicate honestly with customers, partners, and regulators.
3. Legal & Regulatory Compliance
- Follow all applicable laws (e.g., labor, privacy, cybersecurity, safety, environmental, competition, anti-bribery).
- Comply with contractual obligations and industry standards relevant to software/hardware development.
- Never direct or assist others to evade the law.
4. Conflicts of Interest
A conflict exists when personal interests could improperly influence professional judgment.
Examples
- Outside employment with a supplier, competitor, or customer.
- Family/romantic relationships in reporting lines or vendor selection.
- Personal investments that could affect impartiality.
What to Do
- Disclose potential conflicts to your manager and Compliance before acting.
- Recuse yourself from decisions where you aren’t impartial.
5. Anti-Corruption, Gifts & Hospitality
- Zero tolerance for bribery, kickbacks, facilitation payments, or improper advantages—direct or via third parties.
- Gifts/meals must be modest, infrequent, lawful, and never to influence or reward a decision. Extra caution with public officials.
- Record gifts/expenses accurately and obtain required pre-approvals.
6. Intellectual Property & Confidentiality
- Protect Company and third-party confidential information, trade secrets, customer data, designs, source code, SBOMs, and keys.
- Use NDAs where appropriate; share on a need-to-know basis; follow clean-desk and secure-repo practices.
- Respect others’ IP—no unauthorized copying, reverse engineering, or use of unlicensed assets.
7. Open Source & Third-Party Code
- Use third-party and open-source software only with proper license review and approval.
- Honor license obligations (e.g., attribution, source disclosure, copyleft requirements); maintain an up-to-date SBOM.
- Do not import code with unclear origin or incompatible licenses.
- Security-scan dependencies; patch vulnerabilities promptly.
8. Security-by-Design & Responsible Disclosure
- Follow secure SDLC: threat modeling, code review, static/dynamic analysis, dependency scanning, and security testing.
- Protect secrets: use credential vaults; never hardcode secrets or introduce backdoors.
- Report suspected vulnerabilities immediately to Security; do not test production without authorization.
- Support a public vulnerability disclosure policy and coordinate fixes; honor embargoes and CVE processes where applicable.
- For hardware: safeguard boot chains, firmware updates, debug ports, and supply-chain security (e.g., secure provisioning).
9. Privacy-by-Design & Data Ethics
- Collect the minimum personal data necessary; use lawful bases; give users clear choices.
- Apply data minimization, purpose limitation, encryption, and retention limits.
- Access customer data only for legitimate business needs; log access; prohibit misuse or personal curiosity (“snooping”).
- Delete or anonymize data when no longer needed and respond to data subject requests per law.
10. Product Safety, Hardware Integrity & Compliance
- Design and test for safety, EMC, environmental, and regulatory requirements (e.g., CE, UKCA, FCC, UL/IEC where applicable).
- Ensure accurate specifications and truthful claims; no deceptive benchmarks or hidden limitations.
- Manage component provenance; avoid counterfeit parts; track changes via ECOs and maintain traceability.
11. Responsible AI/ML Engineering (if applicable)
- Assess models for bias, safety, misuse risk, and privacy leakage; document datasets and model cards.
- Prohibit uses that enable unlawful surveillance, discrimination, or significant harm.
- Label synthetic media where relevant and implement safeguards proportional to risk.
12. Trade Compliance, Sanctions & Export Controls
- Comply with export control and sanctions laws (e.g., EAR/ITAR, OFAC/EU/UK regimes), including for encryption and dual-use tech.
- Screen customers, partners, and shipments; obtain licenses where required; keep accurate customs documentation.
13. Fair Competition & Marketing
- Compete on merit. No price-fixing, bid-rigging, market/customer allocation, or sharing sensitive competitive information.
- Advertising and comparisons must be truthful and evidence-based.
14. Workplace Conduct, DEI & Anti-Harassment
- Respect and professionalism are mandatory. Harassment, discrimination, bullying, or retaliation are prohibited.
- Provide equitable opportunity, reasonable accommodations, and accessible products and workplaces.
- Substance abuse and workplace violence are not tolerated.
15. Environmental & Supply-Chain Responsibility
- Minimize environmental impact (energy use, e-waste, hazardous substances). Support repairability and responsible end-of-life.
- Follow our Conflict Minerals Policy; prefer responsible smelters/refiners and maintain traceability.
- Expect suppliers to uphold equivalent ethical, labor, and environmental standards.
16. Accurate Records & Financial Integrity
- Maintain complete, accurate, and timely records (engineering logs, test results, expenses, invoices, timekeeping).
- No undisclosed funds, side letters, or falsification. Retain records per policy and legal requirements.
17. Communications & Social Media
- Only authorized spokespersons speak for the Company. Protect confidential information in public forums.
- Be respectful and factual online; label personal opinions as your own; follow disclosure rules for endorsements.
19. Training, Governance & Enforcement
- Mandatory onboarding and periodic training; role-specific modules for engineers, procurement, and sales.
- Violations may result in corrective action up to and including termination of employment or business relationships.
- The Board or designated committee oversees ethics and compliance program effectiveness.