Supplier Code of Conduct

Last Updated: September 2026

PREAMBLE

YugabyteDB, Inc. (“Yugabyte”) operates with integrity, transparency, and accountability in everything we do. We hold ourselves to high ethical standards, as reflected in Yugabyte’s Code of Conduct, and expect the same from the companies and individuals we work with.

This Supplier Code of Conduct (this “Code”) sets forth the minimum standards that apply to all Suppliers engaged by Yugabyte. For purposes of this Code, “Suppliers” means vendors, consultants, contractors (including subcontractors), and other third-party service providers that do business with Yugabyte.

This Code supplements, and does not replace, any existing contractual obligations between a Supplier and Yugabyte. Where this Code and applicable law address the same subject matter, the stricter standard governs. Where compliance with any provision of this Code would violate applicable law, the law controls.

A violation of this Code constitutes a material breach of the Supplier’s contractual relationship with Yugabyte and may result in termination of that relationship.

Suppliers are expected to communicate the principles of this Code to their own subcontractors and suppliers engaged in connection with work for Yugabyte, and to take reasonable steps to monitor their compliance.

1. ETHICAL CONDUCT

1.1 Integrity and Honest Dealing. Suppliers must conduct all business with Yugabyte honestly and in good faith. Suppliers must not take unfair advantage of anyone through manipulation, concealment, misrepresentation, or abuse of privileged information.

1.2 Conflicts of Interest. Suppliers must avoid transactions or relationships that create, or appear to create, conflicts between their interests and those of Yugabyte. Any actual or potential conflict must be disclosed promptly to the Supplier’s primary Yugabyte contact.

1.3 Securities Laws. Suppliers who receive material non-public information about Yugabyte or any other company through their engagement must not trade in those companies’ securities or share that information with others. Suppliers must comply with all applicable securities laws and their own internal trading policies. Yugabyte is currently a private company; this obligation extends to information about any publicly traded company that a Supplier may access through its work with Yugabyte.

1.4 Accurate Records and Financial Reporting. Suppliers must maintain complete, accurate, and timely books and records in compliance with applicable legal and regulatory requirements. Undisclosed or unrecorded funds, assets, or accounts are prohibited regardless of purpose. Suppliers must not misrepresent pricing information or the justification for any discount or margin request.

1.5 Gifts, Meals, and Entertainment. Any gifts, meals, or entertainment offered to Yugabyte personnel must be of modest value, connected to a legitimate business purpose, and consistent with applicable law. Suppliers must not offer anything of value that is intended, or could reasonably be perceived, as influencing a business decision. Cash and cash equivalents (including gift cards) may not be offered to Yugabyte personnel under any circumstances. Suppliers who are uncertain whether a particular courtesy is permissible should contact their primary Yugabyte contact before extending it.

2. LEGAL COMPLIANCE

2.1 Anti-Corruption. Yugabyte conducts its business free from bribery, extortion, and fraud. Suppliers must comply with all applicable anti-corruption laws, including the U.S. Foreign Corrupt Practices Act and the UK Bribery Act 2010. Suppliers must not offer, promise, or provide bribes, kickbacks, improper gifts or hospitality, or anything of value to influence an official act or purchasing decision.

2.2 Fair Competition. Suppliers must comply with all applicable antitrust and competition laws. Suppliers must not engage in price-fixing, bid-rigging, market allocation, or any other anticompetitive conduct. Suppliers should exercise particular care in any communications with competitors concerning Yugabyte’s business.

2.3 Data Privacy and Security. Suppliers must comply with all applicable privacy and data protection laws, including, where applicable, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other regional data protection requirements. Personal information acquired or accessed in connection with work for Yugabyte must be collected, used, stored, and transferred with appropriate safeguards and in accordance with applicable legal requirements. Suppliers that process personal data on Yugabyte’s behalf must do so only as authorized by Yugabyte and must promptly notify Yugabyte of any data subject requests related to Yugabyte data.

2.4 Trade Compliance and Export Controls. Suppliers must comply with all applicable trade, export control, and sanctions laws and regulations, including U.S. trade sanctions, in connection with their work for Yugabyte.

3. INTELLECTUAL PROPERTY AND CONFIDENTIALITY

Suppliers must respect the intellectual property rights of Yugabyte, its customers, and third parties, including patents, trademarks, copyrights, and trade secrets. Such rights may be used only as expressly authorized by valid licenses or contractual provisions. No implied license or right of ownership is granted by virtue of a Supplier’s engagement with Yugabyte.

“Confidential Information” means all non-public information, whether disclosed orally, in writing, electronically, or by any other means, that is provided by or on behalf of Yugabyte to a Supplier, or that a Supplier otherwise obtains through its engagement with Yugabyte. Confidential Information includes, without limitation, technical data, product plans, source code, business strategies, financial information, customer lists, and employee information.

Suppliers must protect Yugabyte’s Confidential Information against unauthorized access, use, or disclosure. Suppliers must comply with all Yugabyte requirements and procedures for password management, network access, system security, and physical access to Yugabyte facilities. Confidential Information may be shared within a Supplier’s organization only on a need-to-know basis and subject to obligations of confidentiality no less protective than those owed to Yugabyte.

If a Supplier becomes aware of any unauthorized use of Yugabyte’s intellectual property or Confidential Information, or any security incident involving Yugabyte data, the Supplier must notify Yugabyte promptly at security@yugabyte.com. The notification must include all known details of the incident and the steps taken or planned to contain it.

Suppliers must not input Yugabyte Confidential Information into external or public artificial intelligence tools, platforms, or services that have not been approved in writing by Yugabyte for that purpose. Suppliers who use AI tools to generate work product for Yugabyte must review that output for accuracy, bias, and appropriateness before delivery. Suppliers remain responsible for the quality and integrity of all deliverables provided to Yugabyte, regardless of whether AI tools were used in their preparation.

4. WORKPLACE STANDARDS AND HUMAN RIGHTS

4.1 Dignity and Respect. Suppliers must maintain a workplace grounded in dignity, safety, and respect, free from discrimination, exploitation, and harassment of any kind. Yugabyte values inclusion and will not maintain business relationships with companies that fail to uphold these principles. Yugabyte may, at its discretion, remove from its premises any Supplier personnel who engage in harassing or offensive conduct. Suppliers must promptly report to Yugabyte management any such conduct involving Yugabyte or Supplier employees.

4.2 Labor Practices and Human Rights. Suppliers must comply with all applicable labor laws and modern slavery legislation, including the UK Modern Slavery Act 2015. Specifically, Suppliers must:

  • Treat workers with respect and observe rights to freedom of association and collective bargaining in accordance with applicable law.
  • Prohibit forced, involuntary, indentured, bonded, or compulsory labor, and any engagement in human trafficking.
  • Prohibit child labor and employ only individuals who meet the minimum working age requirements in each jurisdiction where they operate.
  • Comply with all applicable wage, hour, and overtime requirements.
  • Maintain working conditions that comply with all applicable occupational health and safety laws.

5. ENVIRONMENTAL STEWARDSHIP

Suppliers must comply with all applicable environmental laws and regulations, including requirements related to permits, hazardous materials management, emissions reporting, and waste disposal.

Suppliers should actively work to reduce their carbon footprint, conserve natural resources, minimize waste, and promote recycling and reuse in their operations. Where feasible, Suppliers should set measurable targets for environmental improvement and track progress against those targets.

Yugabyte prefers to partner with Suppliers that demonstrate a genuine, measurable commitment to environmental sustainability. Yugabyte may consider a Supplier’s environmental record and sustainability practices when evaluating proposals, renewing agreements, or making sourcing decisions.

6. OVERSIGHT AND ACCOUNTABILITY

Yugabyte expects Suppliers to uphold this Code throughout the duration of their engagement and to maintain records sufficient to demonstrate their compliance with each applicable provision.

Yugabyte reserves the right to request evidence of compliance at any time, including documentation, certifications, audit reports, or other materials reasonably related to the obligations set forth in this Code. Suppliers must cooperate fully and promptly with any such request.

Suppliers must also cooperate fully with any investigation conducted by Yugabyte, or by a third party acting on Yugabyte’s behalf, into potential violations of this Code. This obligation includes providing timely access to relevant personnel, records, and facilities.

Where Yugabyte determines that a violation of this Code has occurred, or where the nature of the alleged conduct warrants, Yugabyte may refer the matter to appropriate law enforcement or regulatory authorities.

7. GENERAL PROVISIONS

This Code does not create any rights, benefits, or causes of action for any third party. No employee, agent, or representative of any Supplier acquires any rights against Yugabyte under this Code, whether by contract, estoppel, or otherwise.

No employee of any Supplier may compel Yugabyte to enforce any provision of this Code against the Supplier or any other party. Yugabyte’s decision whether to enforce, waive, or modify any requirement of this Code rests entirely with Yugabyte.

The failure by Yugabyte to enforce any provision of this Code on any occasion shall not constitute a waiver of Yugabyte’s right to enforce that provision or any other provision in the future.

8. QUESTIONS AND REPORTING

Yugabyte welcomes questions and concerns about this Code or any aspect of the business relationship. Suppliers should direct general inquiries to their primary Yugabyte contact.

Any Supplier who believes that a Yugabyte employee, or anyone acting on Yugabyte’s behalf, has engaged in unlawful or unethical conduct should report the concern to legal@yugabyte.com. Suppliers may also raise concerns through Yugabyte’s confidential ethics hotline at https://app.goethena.com/hotline/6c192f6f. Reports may be submitted anonymously where permitted by applicable law.

Payment and billing inquiries should be directed to the Supplier’s designated Yugabyte contact.

Yugabyte strictly prohibits retaliation against any individual who raises concerns, seeks guidance, or reports potential misconduct in good faith. Any Supplier who believes that retaliatory action has been taken in response to a good-faith report should immediately notify legal@yugabyte.com.