Security Measurement
Security Policy
We prioritize security to ensure you can use our services with complete confidence.
Data Security
-
Highly reliable data center
We use Amazon Web Service (AWS) as our data center. AWS is a data center with a rich operational track record both in Japan and overseas, and has been certified and approved by many third-party organizations. As a general rule, customer usage data is stored on AWS servers in Japan (Tokyo region).
-
Regular data backup
We regularly back up data for the entire system. In the event of a natural disaster or system trouble, we can restore from the backup data. * For data recovery operations resulting from your own operational errors, etc., please use the separate "Backup Function."
-
Data Center Redundancy
It has a redundant configuration that uses multiple physically separated data centers, so data will not be lost in the event of a large-scale disaster.
Operational Safety
-
Operational structure in accordance
with international security standardsWe have obtained the international standard "ISO27001" for Information Security Management Systems (ISMS) and "ISO27017" for ISMS Cloud Security, and operate in accordance with strict security standards.
-
Server monitoring and
troubleshooting systemThe server is monitored 24 hours a day, 365 days a year, and if an abnormality is detected, the person in charge is notified immediately.
The person in charge will immediately take measures to restore the server depending on the situation.
-
Preparation of development guidelines
We provide our customers with stable and safe services by establishing in-house development guidelines and carrying out development in accordance with them.
Preventing unauthorized use or access
-
Minimal server and data management
Access to the server is limited to system operation personnel, and data stored on the server is only accessed when requested by the customer, such as for research purposes.
-
Blocking unauthorized access
We constantly monitor access to our servers, and provide alerts and obtain logs of any unauthorized access.
-
Communication encryption
Both the PC and mobile versions encrypt communications using SSL, so even if a third party intercepts your communications, they will not be able to learn the content.
-
Conducting vulnerability assessments
Regular inspections are conducted by a third party and the system is generally evaluated as being robust against unauthorized access.
・Web application vulnerability inspection (last conducted: April-June 2024)
・Platform inspection (last conducted: December 2024)
Functions that support operational safety
-
Password and permission management
Users added to a customer's own "group" are managed with a password. Furthermore, the customer (administrator) can set the editing and viewing permissions for the data within the group.
-
Access management and blocking for
each deviceIf a device is lost or stolen, access can be blocked not only on a per-user basis but also on a per-device basis. When access is blocked, any manual data cached on the device is also cleared.
-
Restricting access by IP address
You can set it so that it can be accessed only via a specific global IP address. By restricting access to within your company or base, you can reduce the risk of leaks. * 4G and other mobile communications will also be restricted. Allowed IP addresses must be fixed.