Information Security Policy
KINCHAKU Inc. works continuously to strengthen its security measures and to raise security awareness, so that customers can use our services with confidence and peace of mind.
We protect our own information assets, and those entrusted to us by our customers, from threats including accidents, disasters, and crime. To merit the trust of our customers and of society, the whole company works to the policy below.
Our policy
- Management responsibility. We improve and strengthen information security systematically and continuously, led by management.
- Internal structure. We maintain an organisation responsible for maintaining and improving information security, and set our security measures down as formal internal rules.
- Employee commitment. Our employees acquire the knowledge and skills that information security requires, so that our commitment to it is real.
- Information asset management. We manage the information assets we handle according to their confidentiality, integrity, and availability, in accordance with JIS Q 27001, the Japanese national adoption of ISO/IEC 27001.
- Legal and contractual compliance. We comply with applicable laws and regulations, and with our contracts with customers, business partners, and employees, and handle information assets accordingly.
- Violations and incidents. Where a legal violation, a breach of contract, or an incident affecting information security occurs, we respond appropriately and work to prevent recurrence.
- Subcontractor management. Where we outsource work, we work to maintain a level of information security equivalent to or higher than our own.
- Continuous improvement. We evaluate and review the above regularly, so that information security improves continuously.
- Cybersecurity. We define our cybersecurity structure, the measures that prevent attacks, and our preparations for being attacked, to protect information assets from cyber attack and other threats.
Technical measures
The measures below are how the policy above is implemented. The contractual security commitments that form part of your agreement with us are in the Service Level Agreement; how we collect, use, and protect personal information is set out in the Privacy Policy.
Encryption
Personal information handled by Kinchaku is encrypted in transit with SSL/TLS across every communication path within the system, protecting it against interception and tampering by third parties. Data is encrypted or hashed according to industry-standard practice before it is stored.
Application security
We develop the Kinchaku application following the OWASP Application Security Verification Standard.
Access control
The servers holding Kinchaku data run on cloud infrastructure with strict access control, and only the minimum necessary personnel within Kinchaku are granted access. Access is not granted without prior approval on reasonable grounds. A web application firewall protects the Kinchaku web application from attack. On PREMIUM, for on-premise and dedicated-server deployments, access to Kinchaku servers can be restricted to nominated IP addresses.
Vulnerability management
We carry out regular static analysis and security testing of the application to detect potential vulnerabilities. Vulnerabilities identified are managed through our vulnerability-management workflow and remediated on a priority set from our threat model and the urgency of the finding.
Established 2021-12-22 · Last revised 2026-08-22
KINCHAKU Inc.