Our solutions facilitate the management and use of data that includes private customer information, such as that on companies and individual users. We position the handling and protection of personal information and other vital information assets as our most critical management concern. Convenience and security often come into conflict in developing cloud solutions, but it is vital to maintain the best possible balance between these two elements when increasing efficiency and productivity. Balancing security and convenience is a premise of our corporate philosophy. In addition to ensuring convenience, we minimize security risks by having all officers and employees take every possible measure to protect data privacy and information security to ensure that we stably provide highly secure services.
The Group recognizes that the strict management of all information assets handled through its business activities and the respect for privacy are part of its corporate social responsibility and constitute essential management structure for the Group’s sustainable growth and strengthening of corporate value. Based on this recognition, we have identified “Provide safe and stable infrastructure services” and “Ensure robust protection of data privacy and information security” as material issues to be addressed with priority. To respond quickly and in all directions to privacy and security risks, directors assume the roles of CISO,*1 DPO,*2 and Personal Information Protection Manager. We have also established our Information Security Department as a specialized division dedicated to information security and cybersecurity across the Group. The Information Security Department has the CSIRT*3 function and also operates an in-house SOC*4 to regularly monitor and analyze threats. GRC*5 (security governance) is responsible for responding to new legal regulations and formulating company-wide security rules, thereby managing company-wide governance. We also have set up a product security team to strengthen the security of our products and address vulnerabilities. Since our founding in 2007, we have maintained a Personal Information Protection Management System as a measure to protect data, establishing an environment for dealing with such protection within the company. We have also built a system that can continually monitor key data 24/7 by fully leveraging the latest security technology.
The Information Security Department and those responsible for developing each product report directly to the CISO and are under CISO’s supervision. The CISO participates in management meetings to regularly report security and risk status and makes important decisions on information security and cybersecurity at the management level. The CISO/DPO also analyzes threats and countermeasures for privacy and security risks surrounding the Company and formulates and reviews rules for the handling of personal information in accordance with relevant laws and regulations, reporting regularly to the Executive Committee and the Board of Directors. The Board oversees the above matters by receiving these reports, deliberates and makes decisions on important matters among them, and, if necessary, reviews countermeasures and determines whether to make additional investment.
Kenji Shiomi
Kenji Shiomi, who serves as CISO and DPO, co-founded the Company in 2007 and has consistently led the development of its products. Now as Engineering Division Head with his abundant experience and expertise, he oversees the engineering organization. He also serves as CEO of our overseas subsidiary Sansan Global Development Center, Inc., focusing on building a diverse organization.
In 2023, he assumed the position of CISO. Since then, he has been striving to bolster security in our group by strengthening product security, promoting a Zero Trust security model and taking the lead in the event of an incident. He also contributes to the security enhancement of the entire industry by speaking at external conferences. To promote the protection of data privacy and compliance as DPO, he has developed and implemented data protection strategies for the entire organization and leads the Group both in terms of security and privacy.
We are strengthening our management and control systems against anticipated risks such as information leakage and cyberattacks by establishing regulations and rules on information security and providing guidelines for each solution. The regulations, rules, and guidelines are reviewed annually to keep them up-to-date.
These regulations stipulate procedures for appropriate handling of personal information for the Company to meet JIS Q 15001.
These rules stipulate the procedures on information system management operations handling our information assets.
These rules stipulate the procedures on information asset management to properly and safely manage information assets and effectively use them.
These stipulate the rules on technical safety management of information systems.
They stipulate the guidelines for each service on security functions to be included and their operations.
We take the following measures in response to the revision, enactment, and enforcement of laws regarding the protection of personal information in various countries.
We revise internal regulations, including our Basic Regulations for the Protection of Personal Information, and update various related procedures.
Along with the amendment of the Act on the Protection of Personal Information, we have revised our internal rules, including our basic regulations for the protection of personal information, and changed and tightened relevant procedures.
We take safety management measures for the protection of personal information in our overseas subsidiaries while understanding the related systems in Singapore, the Philippines, and Thailand, where the subsidiaries are located.
Regarding overseas contractors, we have conducted surveys on legal systems in the Philippines, Myanmar, Vietnam, Bangladesh, and Thailand to evaluate safety management measures of the contractors from organizational, human, physical, and technical perspectives.
We promote correct understanding of the Act on the Protection of Personal Information and the safe management of the information among all officers and employees through measures to raise company-wide security awareness.
All officers and employees must acquire Protection of Individual Information Person qualifications. Salary increases are, in principle, suspended if an employee does not pass the exam after a certain period.
Information security and personal information protection training is provided upon hiring and then annually.
The director serving as CISO updates all our officers and employees monthly on security initiatives, risks, and other topics.
Clarifying the classification of information assets according to confidentiality, we define management measures based on each category’s risk. Security committee members are appointed from among employees to conduct mutual security auditing to ensure the implementation of management measures.
We globally recruit human resources by evaluating security knowledge, skills, experience, responses, and expertise in specific areas.
We select people with specialized knowledge, experience, and superb skills in specific areas and who are expected to handle a wide range of security areas, and we provide them with one-on-one on-the-job training (OJT) by experts to develop their expertise.
We encourage our employees to acquire advanced security certifications designated by the Company as part of efforts to secure advanced security personnel and to promote knowledge acquisition through self-learning.
| As of May 31, 2026 | |
|---|---|
| Number of Advanced Security Certifications | 24 |
We develop personnel until they can independently carry out their security-related roles within the Company while experiencing one-on-one on-the-job training (OJT) by experts.
We are committed to obtaining third-party security-related certifications and have received various accreditations.
The operation of our personal information protection management system (PMS) is evaluated based on audit criteria derived from the Japanese Industrial Standard – JIS Q 15001: Personal Information Protection Management Systems – Requirements. We obtained certification from the Japan Data Communications Association in 2007 and have since undergone external audits every two years to renew the certification.
During these audits, our PMS documentation – including internal policies, templates, and our privacy policy – is reviewed for compliance with JIS Q 15001 and the audit criteria. The audit also examines the development of specific procedures and measures to ensure adherence to internal regulations.
Additionally, auditors conduct on-site inspections to confirm whether the PMS framework has been properly established and is being operated as intended. These inspections include interviews, as well as reviews of training and audit records.
By introducing the PMS, we work to strengthen our management system by minimizing risk of exposure to personal information breaches, developing the structure and response procedures in the event of incidents, and taking appropriate measures in response to emergencies, along with recurrence-prevention measures.
We have obtained ISO/IEC 27001 certification, an international standard for Information Security Management Systems (ISMS); ISO/IEC 27017, an international standard for cloud service security; and ISO/IEC 27701, an international standard for Privacy Information Management Systems, which covers a comprehensive operational framework and mechanisms for complying with privacy laws and regulations around the world. Through these certifications, we have established globally standardized systems for information security and privacy protection.
The Information system Security Management and Assessment Program (ISMAP) evaluates and registers cloud services that comply with the Japanese government’s security requirements in advance. This is aimed at ensuring high-level security during procurement and contributing to effective implementation. ISMAP for Low-Impact Use (ISMAP-LIU) is a system for SaaS used for low-risk operations and information processing. The management standards are based on JIS Q 27001, JIS Q 27002, JIS Q 27014, JIS Q 27017, and others. For aspects not covered by international and unified standards, mainly related to incident response, the standards are structured with reference to SP 800-53. In September 2024, we became the first cloud service to be registered on the ISMAP-LIU Cloud Service List.
The Japan Image and Information Management Association (JIIMA) administers the Legal Requirements for Electronic Transaction Software Certification System. The certification checks whether software and software services that create and electronically exchange national tax-related documents meet the requirements of Article 7 of the Electronic Book Storage Act. In April 2022, Bill One and Contract One obtained certification under criteria of the 2021 revision and later.
We have built a robust system to support defense and monitoring activities to combat threats to complicated cybersecurity and information security and to provide safe and secure services to users entrusting us with their important data.
We have adopted a defense-in-depth architecture including network communication control, and have established a system that uses our SOC to promptly investigate and respond to abnormalities when detected with EDR*7 installed in each terminal. The newly established Product Security Team is working to bolster security consistently from the development of each solution. We also have set up the CSIRT and developed a system to ensure immediate response to incidents.
We work with external vendors to conduct 24/7 monitoring activities against cyberattacks and perform fast investigation of and response to abnormalities when detecting them. We also conduct monitoring activities to prevent unauthorized access to internal information equipment.
We test and strengthen the security levels for each solution and our systems by engaging white-hat hackers from external specialist firms to conduct simulated attacks. In addition, penetration testing is conducted in the internal environment and training for targeted attack emails and BCP*8 is provided to our officers and employees.
| (Unit: times) | FY2020 | FY2021 | FY2022 | FY2023 | FY2024 | FY2025 |
|---|---|---|---|---|---|---|
| Vulnerability Assessment | 1 | 1 | 1 | 1 | 1 | 1 |
| Penetration Testing | 1 | 1 | 1 | 1 | 1 | 1 |
We implement a variety of security measures, including vulnerability assessments, which third-party organizations and specialized in-house departments perform.
All external transmissions to our data centers are highly encrypted using user authentication, HTTPS, and other advanced encryption methods.
After business cards, invoices, and other paper documents are scanned, the image data is deleted from the device.
All our servers are load-balanced through multiplexed network equipment. Services can be promptly restored in the event of a failure. Additionally, our data centers are redundantly configured to minimize the risk of functional and service outages in the event of a disaster.
We have adopted Zero Trust security across the company, establishing mechanisms that let us work safely both inside and outside the internal network, and ensuring the security of the entire access path to the information assets we must protect. As a measure to promote Zero Trust security, we are building an environment that applies Zero Trust-based management measures to allow us to work from any location. The key functions include the following:
We have established the standard for risk assessment to perform risk assessment and management.
Risk assessment is performed with threat agent factors and vulnerability factors, and the likelihood of risks (probability of emerging risks) is quantitatively calculated and evaluated at high, medium, and low levels.
Risk assessment is performed with technical impact factors considering confidentiality, integrity, and availability, and business impact factors, and impact of risks (magnitude of impact when risks emerge) is quantitatively calculated and evaluated at high, medium, and low levels.
Risk severity is assessed based on the values calculated at steps 1 and 2. Risks are classified as critical, high, medium, low, and notes, and risk acceptance decisions are made and managed.
We have formally established incident guidelines and set up a reporting channel on our internal communication tool. When a report is received from an employee or the SOC (24/7 monitoring), each business division performs reception and triage, determines the incident level and response mode, and then responds in accordance with the situation. The Information Security Department, which has CSIRT functions, works in unison with each business division to respond depending on the nature of the incident. The reporting destination is expanded in stages based on the level, from the responsible officer, officer in charge, and Representative Director to all Directors and the Audit & Supervisory Committee, and we also conduct regular reports to management meetings and, if necessary, external reports to the police, regulatory authorities, customers, and the Personal Information Protection Commission.
We are heightening security awareness and the ease of reporting within the Company by fostering a no-blame culture, mandating that all officers and employees obtain Protection of Individual Information Person qualification, and conducting training upon hiring and once a year.
In addition to incident reports from employees, vulnerabilities discovered through annual external assessments, penetration testing, and automated diagnostic systems are evaluated for risk level using CVSS scores, etc., and appropriate responses are taken based on the risk level. A summary of the results of the annual external assessment and penetration testing is published on our official website.
We are establishing a series of systems for prevention, detection, response, recovery, adaptation, and learning in order to realize business continuity and prompt recovery even in the event of an attack or failure. In the prevention stage, we classify information assets, establish Zero Trust policies, conduct vulnerability assessments, and perform pre-launch reviews of new solutions by CSIRT. In the detection stage, we monitor all products across the board using SIEM, EDR, WAF,*12 etc. In the response and recovery stage, we have established incident guidelines and set up a reception desk. Each business division triages reports from employees and the SOC (24/7 monitoring) and responds based on the level in coordination with CSIRT. In the adaptation and learning stage, we conduct reviews after incidents and reflect the findings in our prevention, detection, and response systems, while continuously improving the skills and response capabilities of the entire organization through training and drills.
We present requirements that cover personal information protection and information security to our business contractors and we confirm compliance at the time of contract conclusion and renewal. We systematically define the standards that contractors must meet, ranging from the conclusion of business outsourcing agreements to organizational structures such as personal information protection policies and the appointment of managers; operational management such as the establishment of regulations, audits, and incident reporting systems; human and physical measures such as education and access control; and technical safety management measures such as access control, log management, patch application, and antivirus measures. We also evaluate once a year whether our contractors continue to meet these requirements.
Balancing security and convenience is a premise of our corporate philosophy. In addition to ensuring convenience, the Information Security Department minimizes security risks by implementing measures to ensure that our officers and employees maintain data privacy and information security, and it aims to provide highly secure services in a stable manner. It also seeks to lead the SaaS industry as its vision. Additionally, it pursues improving the security level of the entire industry not only by raising the Company’s security level to the highest in the industry, but also by actively sharing and circulating best practices and learning internally and externally. To that end, we aim to build an organization that harnesses individual strengths and the collective power of the team. We encourage all members to demonstrate leadership and take initiative, and we enable everyone to draw on one another’s strengths, as we create a resilient organization capable of sustaining growth even in times of change.
In 2023, we launched a new initiative: the establishment of the Product Security Team. In the development process for each solution and feature, we go beyond conducting vulnerability assessments at the final testing stage. Under the philosophy of Security by Design*13, our security team is involved from the earliest design phases, promoting the development of inherently secure and reliable services from the ground up. Our annual penetration tests are consistently completed with virtually no successful breaches. We take pride in our detection and defense capabilities, which we believe are among the highest in the industry, as demonstrated by our ability to withstand even the efforts of Japan’s top white-hat hackers.
In 2025, we embraced an “AI-First” approach company-wide, driving improvements in operational efficiency and productivity through the use of AI. We view AI like a “powered suit” that enhances human capabilities, and by fostering collaboration among our business, legal, IT systems, and information security departments, we are enabling progress without compromising speed or safety. AI adoption represents a major environmental shift, but we believe it is an essential element for sustainable corporate growth.
As AI adoption continues to accelerate across industries, security risks are rising for society as a whole.
Strong security not only reassures customers and business partners, but also is essential for developing the digital society and brings great benefits to society beyond the framework of companies. We will promote proactive security measures and continue to provide safe and reliable services. To this end, we believe that our initiatives will support AX(AI Transformation) across society and become a driving force to create a sustainable future.