Data Privacy and
Information Security

Basic Concept

Our solutions facilitate the management and use of data that includes private customer information, such as that on companies and individual users. We position the handling and protection of personal information and other vital information assets as our most critical management concern. Convenience and security often come into conflict in developing cloud solutions, but it is vital to maintain the best possible balance between these two elements when increasing efficiency and productivity. Balancing security and convenience is a premise of our corporate philosophy. In addition to ensuring convenience, we minimize security risks by having all officers and employees take every possible measure to protect data privacy and information security to ensure that we stably provide highly secure services.

Information Security Structure

The Group recognizes that the strict management of all information assets handled through its business activities and the respect for privacy are part of its corporate social responsibility and constitute essential management structure for the Group’s sustainable growth and strengthening of corporate value. Based on this recognition, we have identified “Provide safe and stable infrastructure services” and “Ensure robust protection of data privacy and information security” as material issues to be addressed with priority. To respond quickly and in all directions to privacy and security risks, directors assume the roles of CISO,*1 DPO,*2 and Personal Information Protection Manager. We have also established our Information Security Department as a specialized division dedicated to information security and cybersecurity across the Group. The Information Security Department has the CSIRT*3 function and also operates an in-house SOC*4 to regularly monitor and analyze threats. GRC*5 (security governance) is responsible for responding to new legal regulations and formulating company-wide security rules, thereby managing company-wide governance. We also have set up a product security team to strengthen the security of our products and address vulnerabilities. Since our founding in 2007, we have maintained a Personal Information Protection Management System as a measure to protect data, establishing an environment for dealing with such protection within the company. We have also built a system that can continually monitor key data 24/7 by fully leveraging the latest security technology.
The Information Security Department and those responsible for developing each product report directly to the CISO and are under CISO’s supervision. The CISO participates in management meetings to regularly report security and risk status and makes important decisions on information security and cybersecurity at the management level. The CISO/DPO also analyzes threats and countermeasures for privacy and security risks surrounding the Company and formulates and reviews rules for the handling of personal information in accordance with relevant laws and regulations, reporting regularly to the Executive Committee and the Board of Directors. The Board oversees the above matters by receiving these reports, deliberates and makes decisions on important matters among them, and, if necessary, reviews countermeasures and determines whether to make additional investment.

  1. *1 CISO: Chief Information Security Officer
    This role has responsibility and authority for the security and risk management of information systems. The person oversees policies and management methods for information security risks.
  2. *2 DPO: Data Protection Officer
    This role’s main duty is to monitor compliance with the EU General Data Protection Regulation (GDPR). The person oversees the organization’s management activities regarding data protection in accordance with legal regulations.
  3. *3 CSIRT: Computer Security Incident Response Team
    It is a team that gathers information on events that potentially threaten information security and system vulnerabilities, monitors signs of cyberattacks and other risks, and formulates response measures and procedures.
  4. *4 SOC: Security Operation Center
    SOC monitors networks and systems at all times to collect and analyze data logs and proposes measures in the event of an incident.
  5. *5 GRC: Governance, Risk Management, Compliance
    This is a concept for managing these three functions for correctly operating a company in an integrated manner.
System Chart
Career summary of Kenji Shiomi, CISO and DPO

Kenji Shiomi

Kenji Shiomi, who serves as CISO and DPO, co-founded the Company in 2007 and has consistently led the development of its products. Now as Engineering Division Head with his abundant experience and expertise, he oversees the engineering organization. He also serves as CEO of our overseas subsidiary Sansan Global Development Center, Inc., focusing on building a diverse organization.
In 2023, he assumed the position of CISO. Since then, he has been striving to bolster security in our group by strengthening product security, promoting a Zero Trust security model and taking the lead in the event of an incident. He also contributes to the security enhancement of the entire industry by speaking at external conferences. To promote the protection of data privacy and compliance as DPO, he has developed and implemented data protection strategies for the entire organization and leads the Group both in terms of security and privacy.

Major Initiatives

Establishment and Objectives of Regulations

We are strengthening our management and control systems against anticipated risks such as information leakage and cyberattacks by establishing regulations and rules on information security and providing guidelines for each solution. The regulations, rules, and guidelines are reviewed annually to keep them up-to-date.

Basic Regulations for the Protection of Personal Information

These regulations stipulate procedures for appropriate handling of personal information for the Company to meet JIS Q 15001.

Rules on management of information systems

These rules stipulate the procedures on information system management operations handling our information assets.

Rules on information asset management

These rules stipulate the procedures on information asset management to properly and safely manage information assets and effectively use them.

List of rules on technical safety management of information systems

These stipulate the rules on technical safety management of information systems.

Guidelines on product security

They stipulate the guidelines for each service on security functions to be included and their operations.

Strengthening the Management of Personal Information

We take the following measures in response to the revision, enactment, and enforcement of laws regarding the protection of personal information in various countries.

We revise internal regulations, including our Basic Regulations for the Protection of Personal Information, and update various related procedures.

Along with the amendment of the Act on the Protection of Personal Information, we have revised our internal rules, including our basic regulations for the protection of personal information, and changed and tightened relevant procedures.

We take safety management measures for the protection of personal information in our overseas subsidiaries while understanding the related systems in Singapore, the Philippines, and Thailand, where the subsidiaries are located.

Regarding overseas contractors, we have conducted surveys on legal systems in the Philippines, Myanmar, Vietnam, Bangladesh, and Thailand to evaluate safety management measures of the contractors from organizational, human, physical, and technical perspectives.

Education on Information Security

We promote correct understanding of the Act on the Protection of Personal Information and the safe management of the information among all officers and employees through measures to raise company-wide security awareness.

Acquisition of Certification as a Protection of Individual Information Person

All officers and employees must acquire Protection of Individual Information Person qualifications. Salary increases are, in principle, suspended if an employee does not pass the exam after a certain period.

Regular Learning Opportunities

Information security and personal information protection training is provided upon hiring and then annually.

Communications from the CISO

The director serving as CISO updates all our officers and employees monthly on security initiatives, risks, and other topics.

Thorough Implementation of Information Asset Handling Procedures

Clarifying the classification of information assets according to confidentiality, we define management measures based on each category’s risk. Security committee members are appointed from among employees to conduct mutual security auditing to ensure the implementation of management measures.

Ensuring and Developing Security Personnel

Ensuring Security Personnel
Hiring Dedicated Security Personnel

We globally recruit human resources by evaluating security knowledge, skills, experience, responses, and expertise in specific areas.

Training Dedicated Security Personnel Internally

We select people with specialized knowledge, experience, and superb skills in specific areas and who are expected to handle a wide range of security areas, and we provide them with one-on-one on-the-job training (OJT) by experts to develop their expertise.

Developing Advanced Security Personnel
Personnel Development System

We encourage our employees to acquire advanced security certifications designated by the Company as part of efforts to secure advanced security personnel and to promote knowledge acquisition through self-learning.

Number of Advanced Security Certifications*6
As of May 31, 2026
Number of Advanced Security Certifications 24
Personnel Development through On-the-Job Training (OJT)

We develop personnel until they can independently carry out their security-related roles within the Company while experiencing one-on-one on-the-job training (OJT) by experts.

  1. *6 This figure represents the number of advanced security certifications held within the Information Security Department. The certifications include the followings:
    • IPA-certified: Registered Information Security Specialist (RISS)
    • ISC2-certified: CISSP (Certified Information Systems Security Professional), CCSP (Certified Cloud Security Professional)
    • OffSec-certified: OSCP (OffSec Certified Professional), OSDA (OffSec Defense Analyst), OSWE (OffSec Web Expert), OSWP (OffSec Wireless Professional), OSWA (OffSec Web Assessor)
    • ISACA-certified: CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager)
    • SANS GIAC-certified: GWAPT (GIAC Web Application Penetration Tester), GCPN (GIAC Cloud Penetration Tester), GWEB (GIAC Certified Web Application Defender), GCIH (GIAC Certified Incident Handler), GPCS (GIAC Public Cloud Security)

Third-Party Certifications

We are committed to obtaining third-party security-related certifications and have received various accreditations.

PrivacyMark

The operation of our personal information protection management system (PMS) is evaluated based on audit criteria derived from the Japanese Industrial Standard – JIS Q 15001: Personal Information Protection Management Systems – Requirements. We obtained certification from the Japan Data Communications Association in 2007 and have since undergone external audits every two years to renew the certification.
During these audits, our PMS documentation – including internal policies, templates, and our privacy policy – is reviewed for compliance with JIS Q 15001 and the audit criteria. The audit also examines the development of specific procedures and measures to ensure adherence to internal regulations.
Additionally, auditors conduct on-site inspections to confirm whether the PMS framework has been properly established and is being operated as intended. These inspections include interviews, as well as reviews of training and audit records.
By introducing the PMS, we work to strengthen our management system by minimizing risk of exposure to personal information breaches, developing the structure and response procedures in the event of incidents, and taking appropriate measures in response to emergencies, along with recurrence-prevention measures.

ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27701

We have obtained ISO/IEC 27001 certification, an international standard for Information Security Management Systems (ISMS); ISO/IEC 27017, an international standard for cloud service security; and ISO/IEC 27701, an international standard for Privacy Information Management Systems, which covers a comprehensive operational framework and mechanisms for complying with privacy laws and regulations around the world. Through these certifications, we have established globally standardized systems for information security and privacy protection.

ISMAP for Low-Impact Use (ISMAP-LIU)

The Information system Security Management and Assessment Program (ISMAP) evaluates and registers cloud services that comply with the Japanese government’s security requirements in advance. This is aimed at ensuring high-level security during procurement and contributing to effective implementation. ISMAP for Low-Impact Use (ISMAP-LIU) is a system for SaaS used for low-risk operations and information processing. The management standards are based on JIS Q 27001, JIS Q 27002, JIS Q 27014, JIS Q 27017, and others. For aspects not covered by international and unified standards, mainly related to incident response, the standards are structured with reference to SP 800-53. In September 2024, we became the first cloud service to be registered on the ISMAP-LIU Cloud Service List.

Legal Requirements for Electronic Transaction Software Certification

The Japan Image and Information Management Association (JIIMA) administers the Legal Requirements for Electronic Transaction Software Certification System. The certification checks whether software and software services that create and electronically exchange national tax-related documents meet the requirements of Article 7 of the Electronic Book Storage Act. In April 2022, Bill One and Contract One obtained certification under criteria of the 2021 revision and later.

Defense System against Threats

We have built a robust system to support defense and monitoring activities to combat threats to complicated cybersecurity and information security and to provide safe and secure services to users entrusting us with their important data.
We have adopted a defense-in-depth architecture including network communication control, and have established a system that uses our SOC to promptly investigate and respond to abnormalities when detected with EDR*7 installed in each terminal. The newly established Product Security Team is working to bolster security consistently from the development of each solution. We also have set up the CSIRT and developed a system to ensure immediate response to incidents.

24/7 Monitoring Activities by Internal and External SOCs

We work with external vendors to conduct 24/7 monitoring activities against cyberattacks and perform fast investigation of and response to abnormalities when detecting them. We also conduct monitoring activities to prevent unauthorized access to internal information equipment.

Conducting Regular Vulnerability Assessments and Penetration Testing

We test and strengthen the security levels for each solution and our systems by engaging white-hat hackers from external specialist firms to conduct simulated attacks. In addition, penetration testing is conducted in the internal environment and training for targeted attack emails and BCP*8 is provided to our officers and employees.

Number of Vulnerability Assessments and Penetration Testing Conducted by Outside Security Specialists
(Unit: times) FY2020 FY2021 FY2022 FY2023 FY2024 FY2025
Vulnerability Assessment 1 1 1 1 1 1
Penetration Testing 1 1 1 1 1 1
Vulnerability Assessment Results
Penetration Testing Results
  1. *7 EDR: Endpoint Detection and Response
    EDR is a technology to continuously monitor and respond to threats at terminals and devices such as PCs and servers connected to communication networks.
  2. *8 BCP: Business Continuity Plan

Technical Initiatives

We implement a variety of security measures, including vulnerability assessments, which third-party organizations and specialized in-house departments perform.

Encryption of All Data Center Transmissions

All external transmissions to our data centers are highly encrypted using user authentication, HTTPS, and other advanced encryption methods.

Images Deleted from Device After Scanning

After business cards, invoices, and other paper documents are scanned, the image data is deleted from the device.

High Service Availability

All our servers are load-balanced through multiplexed network equipment. Services can be promptly restored in the event of a failure. Additionally, our data centers are redundantly configured to minimize the risk of functional and service outages in the event of a disaster.

Adopting Zero Trust Security

We have adopted Zero Trust security across the company, establishing mechanisms that let us work safely both inside and outside the internal network, and ensuring the security of the entire access path to the information assets we must protect. As a measure to promote Zero Trust security, we are building an environment that applies Zero Trust-based management measures to allow us to work from any location. The key functions include the following:

  • Developing IDaaS*9 (Integrated Authentication Infrastructure) allows for secure authentication based on a unified security policy when accessing internal systems.
  • Installing EDR prevents malware and other cyberattacks and intrusion activities at the endpoints from continuing.
  • UEBA*10 allows us to detect unusual behaviors and quickly identify and respond to unknown cyberattacks that were not included in our rules.
  • SIEM*11 infrastructure allows us to collect a wide range of logs to detect abnormalities, thereby establishing a system for early detection of signs of cyberattacks and attack blocking.
  • Encryption of disks in terminals protects information assets.
  • Information stored on terminals is backed up to the cloud on an ongoing basis while the terminals are online. If a terminal is lost or stolen, we can remotely lock it and erase the data stored on it.
  1. *9 IDaaS: Identity as a Service
    The IDaaS technology provides services that allow integrated management of ID authentication, single sign-on (SSO), and access control as well as IDs and passwords registered for multiple services.
  2. *10 UEBA: User and Entity Behavior Analytics
    This is a cybersecurity technology that analyzes user behavior and applies advanced analysis to detect unusual behavior based on traffic patterns on the network.
  3. *11 SIEM: Security Information and Event Management
    This is a technology that identifies security threats and problems at an early stage by consolidating logs of IT devices such as security and network devices and analyzing them in real time.

Initiatives to Address Risks

We have established the standard for risk assessment to perform risk assessment and management.

Step 1: Assess the likelihood of risks

Risk assessment is performed with threat agent factors and vulnerability factors, and the likelihood of risks (probability of emerging risks) is quantitatively calculated and evaluated at high, medium, and low levels.

Step 2: Assess factors to anticipate risk impact

Risk assessment is performed with technical impact factors considering confidentiality, integrity, and availability, and business impact factors, and impact of risks (magnitude of impact when risks emerge) is quantitatively calculated and evaluated at high, medium, and low levels.

Step 3: Assess severity and manage risks

Risk severity is assessed based on the values calculated at steps 1 and 2. Risks are classified as critical, high, medium, low, and notes, and risk acceptance decisions are made and managed.

Incident and vulnerability reporting and escalation system

We have formally established incident guidelines and set up a reporting channel on our internal communication tool. When a report is received from an employee or the SOC (24/7 monitoring), each business division performs reception and triage, determines the incident level and response mode, and then responds in accordance with the situation. The Information Security Department, which has CSIRT functions, works in unison with each business division to respond depending on the nature of the incident. The reporting destination is expanded in stages based on the level, from the responsible officer, officer in charge, and Representative Director to all Directors and the Audit & Supervisory Committee, and we also conduct regular reports to management meetings and, if necessary, external reports to the police, regulatory authorities, customers, and the Personal Information Protection Commission.

Initiatives for incident response

We are heightening security awareness and the ease of reporting within the Company by fostering a no-blame culture, mandating that all officers and employees obtain Protection of Individual Information Person qualification, and conducting training upon hiring and once a year.

Vulnerability reporting

In addition to incident reports from employees, vulnerabilities discovered through annual external assessments, penetration testing, and automated diagnostic systems are evaluated for risk level using CVSS scores, etc., and appropriate responses are taken based on the risk level. A summary of the results of the annual external assessment and penetration testing is published on our official website.


Cyber resilience

We are establishing a series of systems for prevention, detection, response, recovery, adaptation, and learning in order to realize business continuity and prompt recovery even in the event of an attack or failure. In the prevention stage, we classify information assets, establish Zero Trust policies, conduct vulnerability assessments, and perform pre-launch reviews of new solutions by CSIRT. In the detection stage, we monitor all products across the board using SIEM, EDR, WAF,*12 etc. In the response and recovery stage, we have established incident guidelines and set up a reception desk. Each business division triages reports from employees and the SOC (24/7 monitoring) and responds based on the level in coordination with CSIRT. In the adaptation and learning stage, we conduct reviews after incidents and reflect the findings in our prevention, detection, and response systems, while continuously improving the skills and response capabilities of the entire organization through training and drills.

  1. *12 WAF (Web Application Firewall)
    This technology is a security measure for protecting websites and online services from attacks targeting online applications. It checks the content of incoming communications (HTTP requests) and blocks suspicious ones.

Information Security Requirements for Business Contractors Handling Personal Information

We present requirements that cover personal information protection and information security to our business contractors and we confirm compliance at the time of contract conclusion and renewal. We systematically define the standards that contractors must meet, ranging from the conclusion of business outsourcing agreements to organizational structures such as personal information protection policies and the appointment of managers; operational management such as the establishment of regulations, audits, and incident reporting systems; human and physical measures such as education and access control; and technical safety management measures such as access control, log management, patch application, and antivirus measures. We also evaluate once a year whether our contractors continue to meet these requirements.


Initiatives and Principles of the Information Security Department

Balancing security and convenience is a premise of our corporate philosophy. In addition to ensuring convenience, the Information Security Department minimizes security risks by implementing measures to ensure that our officers and employees maintain data privacy and information security, and it aims to provide highly secure services in a stable manner. It also seeks to lead the SaaS industry as its vision. Additionally, it pursues improving the security level of the entire industry not only by raising the Company’s security level to the highest in the industry, but also by actively sharing and circulating best practices and learning internally and externally. To that end, we aim to build an organization that harnesses individual strengths and the collective power of the team. We encourage all members to demonstrate leadership and take initiative, and we enable everyone to draw on one another’s strengths, as we create a resilient organization capable of sustaining growth even in times of change.
In 2023, we launched a new initiative: the establishment of the Product Security Team. In the development process for each solution and feature, we go beyond conducting vulnerability assessments at the final testing stage. Under the philosophy of Security by Design*13, our security team is involved from the earliest design phases, promoting the development of inherently secure and reliable services from the ground up. Our annual penetration tests are consistently completed with virtually no successful breaches. We take pride in our detection and defense capabilities, which we believe are among the highest in the industry, as demonstrated by our ability to withstand even the efforts of Japan’s top white-hat hackers.
In 2025, we embraced an “AI-First” approach company-wide, driving improvements in operational efficiency and productivity through the use of AI. We view AI like a “powered suit” that enhances human capabilities, and by fostering collaboration among our business, legal, IT systems, and information security departments, we are enabling progress without compromising speed or safety. AI adoption represents a major environmental shift, but we believe it is an essential element for sustainable corporate growth.
As AI adoption continues to accelerate across industries, security risks are rising for society as a whole.
Strong security not only reassures customers and business partners, but also is essential for developing the digital society and brings great benefits to society beyond the framework of companies. We will promote proactive security measures and continue to provide safe and reliable services. To this end, we believe that our initiatives will support AX(AI Transformation) across society and become a driving force to create a sustainable future.

  1. *13 Security by Design
    This is an approach to ensure product security from the planning and designing stages.