CLOUD SECURITY POLICY
Cloud Service Information Security Policy
This English translation is provided for reference only. In the event of any discrepancy, the Japanese version shall prevail.
Basic Philosophy
ShareWis Inc. has established this policy to maintain information security in the provision of cloud services. So that our customers can use our services with confidence, all related parties, including directors and employees, comply with this policy and work on continuous improvement. This policy is positioned as a subordinate policy to our separately established Information Security Policy.
Basic Policy
- Information security requirements applied to the design and implementation of cloud services
We design and implement our services based on customers’ information security requirements, applicable laws including the Act on the Protection of Personal Information, and our company policies. - Addressing insider risks and controlling data access
Our policy is not to access customer data except where permitted by the customer or where unavoidable for service continuity, and access rights are restricted to the minimum necessary. - Multi-tenancy
Even in environments adopting a multi-tenant architecture, customer data is appropriately segregated so that it cannot be accessed across tenants. - Notification of service changes
When service changes occur, such as discontinuation of features or service suspension for maintenance, we notify customers in advance. - Handling of accounts and data after termination
Upon termination of the contract, customer accounts and data are deleted within the period we specify. - Digital forensics
In the event of an information security incident, we maintain a structure capable of responding to individual requests for the submission of evidence.