本文へスキップ

— INFORMATION SECURITY POLICY

Information Security Policy

As an information services company, we treat the appropriate protection of client, partner and our own information assets — and running a trustworthy business as a result — as a core management priority. We continuously work to maintain and improve our information security based on the policy below.

This is a reference translation provided for convenience. The Japanese-language version is the authoritative text.

  1. 01

    Protection of information assets

    We manage all information assets we handle — client data, business data, systems, source code, intellectual property and more — appropriately, from the standpoint of confidentiality, integrity and availability. Information assets are classified by importance, with access rights granted on a minimum-necessary basis.

  2. 02

    Risk assessment and controls

    We continuously identify and evaluate information security risks, and implement appropriate technical, organizational and physical controls. Systems and data directly tied to client work receive priority risk-reduction measures.

  3. 03

    Compliance with laws, regulations and contractual requirements

    We comply with the Act on the Protection of Personal Information and other laws, regulations, industry standards and contractual requirements relevant to information security. Where a violation is found, we take prompt corrective action and establish measures to prevent recurrence.

  4. 04

    Responsibility and training for officers and employees

    All officers and employees are obligated to understand and comply with this policy. We conduct regular security training and drills, maintaining and raising awareness of current threats including phishing and social engineering.

  5. 05

    Management of contractors and external vendors

    When outsourcing information processing, system development, infrastructure operations or similar work, we evaluate the security level of the vendor beforehand. We secure an environment where information assets are properly protected through contracts, non-disclosure agreements and similar means.

  6. 06

    Access control and system security

    We apply multi-factor authentication, the principle of least privilege and regular permission reviews across our business systems, cloud services and networks. We continuously manage software vulnerabilities, apply patches and maintain anti-malware measures.

  7. 07

    Incident response

    When an information security incident occurs, we act quickly to contain the damage, determine the cause, recover, and prevent recurrence. We notify affected clients and other parties at an appropriate time, in accordance with applicable law and contractual obligations.

  8. 08

    Business continuity and availability

    We maintain regular backups, redundancy and recovery procedures for critical business systems and data. We maintain a structure that minimizes client impact in the event of a service disruption.

  9. 09

    Continuous improvement

    We regularly review the effectiveness of our information security management, updating this policy and its controls to reflect changes in technology, threats and our business. We embed a continuous improvement cycle across the organization to keep raising our security standard.

Contact for information security inquiries

Address
Kohobo Bldg 7F, 3-9-15 Kanda-Jimbocho, Chiyoda-ku, Tokyo 101-0051, Japan
Phone
+81-3-3265-1067
Hours
10:00–17:00 JST on our business days

Established: June 6, 2026
Public Design Co., Ltd.
Keigo Hashimoto, Representative Director