YAMASHOU.TECH 日本語

SECURITY & TRUST

Our Approach to Information Security

Yamashou Technology Co., Ltd. regards the security of the information and system environments entrusted to us by our customers as a core business responsibility. This page describes our basic principles and provides a contact point for reporting vulnerabilities.

Information Security Policy

Yamashou Technology Co., Ltd. (“we” or “the Company”) protects the information assets of the Company and its customers in accordance with the following principles.

  1. Management responsibilityUnder the leadership of management, we address information security in an organized and continuous manner.
  2. Compliance with laws and contractsWe comply with laws, regulations, and standards related to information security, as well as our contractual obligations to customers.
  3. Internal organizationWe maintain an organizational structure for sustaining and improving information security, and establish the necessary controls as formal internal rules.
  4. Protection of information assetsWe implement appropriate organizational, technical, and physical controls to protect the information assets of the Company and its customers from leakage, tampering, destruction, unauthorized access, and other threats.
  5. Employee educationWe provide ongoing information security education to all employees to ensure this policy is understood and put into practice.
  6. Incident responseIn the event of an information security incident, or a risk of one, we respond promptly to contain the impact and prevent recurrence.
  7. Continuous improvementWe regularly review and continuously improve our information security practices.

Established: September 3, 2026
Keiichi Noguchi, Representative Director, Yamashou Technology Co., Ltd.

Controlled Public Disclosure

Because we design, operate, and maintain IT environments on behalf of our customers, we deliberately do not publish information on our website or elsewhere that could assist reconnaissance or targeted attacks.

As a rule, we do not publicly disclose:

This is a deliberate security practice intended to protect our customers’ environments, not a limitation of our technical operations. Detailed information is provided directly to parties who require it, under contract and confidentiality obligations.

Defensive Security

We identify, remediate, and continuously improve the security of systems that we own, develop, or operate, and of customer environments for which we have explicit authorization.

Governance

In work involving customer information and systems, we apply the following baseline controls:

Responsible Disclosure

If you discover a vulnerability in a service or system provided by the Company, please contact us using the details below. Reports are used solely for the purpose of improving security.

EMAIL

security@yamashou-tech.co.jp (please include “Vulnerability Report” in the subject line)

MACHINE-READABLE

/.well-known/security.txt (RFC 9116)

What we ask of reporters

What you can expect from us

This page does not authorize access to our customers’ environments or any testing beyond the scope described above.

Yamashou Technology has declared the Two-Star level under the “SECURITY ACTION” initiative promoted by the Information-technology Promotion Agency, Japan (IPA) (One-Star declared September 2024, Two-Star September 2026).
Last updated: September 3, 2026