SECURITY & TRUST
Our Approach to Information Security
Yamashou Technology Co., Ltd. regards the security of the information and system environments entrusted to us by our customers as a core business responsibility. This page describes our basic principles and provides a contact point for reporting vulnerabilities.
Information Security Policy
Yamashou Technology Co., Ltd. (“we” or “the Company”) protects the information assets of the Company and its customers in accordance with the following principles.
- Management responsibilityUnder the leadership of management, we address information security in an organized and continuous manner.
- Compliance with laws and contractsWe comply with laws, regulations, and standards related to information security, as well as our contractual obligations to customers.
- Internal organizationWe maintain an organizational structure for sustaining and improving information security, and establish the necessary controls as formal internal rules.
- Protection of information assetsWe implement appropriate organizational, technical, and physical controls to protect the information assets of the Company and its customers from leakage, tampering, destruction, unauthorized access, and other threats.
- Employee educationWe provide ongoing information security education to all employees to ensure this policy is understood and put into practice.
- Incident responseIn the event of an information security incident, or a risk of one, we respond promptly to contain the impact and prevent recurrence.
- Continuous improvementWe regularly review and continuously improve our information security practices.
Controlled Public Disclosure
Because we design, operate, and maintain IT environments on behalf of our customers, we deliberately do not publish information on our website or elsewhere that could assist reconnaissance or targeted attacks.
As a rule, we do not publicly disclose:
- customer names or case studies;
- network architecture, system configurations, or administrative access paths;
- the products, software, services, and versions we use; or
- details of our operational structure, monitoring methods, or personnel.
This is a deliberate security practice intended to protect our customers’ environments, not a limitation of our technical operations. Detailed information is provided directly to parties who require it, under contract and confidentiality obligations.
Defensive Security
We identify, remediate, and continuously improve the security of systems that we own, develop, or operate, and of customer environments for which we have explicit authorization.
- Scope and authorization are documented in advance. We do not conduct assessments outside the agreed scope.
- Vulnerability validation is performed in isolated test environments wherever practicable. Where validation in a production environment is necessary, it is conducted only within a predefined and authorized scope, with measures to minimize operational impact.
- The process from discovery to remediation is recorded, and fixes are reviewed by a responsible engineer before being applied.
- The same scope and procedures apply when analysis tools, including AI-based tools, are used.
Governance
In work involving customer information and systems, we apply the following baseline controls:
- individual user authentication and multi-factor authentication;
- access control based on the principle of least privilege;
- logging and auditing of access and operational activity;
- human review and approval of significant changes; and
- need-to-know handling of information, with appropriate retention and disposal.
Responsible Disclosure
If you discover a vulnerability in a service or system provided by the Company, please contact us using the details below. Reports are used solely for the purpose of improving security.
security@yamashou-tech.co.jp (please include “Vulnerability Report” in the subject line)
MACHINE-READABLE
/.well-known/security.txt (RFC 9116)
What we ask of reporters
- Please describe the affected target, steps to reproduce, and the expected impact.
- Please refrain from viewing, retrieving, modifying, or deleting data, and from any activity that could disrupt service availability.
- Please do not publicly disclose the issue until we have completed our response.
What you can expect from us
- We will review the report and a responsible engineer will contact you.
- We do not intend to pursue legal action against good-faith research conducted in accordance with this page.
- For vulnerabilities in third-party products, we cooperate in responsible disclosure to the relevant vendor or maintainer.
This page does not authorize access to our customers’ environments or any testing beyond the scope described above.
Yamashou Technology has declared the Two-Star level under the “SECURITY ACTION” initiative promoted by the Information-technology Promotion Agency, Japan (IPA) (One-Star declared September 2024, Two-Star September 2026).
Last updated: September 3, 2026