Security Policy
Last updated: June 30, 2026
Kachilu Inc. ("Kachilu," "we," "us," or "our") recognizes that protecting information assets is essential to maintaining trust with customers, users, partners, and society. We establish this Security Policy to guide the secure operation of our services and business.
1. Scope
This policy applies to information assets handled by Kachilu and to officers, employees, contractors, temporary staff, and other personnel who handle those assets on our behalf.
2. Security Governance
We maintain an information security management framework appropriate to the nature and scale of our business. We define responsibilities for information security, establish internal rules where necessary, and review controls in response to changes in risk, technology, laws, and business operations.
3. Compliance
We comply with applicable laws, regulations, government guidelines, contractual obligations, and internal rules concerning information security, personal information protection, confidentiality, and data handling.
4. Security Control Measures
We implement reasonable and appropriate security controls based on risk. These controls may include
- access control and least-privilege permissions;
- authentication controls and account management;
- encryption of communications using SSL/TLS;
- secure management of production systems and cloud environments;
- logging, monitoring, and investigation of relevant system activity;
- vulnerability management and security updates;
- backup, recovery, and availability controls;
- malware and unauthorized-access countermeasures;
- confidentiality obligations and internal guidance for personnel;
- physical and device security measures appropriate to our operating environment.
5. Service Provider Management
When outsourcing operations or using third-party service providers, we assess security and data handling as appropriate to the risk and require necessary confidentiality, data protection, and security obligations.
6. Incident Response
If a security incident occurs or is suspected, we will work to confirm facts, contain damage, investigate causes, notify affected parties or authorities where required, and implement recurrence prevention measures as appropriate.
7. Education and Awareness
We provide personnel with security and privacy guidance appropriate to their roles and responsibilities.
8. Continuous Improvement
We periodically review and improve our security controls and management framework in light of operational experience, incidents, social expectations, technological changes, and legal developments.
Kachilu Inc.
Ryutaro Imai, Representative Director
3-4-1 Wakaba, Shinjuku-ku
Tokyo 160-0011, Japan
Email: support@biz-db.com