LEGAL — SECURITY

情報セキュリティ方針Information Security Policy

制定日 / EFFECTIVE: 2026-07

イスナ株式会社は、経営者および人事責任者からお預かりする情報 — 経営戦略、組織情報、報酬情報、個人評価情報を含む機微性の高い情報 — の重要性を認識し、これらを適切に保護するため、本情報セキュリティ方針を定めます。本方針は、JIS Q 27001(ISO/IEC 27001)の考え方を参考に策定しています。Isuna Inc. recognizes the criticality of information entrusted by executives and HR leaders — including management strategy, organizational data, compensation data, and individual evaluations — and establishes this policy to protect such information appropriately. The policy draws on the principles of JIS Q 27001 (ISO/IEC 27001).

01適用範囲と目標Scope and objectives

本方針は、当社の全役員、従業員、および業務委託先(関与メンバー)に適用されます。当社は、情報の機密性(認可された者のみのアクセス)、完全性(正確性の確保)、可用性(必要時のアクセス確保)の3要素の維持を目標とします。This policy applies to all officers, employees, and engaged team members. We aim to maintain confidentiality (access limited to authorized persons), integrity (accuracy and completeness), and availability (access when required).

02管理体制Governance

情報セキュリティの最高責任者は代表取締役とし、方針の策定・改定、リスク評価、インシデント対応を統括します。方針と運用は定期的に見直します。The CEO serves as the chief information security officer, overseeing policy formulation, risk assessment, and incident response. The policy and its operation are reviewed periodically.

03情報資産の分類Information classification

  • 極秘:上場準備に関わる未公表情報、M&A情報、個人給与情報等Highly confidential: non-public pre-IPO information, M&A information, individual compensation data
  • 秘:組織情報、評価情報、経営会議資料等Confidential: organizational data, evaluation data, board materials
  • 社外秘:業務プロセス、一般的な取引情報等Internal: business processes, general transaction information

各区分に応じたアクセス制限と保管ルールを適用します。Access restrictions and storage rules are applied per tier.

04主な管理策Key controls

  • アクセスは業務上の必要性(need-to-know)に基づき最小限に限定し、多要素認証を必須とするAccess is limited to a strict need-to-know basis, with multi-factor authentication required
  • クライアント情報は暗号化ストレージに保管し、通信はTLSで暗号化するClient data is stored on encrypted storage; all communications are TLS-encrypted
  • ローカルデバイスへの機密情報の保存、および可搬媒体(USBメモリ等)の使用は原則禁止Storing confidential data on local devices and use of removable media are prohibited as a rule
  • 業務利用端末はディスク暗号化・自動ロック・リモートワイプを有効化し、セキュリティアップデートを速やかに適用Business devices run full-disk encryption, auto-lock and remote wipe, with security updates applied promptly
  • 全関与者と秘密保持契約を締結し、契約終了時にアクセス権限を即時失効NDAs with all engaged personnel; access revoked immediately upon contract end
  • 離席時のクリアデスク・画面ロック、書類の施錠保管と廃棄時の裁断Clear desk and screen lock when unattended; locked document storage and shredding at disposal

05インシデント対応Incident response

情報漏えい、不正アクセス等のインシデントが発生し、または発生のおそれがある場合、直ちに影響範囲を特定して被害拡大を防止し、影響を受けるお客様に速やかに第一報を行います。個人情報保護委員会等への報告義務がある場合は、法令に従い遅滞なく報告します。事後は根本原因を分析し、再発防止策を実施します。In case of an incident (or suspected incident) — data leakage, unauthorized access, etc. — we immediately assess and contain the impact and provide prompt initial notification to affected clients. Where regulatory reporting is required, we report to the Personal Information Protection Commission or other authorities without delay, followed by root cause analysis and corrective action.

06業務委託先の管理Third-party management

業務委託先(関与メンバー等)に対しては、契約締結前のセキュリティ体制の確認、秘密保持義務・安全管理措置の契約への明記、定期的な状況確認を行います。For service providers, we verify security posture before contracting, contractually require confidentiality and security controls, and conduct periodic reviews.

07事業継続Business continuity

業務データはクラウド上で保管し、定期的にバックアップします。主要業務はリモートで実施可能な体制を維持し、責任者不在時の緊急連絡体制を整備しています。Operational data is stored in the cloud with periodic backups. Core operations remain executable remotely, and emergency contact protocols cover key-person absence.

08問い合わせ窓口Contact

本方針に関するお問い合わせ、情報セキュリティに関するご相談・ご懸念は、お問い合わせContact までご連絡ください。For inquiries regarding this policy or any information security concerns, contact お問い合わせContact.

イスナ株式会社
代表取締役 齋藤 大輔
Isuna Inc.
Daisuke Saito, Founder & CEO