Security
We protect your request data and approval history with organizational and technical controls, continuously.
Certifications and third-party assessment
| Item | Status |
|---|---|
| ISO/IEC 27001 (ISMS) | Certified (2019) |
| ISO/IEC 27017 (cloud security) | Certified (2022) |
| SOC 2 Type II | Annual report |
| Vulnerability assessment | Twice-yearly third-party assessment plus pre-release internal testing |
Data protection
- Encryption at rest: all databases and backups encrypted with AES-256
- Encryption in transit: TLS 1.2 or higher only
- Data centres: redundant across two regions in Japan; data never leaves the country
- Backups: daily, retained 30 days; recovery time objective (RTO) of 4 hours
Access control
- SSO via SAML 2.0 (Scale plan and above)
- IP restrictions and multi-factor authentication
- Viewing permissions by department and role
- Full operation logs, including administrator actions
Operations
- 24/7 monitoring; first response within one hour for critical incidents
- Annual security training for all staff and secure-coding training for engineers
- Annual vendor assessments and contractual confidentiality obligations
Uptime and SLA
| Plan | SLA |
|---|---|
| Starter | — |
| Scale | 99.5% |
| Enterprise | 99.9% |
Actual uptime over the past 12 months: 99.98%.
Questions
For security questionnaires or detailed documentation, please contact us.