Through building on-premise AI systems and developing AI applications, RAYWARD Inc. ("the Company") is involved in handling highly confidential customer information. We regard information security as the very quality of our business, and establish the following Security Policy.
Contents
01Basic Information Security Policy
1. Management responsibility
Under the leadership of the Representative Director, the Company works continuously as an organization to maintain and improve information security.
2. Internal framework
The Company appoints a person responsible for information security, and establishes and operates internal rules for handling information.
3. Commitment of officers and employees
Officers and employees acquire the necessary knowledge and skills and act in accordance with this Policy. When work is outsourced, the Company requires contractors to manage information to an equivalent standard.
4. Compliance
The Company complies with laws, regulations and norms related to information security, as well as its contractual obligations to customers.
5. Handling of customer information
Customer information obtained in the course of business is used only for the purposes agreed in the contract, and is not copied or taken off-site beyond what is necessary for the work.
6. Incident response
The Company strives to prevent incidents. Should one occur, the Company will respond promptly to minimize its impact, report to the parties concerned and prevent recurrence.
7. Continuous improvement
The Company regularly reviews and continuously improves its information security practices.
02Security measures
- Organizational
- The Representative Director is responsible for information security, with clearly defined roles and authority.
- Information assets, including customer information, are identified and managed according to their importance.
- Contractors are selected after reviewing their information management, and confidentiality agreements are concluded.
- Human
- Officers and employees sign confidentiality pledges.
- Information security training is provided on an ongoing basis.
- Technical
- Access rights are limited to the minimum necessary for each role.
- Strong authentication, such as multi-factor authentication, is used for important systems.
- Communications are encrypted, software is kept up to date and anti-malware measures are applied.
- Vulnerability information is monitored and acted upon.
- Physical
- Work devices and storage media are managed to prevent loss and theft.
- Media and equipment no longer needed are erased or disposed of so that data cannot be recovered.
03Security in building and maintaining on-premise AI
Design
- Systems are designed so that AI processing does not require external communication. Where any external communication is exceptionally needed, its content and purpose are disclosed to the customer and configured only with approval.
Work
- Installation and maintenance are carried out within the scope and procedures agreed in advance.
- Remote maintenance is performed only with the customer's approval, and connection records are kept.
Customer data
- Building and testing are performed with sample data provided by the customer wherever possible, and business data is not taken into the Company's environment.
AI models and software
- AI models and software are adopted after confirming their source and terms of use, and updates are reviewed before being applied.
Handover and termination
- At handover, administrator rights are transferred to the customer and the treatment of accounts used by the Company is agreed.
- When a maintenance contract ends, connection information held by the Company is deleted.
04Security of this website
- Communication with this website is encrypted with SSL/TLS.
- Our contact and download forms include protection against forged and automated submissions.
- Form entries are held only temporarily for processing; they are not accumulated on the web server but are received and managed by email.
- This website does not use analytics tools or advertising services.
05Reporting vulnerabilities and security issues
If you discover a vulnerability or security issue related to our website or services, please contact us. We will review your report and respond in good faith.
Contact: info@rayward.jp (please use the subject "Security report")
We ask that you:
- Do not disclose the issue publicly until we have addressed it.
- Keep testing to the minimum necessary and avoid any action that could disrupt services, affect other users or access personal information.
This contact is also published in our security.txt.
Established: October 6, 2026
RAYWARD Inc.
Hitoshi Watanabe, Representative Director
This English translation is provided for reference. In the event of any discrepancy, the Japanese version shall prevail.