uSonar has established an advanced security framework to protect our vast database.
We have appointed a person responsible for the handling of personal information, clarified the scope of employees who handle personal information and the personal information they manage, and established a reporting and communication system to the responsible person in the event that any facts or signs of violations of the Act on the Protection of Personal Information or internal regulations are identified.
Establishment of Organizational Structure
To manage personal information securely, we have designated a Chief Privacy Officer (CPO), audit supervisors, and various operational managers, clearly defining their responsibilities and roles.
Development and Implementation of Compliance Programs (Personal Information Protection Regulations)
We have established a compliance program as a code of conduct for personal information protection (including provisions based on the determination that Japan ensures an adequate level of protection for personal information in accordance with GDPR). We conduct regular education and training for all personnel engaged in uSonar operations to ensure thorough awareness and promote continuous improvement.
Means to Monitor the Handling Status of Entrusted Data
We have built a system to visualize the handling status by utilizing an entrusted media management ledger. Furthermore, when receiving data, we issue a "Customer Information Custody and Return Form," store the data on servers with access restrictions, and manage physical media under lock and key.
Evaluation, Review, and Improvement (Establishment and Operation of the Security Center)
We have assigned personnel responsible for personal information and, through the Security Center (Management Committee, chaired by Representative Director Nami Fukutomi), we execute evaluations, reviews, and improvements on an ongoing basis.
Response to Accidents or Violations
In the unlikely event that an accident or violation is discovered, we have established a workflow within the Security Center to conduct fact-finding investigations, identify root causes, determine the scope of impact, develop and implement recurrence prevention measures, and execute appropriate countermeasures.
We conduct regular training for employees regarding important considerations for handling personal information and include provisions concerning the confidentiality of personal information in our employment regulations. We implement personnel security management measures by requiring employees to sign non-disclosure agreements regarding designated confidential personal information and by providing ongoing education and training.
We implement physical security management measures, such as managing entry and exit to buildings and rooms and preventing the theft of personal information, to protect against unauthorized access, loss, destruction, tampering, or leakage of information.
Prevention of Theft and Similar Incidents
• Surveillance Cameras
We monitor for unauthorized intruders and illicit activities 24 hours a day, 365 days a year using surveillance cameras. Image data recorded by these cameras is retained for a minimum of three months for history management purposes.
• Electronic Media Security Management
In addition to physical locking mechanisms, access to the area where storage cabinets are located is restricted via an entry/exit management system.
• After-Hours and Holiday Support
We provide 24/7/365 security through a combination of building security personnel and monitoring equipment, including surveillance cameras and entry/exit management systems.
• Prohibition of Removing Equipment from the Office
Removing equipment such as PCs from the office is prohibited. As an exception, removal is permitted only after following the application and approval procedures designated by the CIO.
• Implementation of Personal Belongings Inspections
By conducting random inspections of personal belongings, we regularly check to ensure that unauthorized items—such as personal PCs, storage media, unapproved smartphones, or hazardous materials—are not brought into the office.
We have implemented mechanisms to protect information systems that handle personal data from unauthorized external access or malicious software.
Access Control
• Login Control
uSonar grants access to personal information only to specific employees with authorized privileges. Data is not duplicated, and all access logs are stored and monitored. Furthermore, at uSonar, each individual sets their own password for logging into their personal terminal. Electronic documentation is managed on a shared server, with access control enforced at the folder level within the system.
• ID Management and Deletion
We immediately execute permission changes or deletions for IDs and access cards for employees who have transferred or resigned.
Software Security Measures
Malware Countermeasures
To address both known and unknown malware, we have installed multiple software solutions on all terminals.
Blacklisting
Each user possesses only user-level privileges on their terminal and cannot install applications. We maintain a blacklist of unauthorized software and implement controls to prevent such software from launching, even if it is installed.
Other security measures are not disclosed for security reasons. For further details, please contact us. We will provide explanations as necessary.
uSonar has obtained three ISO certifications.
2021/12/15 Partially Revised
2022/07/19 Updated company name from Landscape Co., Ltd. to uSonar Co., Ltd.