Generated at: 2026-07-14 21:42:51

Security Policy

uSonar has established an advanced security framework to protect our vast database.

Organizational Security Management Measures

We have appointed a person responsible for the handling of personal information, clarified the scope of employees who handle personal information and the personal information they manage, and established a reporting and communication system to the responsible person in the event that any facts or signs of violations of the Act on the Protection of Personal Information or internal regulations are identified.

  1. Establishment of Organizational Structure
    To manage personal information securely, we have designated a Chief Privacy Officer (CPO), audit supervisors, and various operational managers, clearly defining their responsibilities and roles.

  2. Development and Implementation of Compliance Programs (Personal Information Protection Regulations)
    We have established a compliance program as a code of conduct for personal information protection (including provisions based on the determination that Japan ensures an adequate level of protection for personal information in accordance with GDPR). We conduct regular education and training for all personnel engaged in uSonar operations to ensure thorough awareness and promote continuous improvement.

  3. Means to Monitor the Handling Status of Entrusted Data
    We have built a system to visualize the handling status by utilizing an entrusted media management ledger. Furthermore, when receiving data, we issue a "Customer Information Custody and Return Form," store the data on servers with access restrictions, and manage physical media under lock and key.

  4. Evaluation, Review, and Improvement (Establishment and Operation of the Security Center)
    We have assigned personnel responsible for personal information and, through the Security Center (Management Committee, chaired by Representative Director Nami Fukutomi), we execute evaluations, reviews, and improvements on an ongoing basis.

  5. Response to Accidents or Violations
    In the unlikely event that an accident or violation is discovered, we have established a workflow within the Security Center to conduct fact-finding investigations, identify root causes, determine the scope of impact, develop and implement recurrence prevention measures, and execute appropriate countermeasures.

Personnel Security Management Measures

We conduct regular training for employees regarding important considerations for handling personal information and include provisions concerning the confidentiality of personal information in our employment regulations. We implement personnel security management measures by requiring employees to sign non-disclosure agreements regarding designated confidential personal information and by providing ongoing education and training.

  1. Execution of Pledges with Employees at the Time of Hiring
    We require all employees, temporary staff, and part-time workers at uSonar to sign a confidentiality pledge. Furthermore, we require family members to act as joint guarantors.
  2. Execution of Agreements with External Contractors During Outsourcing
    When outsourcing the handling of personal information to direct mail distribution companies, data entry firms, or similar entities, we select providers that maintain a specific standard of information security and personal data protection. As part of our selection process, we have established internal criteria for selecting contractors, maintain investigation records, and clarify the responsibilities (and standards for exemption) of the contractor through business outsourcing agreements, which include provisions for confidentiality, sub-contracting, liability in the event of an incident, and the return or deletion of personal information upon contract termination.
  3. Implementation of Awareness, Education, and Training on Internal Regulations for Employees
    uSonar conducts personal information protection training for all new hires, mid-career recruits, part-time staff, and consultants as part of our onboarding program. For all uSonar employees, we provide updates at least once a year regarding our internal compliance program and personal information protection manuals, including improvements and changes in relevant laws, to ensure full awareness.
  4. Analysis of Employee Psychological States
    We utilize text mining to extract psychological states from the daily reports submitted by employees, allowing us to analyze levels of negativity and positivity.
  5. Special Management of Temporary Staff
    Since temporary staff are employed by different entities, we set their security permissions lower than those of regular employees, ensuring they cannot physically or technically access personal information.
  6. Fair Evaluation and Self-Reporting System
    We strive to maintain employee motivation by ensuring fair evaluations and utilizing systems such as self-reporting.
  7. Prevention of Unauthorized Customer Information Manipulation by Individuals
    We have established a system that prevents any single operator from extracting highly confidential personal information, requiring at least two individuals to perform such tasks.

Physical Security Management Measures

We implement physical security management measures, such as managing entry and exit to buildings and rooms and preventing the theft of personal information, to protect against unauthorized access, loss, destruction, tampering, or leakage of information.

  1. Entry and Exit Management
    We have implemented an entry and exit management system for all doors using employee credit cards, allowing us to track access history and restrict entry and exit.
  2. Prevention of Theft and Similar Incidents

    • Surveillance Cameras
    We monitor for unauthorized intruders and illicit activities 24 hours a day, 365 days a year using surveillance cameras. Image data recorded by these cameras is retained for a minimum of three months for history management purposes.

    • Electronic Media Security Management
    In addition to physical locking mechanisms, access to the area where storage cabinets are located is restricted via an entry/exit management system.

    • After-Hours and Holiday Support
    We provide 24/7/365 security through a combination of building security personnel and monitoring equipment, including surveillance cameras and entry/exit management systems.

    • Prohibition of Removing Equipment from the Office
    Removing equipment such as PCs from the office is prohibited. As an exception, removal is permitted only after following the application and approval procedures designated by the CIO.

    • Implementation of Personal Belongings Inspections
    By conducting random inspections of personal belongings, we regularly check to ensure that unauthorized items—such as personal PCs, storage media, unapproved smartphones, or hazardous materials—are not brought into the office.

Technical Security Management Measures

We have implemented mechanisms to protect information systems that handle personal data from unauthorized external access or malicious software.

  1. Identification and Authentication for Data Access
    For all terminals, we maintain logs in real time that record who performed what operations, at what time, and in what manner.
  2. Access Control

    • Login Control
    uSonar grants access to personal information only to specific employees with authorized privileges. Data is not duplicated, and all access logs are stored and monitored. Furthermore, at uSonar, each individual sets their own password for logging into their personal terminal. Electronic documentation is managed on a shared server, with access control enforced at the folder level within the system.

    • ID Management and Deletion
    We immediately execute permission changes or deletions for IDs and access cards for employees who have transferred or resigned.

  3. Software Security Measures

    Malware Countermeasures
    To address both known and unknown malware, we have installed multiple software solutions on all terminals.

    Blacklisting
    Each user possesses only user-level privileges on their terminal and cannot install applications. We maintain a blacklist of unauthorized software and implement controls to prevent such software from launching, even if it is installed.

  4. Transfer and Transmission Security Measures
    Confidential information transmitted via the uSonar network or the internet is encrypted using TLS and is only sent after receiving approval from a designated administrator. Furthermore, when files are sent via email attachment, an automatic BCC function notifies supervisors. Designated personnel also conduct periodic reviews to ensure that all transmissions were appropriate.
  5. Desktop Virtualization (VDI)
    Through the implementation of VDI, no data remains on individual client terminals (including laptops). Consequently, there is no need to manage data exfiltration risks via USB, Bluetooth, or other external media.
  6. Third-Party Security Audits
    We conduct periodic security inspections (information leakage checks). As a result, we have received evaluations confirming that the uSonar security framework is robust.

Other security measures are not disclosed for security reasons. For further details, please contact us. We will provide explanations as necessary.

Formulation of Personal Information Protection Policies and Establishment of Rules Regarding the Handling of Personal Information

  • • To ensure the appropriate handling of personal information, we have established regulations regarding compliance with relevant laws, guidelines, and the establishment of a point of contact for inquiries and complaints. These cover the acquisition, use, storage,
  • We have established regulations regarding handling methods, responsible personnel, and their respective duties for each stage, including provision, deletion, and disposal.

ISO Certification

uSonar has obtained three ISO certifications.

  1. Information Security Management System - ISO/IEC 27001:2013
    Certification Registration Number: IS 696370  Certification Date: 2018/09/25
  2. ISMS Cloud Security - ISO/IEC 27017:2015
    Certification Registration Number: CLOUD 731975  Certification Date: 2020/11/04
  3. Management System for Protection of PII in Public Clouds Action as PII Processors - ISO/IEC 27018:2019
    Certification Registration Number: PII 731976  Certification Date: 2020/11/04

2021/12/15 Partially Revised
2022/07/19 Updated company name from Landscape Co., Ltd. to uSonar Co., Ltd.

For Urgent Inquiries, Please Call Us at 03-5388-7000 Business Hours: 10:00 AM - 5:00 PM (Closed on Weekends and Holidays)

The Definitive Solution for Sales DX Through Data Utilization

Service Materials

Understand uSonar in 5 Minutes

Understand uSonar in 5 Minutes

Download Materials