Generated at: 2026-09-01 03:46:39

Security Policy

uSonar has established an advanced security framework to protect our extensive database.

Organizational Security Management Measures

We have appointed a manager responsible for the handling of personal information, clarified the scope of employees who handle personal information and the personal information they manage, and established a reporting and communication system to the responsible manager in the event that any facts or signs of violations of the Personal Information Protection Act or internal regulations are identified.

  1. Development of Organizational Structure
    To manage personal information securely, we have appointed a Chief Privacy Officer (CPO), an audit manager, and various operational managers, clearly defining their responsibilities and roles.

  2. Development and Operation of Compliance Programs (Personal Information Protection Regulations)
    We have established a compliance program as a code of conduct for personal information protection (including provisions based on the determination that Japan ensures an adequate level of protection for personal information in accordance with GDPR). We conduct regular education and training for all personnel engaged in uSonar's business to ensure thorough awareness and promote continuous improvement.

  3. Means to Monitor the Handling Status of Entrusted Data
    We have built a system that centralizes the handling status of entrusted media using a management ledger. When data is entrusted, we issue a "Customer Information Deposit and Return Receipt," store the data on servers with access restrictions, and manage physical media under lock and key.

  4. Evaluation, Review, and Improvement (Establishment and Operation of the Security Center)
    We have assigned responsible personnel and staff for personal information and execute ongoing evaluations, reviews, and improvements through our Security Center (Management Committee Chairperson: Representative Director Nami Fukutomi).

  5. Response to Incidents or Violations
    In the unlikely event that an incident or violation is discovered, our Security Center has established a workflow to conduct fact-finding investigations, determine root causes, identify the scope of impact, implement recurrence prevention measures, and execute appropriate corrective actions.

Personnel Security Management Measures

We conduct regular training for employees regarding considerations for handling personal information and include confidentiality requirements for personal information in our employment regulations. We implement personnel security management measures by requiring employees to sign non-disclosure agreements for designated confidential personal information and by providing ongoing education and training.

  1. Execution of Confidentiality Agreements at the Time of Employment
    We require all employees, temporary staff, and part-time workers at uSonar to sign a confidentiality agreement. Furthermore, we require family members to act as joint guarantors.
  2. Execution of Contracts with External Vendors for Outsourced Operations
    When outsourcing the handling of personal information to entities such as direct mail distribution companies or data entry firms, we select providers that maintain a high standard of information security and personal data protection. We have established internal criteria for selecting contractors, maintain records of our assessments, and clarify the responsibilities (and criteria for exemption) of the contractor through service agreements that include provisions for confidentiality, sub-contracting, liability in the event of an incident, and the return or deletion of personal information upon contract termination.
  3. Dissemination of Internal Regulations and Implementation of Education and Training for Employees
    uSonar conducts personal information protection training as part of the onboarding programs for all new hires, mid-career recruits, part-time staff, and advisors. For all uSonar employees, we provide updates at least once a year regarding our internal compliance program, revisions to the personal information protection training manual, and any relevant changes in legislation.
  4. Analysis of Employee Psychological State
    We utilize text mining to extract and analyze the psychological state of employees based on their daily reports, assessing levels of negativity and positivity.
  5. Special Management for Temporary Staff
    Because temporary staff have different employers, we set their security access privileges lower than those of permanent employees, ensuring they cannot physically or technically access personal information.
  6. Fair Evaluation and Self-Reporting System
    We strive to maintain employee motivation by ensuring fair evaluations and utilizing systems such as self-reporting.
  7. Prevention of Unauthorized Customer Information Manipulation by Individuals
    We have established a system that prevents any single operator from extracting highly confidential personal information, requiring at least two individuals to perform such tasks.

Physical Security Management Measures

We implement physical security management measures, including access control for buildings and rooms, and the prevention of theft of personal information, to protect against unauthorized access, loss, destruction, alteration, and leakage of information.

  1. Building and Room Access Control
    We have implemented an access control system for all doors using employee credit cards to manage entry and exit logs and restrict access.
  2. Prevention of Theft and Other Incidents

    • Surveillance Cameras
    We monitor for unauthorized intruders and illicit activities 24 hours a day, 365 days a year using surveillance cameras. Recorded image data is retained for a minimum of three months for log management purposes.

    • Locked Storage for Electronic Media
    In addition to physical locking mechanisms, access to areas containing storage cabinets is restricted via our access control system.

    • After-Hours and Holiday Security
    We maintain 24/7, 365-day security through a combination of building security personnel and monitoring equipment, including surveillance cameras and access control systems.

    • Prohibition of Removing Equipment from the Office
    Removing equipment such as PCs from the office is prohibited. Exceptions are permitted only following a formal application to and approval by the CIO.

    • Implementation of Personal Belongings Inspections
    We conduct random inspections of personal belongings to regularly check for unauthorized items, such as personal PCs, storage media, unapproved smartphones, or hazardous materials.

Technical Security Management Measures

We have implemented mechanisms to protect information systems that handle personal data from unauthorized external access or malicious software.

  1. Identification and Authentication for Data Access
    We maintain comprehensive logs for all terminals, recording in real time who performed which operations, at what time, and how.
  2. Access Control

    • Login Control
    uSonar grants access to personal information only to authorized personnel. Data is not duplicated, and access logs are maintained and monitored. Furthermore, at uSonar, each individual sets their own password for logging into their personal terminal. Electronic documentation is managed on a shared server, with access control implemented at the folder level within the system.

    • ID Management and Deletion
    We immediately modify or revoke access rights, including IDs and building access cards, for employees who transfer or resign.

  3. Software Security Measures

    Malware Protection
    To defend against both known and unknown malware, we have installed multiple security software solutions on all terminals.

    Blacklisting
    Each user is granted only standard user privileges on their terminal and is prohibited from installing applications. We maintain a blacklist of unauthorized software and have implemented controls to prevent such software from launching, even if it were to be installed.

  4. Measures for Data Transfer and Transmission
    Confidential information transmitted via the uSonar network or the internet is encrypted using TLS and is only sent after receiving approval from a designated administrator. Additionally, when files are sent via email attachments, an automatic BCC function notifies supervisors. Designated personnel also conduct periodic reviews to ensure that all transmissions were appropriate.
  5. Desktop Virtualization (VDI)
    Through the implementation of VDI, no data is stored on the client terminals (including laptops) used by individuals. Consequently, there is no need for measures against data exfiltration via USB, Bluetooth, or other external media.
  6. Implementation of Third-Party Security Audits
    We conduct regular security inspections (information leakage checks). As a result, we have received evaluations confirming that uSonar's security framework is robust.

For security reasons, other measures are not disclosed. Please contact us for further details. We will provide explanations as necessary.

Formulation of Personal Information Protection Policies and Establishment of Rules Regarding the Handling of Personal Information

  • • To ensure the appropriate handling of personal information, we have established regulations regarding compliance with relevant laws, guidelines, and other standards, as well as points of contact for inquiries and complaints. For the stages of acquisition, utilization, storage,
  • • Provision, deletion, and disposal, we have established regulations concerning handling methods, responsible personnel, and their respective duties.

ISO Certification

uSonar has obtained three ISO certifications.

  1. Information Security Management System - ISO/IEC 27001:2013
    Certification Registration Number: IS 696370  Certification Date: 2018/09/25
  2. ISMS Cloud Security - ISO/IEC 27017:2015
    Certification Registration Number: CLOUD 731975  Certification Date: 2020/11/04
  3. Management System for Protection of PII in Public Clouds Action as PII Processors - ISO/IEC 27018:2019
    Certification Registration Number: PII 731976  Certification Date: 2020/11/04

December 15, 2021: Partially Revised
July 19, 2022: Updated company name from Landscape Co., Ltd. to uSonar Co., Ltd.

For Urgent Inquiries, Please Call Us03-5388-7000Business Hours: 10:00 AM - 5:00 PM (Closed on Weekends and Holidays)

The Definitive Solution for Sales DX Through Data Utilization

Service Brochure

uSonar in 5 Minutes

Understand uSonar in 5 Minutes

Download Brochure