Skycreates Inc. (the “Company”) provides technical services focused on infrastructure and security, and develops and operates its own products.
The Company regards the information assets entrusted to us by our customers, as well as the information assets we own and manage, as important management resources. We believe that appropriately protecting these assets from a wide range of threats is an essential responsibility for sustaining our business and earning the trust of society.
To that end, we continuously operate and improve our Information Security Management System (ISMS), ensure the confidentiality, integrity and availability of information assets, and strive to provide safe and reliable services.
Code of Conduct
- We take appropriate organizational and technical measures to reliably protect the confidentiality, integrity and availability of information assets, and respond to changing information technology and new threats.
- We provide information security training to all employees and ensure they are thoroughly informed of this policy, working to raise and maintain awareness.
- We set objectives for our management system and information security, review them regularly, and continuously improve and maintain them.
1. Internal structure and information security policy
We establish the management structure necessary to maintain and improve security, and define the necessary information security measures as formal internal rules.
2. Leadership responsibility and continuous improvement
Our management leads the way in ensuring that the information assets of the Company and our customers are properly managed through compliance with this policy.
3. Compliance with laws and contractual requirements
Our employees comply with laws, regulations, norms and contractual security requirements with customers relating to the information assets used in our business activities.
4. Employee efforts
Our employees acquire the knowledge and skills required to maintain and improve information security, ensuring our information security efforts are effective.
5. Response to violations and incidents
We establish a structure for responding to violations of laws, regulations, norms and customer contracts related to information security, as well as information security incidents, and reduce their impact.
Established: March 15, 2019Revised: September 27, 2026Skycreates Inc.Yoshitaka Yanase, CEO
Our practices in detail
How we manage information security
Under the responsibility of management, we treat information security as a key management issue and operate a management structure based on our ISMS.
- Management sets information security objectives and secures the necessary resources.
- We identify information assets, assess risks, and select and review controls according to those risks.
- We conduct internal audits and management reviews on a regular basis to confirm and improve effectiveness.
- We provide regular information security training to all employees.
- We require our contractors to maintain a level of information security equivalent to our own, and manage them appropriately.
Protecting information
We handle information entrusted to us by our customers only within the scope of our contracts and its intended purpose, and protect it with measures such as the following:
- Access control based on least privilege, with recording and review of access
- Technical measures appropriate to the sensitivity of information, such as encryption in transit and at rest
- Proper management of devices and accounts, and prevention of unauthorized access through measures such as multi-factor authentication
- Regular backups and established recovery procedures
- Secure deletion and disposal of information that is no longer needed
Building security in
In developing and operating our own products and systems for our customers, we build security into every stage of design, development and operation rather than adding it afterwards.
- Considering security requirements at the design stage
- Code review to verify quality and safety
- Vulnerability management and continuous updating of the libraries and components we use
- Separation of development, staging and production environments, and proper management of credentials and keys
- Secure coding training for developers
Responding to incidents
We have established procedures and a structure for responding when an information security incident occurs or is suspected.
- We respond promptly to prevent further damage.
- We investigate the scope and cause, and work to restore normal operations.
- We promptly notify affected customers and report to the relevant authorities as required by law.
- We analyze root causes and take measures to prevent recurrence.
For how we handle personal information, please see our Privacy Policy.