FP Partner Inc.Information Security
Recognizing that the information assets handled during its business activities are a critical foundation of its management, the Company believes it has a social responsibility to protect such assets from risks such as leakage, damage, or loss and to manage them appropriately. To this end, the Company has established this Information Security Policy and will implement and maintain it.
The Company uses cloud infrastructure that meets high security standards to protect customers’ important information and has established and strengthened a customer information management framework based on a defense-in-depth approach.
The Company enforces the principle of least privilege, encrypted communications, and the preservation of audit logs, and continuously improves day-to-day operations through ongoing system monitoring and internal audits.
Business systems are operated on cloud infrastructure designed with availability, scalability, and security in mind.
To reduce risk, network access is restricted to secure connection routes, and access to data is controlled through appropriate role-based permissions.
Data is encrypted both at rest and in transit, and encryption keys are managed appropriately.
Company-issued smartphones and PCs are managed under an integrated endpoint management framework, with full-disk encryption, enhanced authentication, and remote protection measures in place. A secure working environment is maintained through the continuous application of the latest security patches and the proactive detection of suspicious activity.
Business chat tools are used for day-to-day work communications to improve operational flexibility. When coordinating with external customers and partners, communication practices are designed to balance convenience with security.
Certified under the PrivacyMark system, personal information is handled in accordance with applicable laws and internal rules, including limiting purposes of use, applying the principle of least privilege, and preserving audit trails.
The data protection framework is continuously improved through education, training, and internal audits.
In addition, procedures for detection, containment, and recovery have been established in preparation for potential incidents, and regular drills are conducted.
