POLICY
Information Security Policy
Popaz co. ("we," "us" or "the Company") operates principally in website and e-commerce development, system and app development, and digital marketing support (including managed social media operations). We recognize that protecting the information assets entrusted to us by our clients — merchants as well as the production companies and agencies we collaborate with — including customer data, system credentials, social media account information and source code, from every kind of threat, and managing them safely and appropriately, is the single most important issue in our business. In order to live up to that trust and build strong partnerships, we hereby establish the following Information Security Policy and declare that we will comply with it and put it into practice.
1. Information security management structure
Our Representative Director serves as the officer responsible for information security, and personally bears full responsibility for the rigorous protection and management of all information assets involved in our business activities.
2. Appropriate protection and management of information assets
To ensure the confidentiality, integrity and availability of the information assets we handle, we implement the following technical and physical measures.
Strict management of access privileges:
Access to client systems (servers, CMS admin consoles, cloud services, social media accounts and so on) uses only the minimum privileges required for the work, with multi-factor authentication (MFA) applied wherever possible. Once the work or project is complete, we promptly request removal of those privileges, or revoke our own access ourselves.
Management of source code and confidential information:
Source code used in development work is kept in secure repositories with appropriate access control, and confidential information such as API keys and access tokens is never written directly into source code but is managed under strict control. Customer and account information handled in marketing work is likewise managed centrally in a hardened security environment.
Protection of devices and network environments:
Every device used for work has anti-malware software installed, keeps its OS and software up to date, and has encrypted storage; work is performed only over secure network environments.
3. Compliance with legal and contractual requirements
We comply with the laws, government guidelines and other norms relating to information security. We also strictly observe the security requirements of contracts concluded with clients, including non-disclosure agreements (NDAs).
4. Response to information security incidents
In the unlikely event that an information security incident such as a data leak or unauthorized access occurs, or is suspected, we will report it to the affected client immediately, take initial action to contain the damage, investigate the cause, and swiftly put preventive measures in place.
5. Continuous improvement
We keep track of the expansion of our business areas, changes in the information security landscape and the movement of new threats, and work to review and improve our information security measures on an ongoing basis.