Security
Security & Trust
We have held ISO/IEC 27001 (ISMS) certification since 2016 and run an information security management system under it. Protecting the information our clients place with us is a condition of doing business, not an add-on.
ISMS certification
| Standard | ISO/IEC 27001:2022 (JIS Q 27001:2023) |
|---|---|
| Registration number | ISA IS 0201 |
| Scope | Head office |
| Certification body | International System Audit Co., Ltd. JAPAN |
| Certified since | July 2016 |
| Valid until | 18 July 2028 |
Controls we operate
Organisational
A named owner, written procedures, risk assessment, and management of subcontractors.
People
Training on joining and every year after, confidentiality agreements, and withdrawal of access on leaving.
Physical
Access control to work areas, control of removable media, clear desk.
Technical
Access control, retained operation logs, malware protection, vulnerability management.
Using generative AI on client work
Four commitments that apply whenever we use generative AI in our own work or in what we deliver.
Your data is not used for training
We configure engagements so that data you give us is not used to train models, and we secure that in the contract as well as in the settings. The configuration is shown to you at the start of the work.
Output is not the final decision
Generated output is not used as a business decision or a deliverable on its own. Who reviews it, and what they are responsible for, is written into the workflow.
We say when we used it
Where generative AI was used in producing a deliverable, we disclose it within the scope agreed with you.
Rights and law
We work on the basis that third-party rights are not infringed and that applicable laws and guidelines are followed.
The full policy, including retention periods, access scope, subcontracting and deletion at the end of an engagement, is published in Japanese at AI利用方針・データの取り扱い.
Security enquiries and vulnerability reports
Emailcompliance@afroci.com Phone+81-3-5817-8244