Information Security Policy
StandUp Inc. (the “Company”) is entrusted with important information about customers, business partners and employees through its real estate operations and its AI adoption support. Recognising that protecting this information is a precondition of our business, we establish this Information Security Policy and act on it as an organisation.
1. Purpose
This Policy sets out what is necessary to protect the important information the Company handles — personal information of customers, tenants, property owners and business partners, trade secrets, and confidential information learned in the course of business — from leakage, alteration, loss and other threats, and to keep our business running without interruption.
2. Scope
This Policy applies to the Company's directors and employees (including part-time, casual and dispatched staff) and to contractors entrusted with the Company's work. It covers all information and information systems used in our business activities (computers, smartphones, cloud services, documents, storage media and the like).
3. Management responsibility and structure
The Company treats information security as a key management issue and appoints the Representative Director as the chief officer responsible for information security. The chief officer secures the structure and resources needed to implement our measures and regularly reviews how this Policy is being carried out.
4. Implementation of information security measures
Guided by the “Information Security Guidelines for Small and Medium-sized Enterprises” published by the Information-technology Promotion Agency, Japan (IPA), the Company implements the following measures.
(1) Basic measures
- We keep the operating systems and software on computers, smartphones and similar devices up to date at all times.
- We keep anti-virus functions enabled and definition files current.
- We set passwords that are hard to guess and use multi-factor authentication where available. Reusing passwords is prohibited.
- We limit file and folder sharing settings to those who need access for their work.
- We back up important information regularly in preparation for equipment failure, operating error, virus infection and similar events.
- We gather information on new threats and attack methods and share it within the company.
(2) Measures in day-to-day work
- We do not casually open email attachments or URLs contained in messages, and we verify suspicious email before opening it.
- We check the recipient before sending, to prevent misdirected email and fax.
- We exchange important information by safe means such as encryption or password protection.
- We configure appropriate encryption on the wireless LAN used for business.
- We follow the rules we have set for use of the internet and social media, including not posting information learned through our work.
- We do not leave documents or storage media containing important information on desks, and keep them in a lockable place. We take precautions against theft and loss when taking them outside.
- We dispose of documents and storage media that are no longer needed by a method that prevents restoration.
- We lock the screen when away from the desk and store computers and similar devices safely when leaving the office.
- We restrict entry to the office by people other than those concerned.
- We do not publish information that should not be disclosed on our website or elsewhere.
(3) Organisational measures
- We provide ongoing education and reminders on information security to directors and employees.
- We clearly define how personally owned devices are treated when used for work.
- We include confidentiality clauses in contracts for transactions that involve the exchange of important information.
- We select cloud services and other external services only after confirming their safety and reliability.
- We set out our information security measures as rules and make them known to directors and employees.
5. Compliance with laws and contractual requirements
The Company complies with the Act on the Protection of Personal Information, Article 45 of the Building Lots and Buildings Transaction Business Act (the duty to keep secrets learned in the course of business), the Unfair Competition Prevention Act and other related laws and standards, as well as confidentiality obligations under contracts with business partners. The specific handling of personal information is set out in our Privacy Policy.
6. Management of contractors
Where all or part of our work is outsourced, we select contractors after confirming the state of their information security measures, conclude contracts that include confidentiality obligations, and exercise necessary and appropriate supervision.
7. Response to incidents
The Company maintains an emergency reporting structure and response procedures for information security incidents and suspected incidents. If an incident occurs, we act first to prevent the damage from spreading, promptly report to the customers, business partners and supervisory authorities concerned, investigate the cause and put measures in place to prevent recurrence.
8. Continuous review
The Company reviews how this Policy is being carried out at least once a year, and revises the Policy and related internal rules as our business changes and new threats emerge, improving them continuously.
Established 31 July 2026
StandUp Inc.
Representative Director: Yutaro Torigoe
3-15-5 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
Real estate licence: Governor of Tokyo (01) No. 107241
*This Policy was prepared with reference to the “Information Security Guidelines for Small and Medium-sized Enterprises (4th edition)” and its appendix “Five-minute Information Security Self-check” published by the Information-technology Promotion Agency, Japan (IPA).
Questions about how we handle information? Just ask.
We are also happy to answer the security checks that come with doing business together.