Information Security Policy / Basic Policy on Cloud Security
Information Security Policy
enechain (hereinafter "we") are committed to company-wide information security based on the following policy to protect our information assets and those entrusted to us by our customers from threats such as incidents, disasters, and crimes, and to live up to the trust of our customers and society.
1. Management's Responsibility
The management will take the initiative in systematically and continuously improving and enhancing information security.
2. Establishment of company structure
We will set up an organization to maintain and improve information security, and establish information security measures as official company rules.
3. Efforts by Employees
Our employees will acquire the knowledge and skills required for information security, and ensure that they are committed to information security.
4. Compliance with laws, regulations, and contractual requirements
We will comply with laws, regulations, norms, and contractual obligations related to information security, and will meet the expectations of our customers.
5. Response to Violations and Incidents
In the event of an incident or a violation of laws, regulations, rules, or contractual obligations related to information security, we will take appropriate action to prevent recurrence of such an incident.
Contact for Vulnerability Reporting and Security Incidents
csirt@enechain.co.jp
Basic Policy on Cloud Security
To fulfill our responsibilities as a Cloud Service Provider (CSP) for the cloud services we provide (hereinafter referred to as "the Service") and as a Cloud Service Customer (CSC) for the cloud services we utilize in our business activities, we have established this policy in compliance with ISO/IEC 27017.
1. Requirements Applicable to Cloud Service Design and Implementation
In the development and operation of the Service, we apply security requirements requested by our customers as well as our Information Security Basic Policy to design and implement a secure environment optimized for the cloud.
2. Risk Assessment for Cloud Services
We regularly conduct risk assessments to identify and evaluate risks inherent to cloud environments (such as misconfigurations, unauthorized access, and data leakage) and implement appropriate control measures.
3. Application of the Shared Responsibility Model
We properly understand and apply the Shared Responsibility Model for our adopted cloud infrastructure (such as IaaS and PaaS). In addition to the infrastructure security guaranteed by cloud providers, we properly maintain and manage the security configurations of virtual environments, networks, applications, and data under our responsibility.
4. Isolation in Virtual and Multi-Tenant Environments
The Service strictly isolates each customer's environment and data by leveraging logical isolation features (such as project boundaries and virtual networks) provided by cloud service providers, alongside appropriate database design, thereby preventing any interference with, or leakage of, data between customers.
5. Employee Access to and Protection of Customer Data
During maintenance and operational activities, employee access to customer data is strictly limited to the bare minimum required. Furthermore, we thoroughly verify the identity of employees with access privileges and will not monitor, edit, or disclose customer data without prior authorization.
6. Access Control and Credential Management
Access to the cloud services we use and provide strictly requires strong password policies and Multi-Factor Authentication (MFA) using Identity and Access Management (IAM) capabilities provided by cloud service providers, in order to prevent unauthorized privileged access.
7. Customer Notifications and Change Management
When specification changes to the Service, major cloud infrastructure failures, or events affecting security are identified, we will promptly inform our customers according to predetermined notification processes.
8. Customer Account Management
Customer account information within the Service is properly managed throughout its lifecycle (registration, modification, and deletion upon contract termination) under our responsibility.
9. Data Protection and Secure Lifecycle Management
We thoroughly encrypt data at rest and data in transit in cloud environments. Upon contract termination or cancellation, all data stored in cloud environments will be securely and completely erased, rendering it unrecoverable.
10. Continuous Improvement
We continuously monitor security technology trends, cloud infrastructure updates, and changes in legal regulations to drive ongoing improvements in this policy and our security management structure.
Version History
Version 2 Updated: August 13, 2026
Version 1 Established: May 16, 2022
CEO
Ryo Nozawa
enechain Corporation


