Information security policy

How nomarz LLC (nomarz合同会社, brand: Orrery; “we”) protects the information our clients entrust to us.

Last updated: [Revision date]

Basic policy

We are entrusted with our clients’ business data in order to design, build and run AI agents. To handle it safely, we comply with the applicable laws and our contracts, and work according to this policy.

Person responsible for information security
[Information security officer]

Scope

This policy applies to the information we handle in our work (data entrusted by clients, the AI agents we build and run and their settings, and internal information) and to everyone who works with us.

Data in private environments

Client data is stored and processed in a private environment that is not open to the public.

Environment
[How the private environment is set up (client’s or ours, which cloud, which country the data is in)]
Separation by client
[How each client’s data is kept separate]
Encryption
[Encryption in transit and at rest]
Retention and deletion
[How long data is kept, and how it is returned or deleted when a contract ends]

Access control

Only the people whose work requires it can access data and AI agent settings. AI agents, too, act only within the permissions set for them.

Who has access
[Who can access, and how access is granted and reviewed]
Authentication
[How sign-in is authenticated (multi-factor authentication, etc.)]
AI agent permissions
[How permissions for AI agents are decided]

Activity logs

Every AI agent action is logged. Logs are used to find the cause when something goes wrong, and to improve.

What is logged
[Which actions are logged (including whether human access to data is)]
Fields
[Fields recorded (the action, time, who approved, etc.)]
Retention
[How long logs are kept]
How to check
[How clients can check the logs]

Human approval (approval gates)

Before an AI agent carries out an important action, a person checks and approves it. Which actions need approval, we decide with the client at the design stage.

Actions that need approval
[List of actions that need approval]
Who approves
[How the approver is chosen]

How responsibility is shared for approved actions is set out in the guarantee and support terms.

Your data is never used for training

We never use entrusted data to train AI models.

[External AI services used, and the settings or contract terms confirming that input data is not used for training]

Managing processors

When we use outside services such as cloud hosting or email delivery, we check that they handle information properly before choosing them, and share only the information they need.

[What we check when choosing processors, and how often we review them]

Examples and the list of processors are in our privacy policy.

Training

Everyone who works with us is informed about this policy and trained in how to handle information. [Training content and frequency]

Incident response

If an incident such as a data leak occurs or may have occurred, we act to limit the damage, investigate the cause and prevent it from happening again. Where the Act on the Protection of Personal Information requires a report to the Personal Information Protection Commission or notice to the people affected, we make it as the law requires.

Telling affected clients
[How and how quickly affected clients are told]
Stopping AI agents
[How a problematic AI agent is paused]
Where to report
Security reports are accepted at [Contact email].

Ongoing review

We review this policy and our practices [Regular review frequency], and also when technology, threats or laws change, and keep improving them.