Security and Shared Responsibility Policy · KOMORI
Scroll down to continue
campaign
Notice about access volumeDue to the high traffic generated by our current campaign, the sign-up and contracting pages may be temporarily slow or unstable. Services already contracted and day-to-day operations are not affected.
SECURITY IS A SHARED — AND VERIFIABLE — RESPONSIBILITY
「Security and Shared Responsibility Policy」
What KOMORI protects, how, where data is stored, what we do not yet do, and what is the customer role.
Plain-language summary
We publish only measures that are actually implemented and verifiable. What we do not yet do is stated openly on this same page, under "Current limits".
How these documents work
A quotation, individual agreement and product-specific terms prevail where they address the same matter. Nothing in these documents limits mandatory statutory rights. Contact us before contracting if anything is unclear.
01Verifiable safeguards
This policy is meant to be checked, not merely read. Each figure below reflects an actual infrastructure setting at the time of revision, not a target or intention.
Details that would weaken security if published — internal topology, firewall rules, credential names — are provided under a confidentiality agreement during vendor assessment.
TLS 1.2+Encrypted transportTLS 1.0 and 1.1 refused
bcryptPasswordsSalted hash, never plain text
DailyAutomated backupCopied off the server
50+History trailsChanges versioned per record
02Layers of protection
No single control protects a system. We work in layers so that the failure of one does not directly expose data.
From the public edge to the data
L1Edge and mitigationPublic traffic passes through a CDN/WAF before reaching the application.
L2Encrypted transportHTTPS enforced, using TLS 1.2 or 1.3 with a valid public certificate.
L3Network and portsAdministrative and database services are not exposed to the internet; filtering is reapplied automatically on every server restart.
L4Application and permissionsIndividual accounts, role and module permissions, checked on every request.
L5Data and audit trailMaterial changes write history with author and timestamp, allowing reconstruction of what changed.
03Where data is stored and who processes it
This is the information that most affects a vendor assessment, so it comes first and without hedging.
By contracting, the customer authorizes this processing. If your operation requires data to remain physically in Japan, tell us before contracting: that condition must be written into the contract, as it is not the current configuration.
Providers processing data to deliver the service, as of this revision.
Provider
Role
Country
Data involved
Contabo GmbH
Server running the application and database
United States
All service data
Cloudflare, Inc.
Network edge, attack protection and content delivery
United States
Connection and traffic metadata
Google LLC
Corporate e-mail and backup destination
United States
Messages and backup files
Stripe, Inc.
Card and convenience-store payment processing
United States
Billing data. KOMORI does not store card numbers.
04Transport, accounts and access
All system access happens over an encrypted channel under a named account. There are no accounts shared between people and no anonymous access to customer data.
Control
Current state
Note
Transport protocol
TLS 1.2 and TLS 1.3
Older versions refuse the connection
Password storage
Salted bcrypt hash
Irreversible; not even KOMORI can recover the original
Permission model
By role and by module
Checked on each request, not only in the menu
Browser protection headers
nosniff · SAMEORIGIN · restricted referrer
Reduces content hijacking and referrer leakage
05Backup and continuity
Backups are generated automatically every day and copied off the production server, so losing the server does not mean losing the data.
The database is copied consistently without interrupting service. Each run is logged, so a failed backup is detected then, rather than at the moment a restore is needed.
DailyFrequencyAutomatic, no manual step
14days of databaseDatabase copy retention
31days of filesFile copy retention
06Who does what
Most real incidents do not come from a provider technical failure, but from a forgotten permission, an unprotected device or a shared password. Hence the explicit split below.
AreaKOMORICustomer
Infrastructure and networkServer, port filtering, component updatesOwn office network and equipment
User accountsLogin mechanism, password hashing, sessionCreate, review and remove users when people leave
PermissionsProvide role and module controlsDecide who sees what and review periodically
Data contentStore, protect and return on requestLegality, accuracy and necessity of what is entered
BackupRun, verify and retain per this policyTell us if retention beyond the standard is needed
IncidentsContain, investigate, fix and notifyReport suspicion immediately, without waiting for confirmation
07Incident response
If unauthorized access, leakage, loss or unauthorized change occurs, we follow a defined sequence. It exists so the response does not depend on improvisation at the worst moment.
01ContainStop what is in progress and limit the reach, even if that means temporarily suspending a feature.
02PreserveKeep logs and evidence before any fix, so the cause can be determined afterwards.
03DetermineIdentify what was accessed, whose data it was and the real impact, without downplaying.
04NotifyInform the affected customer as soon as reliable information exists, and the competent authority when required by law.
05FixRemove the cause, not just the symptom, and confirm the fix worked.
06PreventRecord the lesson and change process or code so the same failure does not return in another form.
08AI with limited context
We use AI for support, organization and verification. That extends the team capability, but also extends the reach of a mistake. Its use is therefore limited by design.
The agent receives only the context of the product and the user being assisted.
Irreversible actions and high-impact decisions require human confirmation.
AI does not decide legal, medical, financial or disciplinary matters on behalf of KOMORI or the customer.
09Current limits
The measures below are not yet implemented. They are listed because their absence may matter to the customer decision, and omitting them would be misleading.
Measure
Status
Two-factor authentication
Not available. Access relies on the password and the customer internal policy.
Disk encryption at rest
Not applied to the server volume. Backups travel to and rest in an external service with account-based access control.
HSTS and Content Security Policy
Not yet enabled. HTTPS works, but without these additional hardening layers.
Independent third-party certification
None held. Vendor assessments are handled with documentation and a technical interview.
10Reporting a security flaw
If you find a vulnerability in any KOMORI system, report it through the support channel before public disclosure. We commit to acknowledge, investigate and report the outcome.
Do not access, change or copy third-party data while verifying.
Do not run tests that degrade the service for other users.
Anyone reporting in good faith and respecting these limits will face no legal action from KOMORI for doing so.
Contact channel
Use these channels for questions about data, security or contractual terms.
Your contact has entered the chat queue. Our team will reply through this channel.
Essential cookies and privacy
We use essential first-party cookies for language, sessions, security and requested functions. External services and browser choices are explained in the External Transmission Policy.
admin_panel_settings
Login
Use your authorized account to access the internal environment.