Security Policy
보안 정책

Yaraku 번역의 보안 체계
비즈니스 현장에서도 안심하고 사용할 수 있도록 Yaraku 번역에서는 정보 관리 체계를 구축하고 세심한 주의를 기울여 서비스를 운영하고 있습니다.
보안 기능

- 고객별 데이터 관리
- 데이터 암호화
- 데이터 상시 백업
- 24시간 365일 시스템 모니터링
- 취약점 및 해킹 대응
- SSO(Single Sign-On)
- 프라이빗 클라우드 도입
컴플라이언스 프로그램
Yaraku 번역은 아래 인증을 취득했습니다.

ISMS(ISO/IEC 27001:2022) 인증
야라쿠 주식회사 도쿄 본사는 2022년 12월 22일부로 정보 보안 관리 시스템(ISMS)의 국제 규격인 ISO/IEC 27001:2022 및 JIS Q 27001:2023 인증을 취득했습니다.
인증 등록 개요 등록 조직: 야라쿠 주식회사 인증 등록 범위: 다국어 커뮤니케이션 도구의 기획, 개발 및 관련 서비스 제공 인증 규격: ISO/IEC 27001:2022, JIS Q 27001:2023 인증서 번호: IS778669 인증 등록일: 2022년 12월 22일 최근 갱신일: 2025년 2월 4일

Yaraku 번역의 데이터 관리
Yaraku 번역에 보관된 데이터는 고객의 프라이버시가 안전하게 보호되도록 관리됩니다.

데이터베이스
Yaraku 번역에서는 고객별로 번역 데이터가 별도로 관리됩니다. 따라서 제3자가 데이터베이스에 접근하거나 변경할 수 없습니다. 야라쿠 주식회사에서는 권한이 부여된 직원만 데이터베이스에 접근할 수 있으며, 시스템 유지보수 및 문제 해결 목적으로만 사용됩니다.
고객의 동의를 받은 경우 또는 법령에 따라 요구되는 경우 등 특정 상황을 제외하고 데이터는 공개하지 않습니다.
데이터베이스의 데이터는 지속적으로 백업됩니다. 인적 오류로 데이터가 손실된 경우, 최근 14일간 보관된 백업을 사용해 시스템의 데이터를 복원할 수 있습니다.

암호화
Yaraku 번역에서는 모든 통신에 SSL(*)을 사용해 데이터를 암호화합니다. 이를 통해 제3자가 내용을 확인하거나 변조할 수 없습니다. 또한 비밀번호 등 기밀성이 높은 데이터는 데이터베이스 내에서 암호화됩니다.
*SSL은 Secure Sockets Layer의 약자로, 온라인 결제를 처리하는 웹페이지 등에서도 널리 사용되며 통신 내용을 암호화해 도청과 변조를 방지하는 방식입니다.
취약점·해킹 대책
소중한 고객 데이터를 보호하기 위해 다양한 취약점 및 해킹 대응책을 시행하고 있습니다.

취약점 대응
시스템의 안전성을 확인하기 위해 정기적으로 취약점 테스트를 실시합니다. 또한 시스템을 24시간 365일 상시 모니터링하며, 디스크 사용량, 메모리, CPU 등의 가동 상태를 지속적으로 확인해 이상을 감지할 수 있는 체계를 갖추고 있습니다.

해킹 대응
당사는 무단 접근 및 기타 보안 위협으로부터 시스템을 보호하기 위해 방화벽을 설치하고 있습니다.
Yaraku 번역은 SQL 인젝션, 크로스 사이트 스크립팅, OS 커맨드 인젝션, HTTP 헤더 인젝션, 세션 관리 미비 등으로 인한 서버 및 데이터베이스 해킹 위험을 방지하기 위해 다양한 대책을 마련하고 있습니다.
Yaraku 번역의 인프라
Yaraku 번역은 엄격한 보안 요건을 충족하는 AWS 인프라에서 운영됩니다.

데이터 센터
Yaraku 번역은 Amazon Web Services(AWS)의 데이터 센터를 이용합니다. AWS 서버는 독립적인 전원, 냉방 및 네트워크 환경을 갖춘 여러 데이터 센터에 분산 배치되어 있습니다. 특정 데이터 센터에서 장애가 발생하면 다른 데이터 센터에서 운영 중인 서버로 자동 전환되어 서비스 운영을 지속합니다.
AWS 데이터 센터에는 고유한 사이트 보안, 재해 대책 및 리스크 관리가 적용되어 있습니다. Amazon Web Services에 대한 자세한 내용은 AWS 보안 센터 및 AWS 데이터 센터 컨트롤 페이지를 참조하십시오.
보안 정책에 유연하게 대응하는 다양한 옵션
Yaraku 번역을 안심하고 도입할 수 있도록 다양한 옵션을 제공합니다.

보안 옵션
- SSO: SAML(Security Assertion Markup Language) 인증을 통한 싱글 사인온을 지원합니다. Microsoft ADFS 및 Google Workspace 등의 ID 공급자와도 연동할 수 있습니다.
- IP 주소 제한: Yaraku 번역에 대한 접근을 지정한 IP 주소로 제한합니다.
- 비밀번호 강화 설정: 비밀번호 정기 변경, 대문자·소문자·숫자 사용, 비밀번호 길이 등의 규칙을 설정할 수 있습니다.
- 문서 자동 삭제: 기밀성이 높은 번역 문서를 설정한 기간 후 자동으로 삭제합니다.
- 서버 옵션: 고객의 보안 요구사항에 맞게 프라이빗 클라우드(VPC)를 통한 도입이 가능합니다. 자세한 내용은 문의 페이지를 통해 연락해 주세요.

연동 파트너
소니 네트워크 커뮤니케이션즈 주식회사는 인터넷 서비스 제공업체로서 쌓아 온 기술력과 노하우를 활용해 Yaraku 번역을 견고하고 안전하게 도입할 수 있도록 지원합니다.
각종 보안 대책, 서버 설정 등의 연동 서비스에 더해 고객의 다양한 요건에 맞춘 유지보수 및 운영도 지원합니다.
Information Security Policy
Basic Philosophy
Yaraku, Inc. (hereinafter referred to as “the company”) conducts business based on the philosophy of “enjoying global communication”.
The Information assets handled by the company, such as customer information, are extremely important to us as the foundation of our business.
To guard against the risk of leakage, damage, loss, etc., we recognize the importance of protecting information assests and all personnel who handle information assests, including officers of the company and any personnel responsible for information protection, must comply with the following policy to maintain the confidentiality, integrity, availability, and other aspects of information security of information assets.
Basic Policy
- In order to protect information assets, we will formulate an information security policy and related regulations; and conduct business in accordance with this policy, as well as comply with legislaion, regulations, and other norms related to information security, as well as contractually-agreed terms with customers.
- We will determine the criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets, establish systematic risk assessment methods, and carry out risk assessments on a regular basis. Based on the results, we will implement necessary and appropriate security measures.
- We will establish an information security system centered on the officer in charge and clarify authority and responsibility for information security. In addition, all employees will be made aware of the importance of information security with regular education, training and development provided to ensure the proper handling of information assets.
- We will regularly inspect and audit the status of compliance with the information security policy and the handling of information assets, and promptly take corrective action for any deficiencies that are discovered or make improvements based on the inspection.
- In addition to taking appropriate measures against the occurrence of information security events and incidents, we will establish response procedures and protocols in advance such that in the unlikely event that an incident occurs, the damage will be minimized and all appropriate parties are notified as we respond and take appropriate corrective action. In addition, particularly for incidents related to business or service interruption, we will ensure business continuity by establishing a management framework and periodically reviewing it.
- We will establish and implement an information security management system with goals to realize our basic philosophy, while continuously reviewing and improving it.
Established September 30, 2022Yaraku Inc.Chief Executive Officer: Sakanishi Suguru