首頁安全性政策

安全性政策

Yaraku翻譯的資安防護機制

為了讓您在商務情境中也能安心使用,Yaraku翻譯建立了完善的資訊管理體制,並始終審慎地營運服務。

資安特色

  • 客戶資料獨立管理
  • 資料加密
  • 資料持續備份
  • 24/7系統監控
  • 弱點與駭客攻擊防護
  • SSO(Single Sign-On)
  • 私有雲部署

合規計畫

Yaraku翻譯已取得以下認證。

ISMS(ISO/IEC 27001:2022)認證

八樂株式會社東京總部於2022/12/22取得資訊安全管理系統(ISMS)國際標準ISO/IEC 27001:2022與JIS Q 27001:2023認證。

【認證登錄概要】 登錄組織:八樂株式會社 認證登錄範圍:多語言溝通工具的企劃、開發及相關服務的提供 認證標準:ISO/IEC 27001:2022、JIS Q 27001:2023 證書編號:IS778669 認證登錄日期:2022/12/22 最新更新日期:2025/02/04

Yaraku翻譯的資料管理

Yaraku翻譯會妥善管理所儲存的資料,以確保客戶隱私受到保護。

資料庫

在Yaraku翻譯中,每位客戶的翻譯資料皆會分別管理,因此第三方無法存取或修改資料庫。八樂株式會社僅允許獲得授權的員工存取資料庫,且只能用於系統維護或疑難排解。

除取得客戶同意或依法令要求等特定情況外,我們不會揭露資料。

資料庫中的資料會持續備份。如因人為錯誤導致資料遺失,可使用最近14天內保留的備份還原系統中的資料。

加密

Yaraku翻譯使用SSL(*)加密所有通訊資料,防止第三方查看或竄改內容。此外,密碼等高度機密的資料也會在資料庫中加密。

*SSL是Secure Sockets Layer的縮寫,是一種廣泛用於線上付款網頁等情境的機制,可加密通訊內容,防止竊聽與竄改。

我們會執行各種弱點與防駭對策以保護重要的客戶資料。

為了保護客戶的重要資料,我們採取多項弱點與駭客攻擊防護措施。

弱點防護

為確認系統安全性,我們會定期進行弱點測試。我們也會全天候(24/7)監控系統,持續追蹤磁碟使用量、記憶體、CPU等運作狀態,以便偵測異常。

駭客攻擊防護

我們的系統設有防火牆,以防範未授權存取及其他資安威脅。

Yaraku翻譯針對SQL注入、跨網站指令碼攻擊、OS命令注入、HTTP標頭注入、工作階段管理不當等問題,採取多項措施,以降低伺服器和資料庫遭受駭客攻擊的風險。

Yaraku翻譯的基礎架構

Yaraku翻譯運作於符合嚴格資安要求的AWS基礎架構上。

資料中心

AWS資料中心擁有獨特的網站安全性、防災對策與風險管理。 關於Amazon Web服務的詳情,請參考AWS安全中心AWS安全中心的控管措施頁面。

AWS資料中心實施實體安全措施、防災措施及風險管理。有關AWS資安的詳細資訊,請參閱AWS Security CenterAWS Data Center Controls頁面。

彈性因應安全性政策的多種選項

我們提供多種選項,協助您安心導入Yaraku翻譯。

  • 資安選項
  • SSO:支援以SAML(Security Assertion Markup Language)認證進行單一登入,也可與Microsoft ADFS、Google Workspace等身分識別提供者整合。
  • 限制IP位址:僅允許從指定的IP位址存取Yaraku翻譯。
  • 設定高強度密碼:可設定定期變更密碼、使用大小寫字母和數字、密碼長度等規則。
  • 伺服器選項: 我們也可配合客戶的安全性需求,在私人雲端(VPC)導入服務。詳細內容,請透過聯絡洽詢頁面與我們聯繫。

整合合作夥伴

Sony Network Communications Inc.運用其作為網際網路服務供應商所累積的技術能力與專業知識,協助穩健且安全地部署Yaraku翻譯。

除各項資安措施、伺服器設定等整合服務外,也可依客戶的不同需求提供維護與營運支援。 詳細內容請參考Sony Network Communications自動翻譯Yaraku Translate導入支援頁面

Information Security Policy

Basic Philosophy


Yaraku, Inc. (hereinafter referred to as “the company”) conducts business based on the philosophy of “enjoying global communication”.The Information assets handled by the company, such as customer information, are extremely important to us as the foundation of our business.To guard against the risk of leakage, damage, loss, etc., we recognize the importance of protecting information assests and all personnel who handle information assests, including officers of the company and any personnel responsible for information protection, must comply with the following policy to maintain the confidentiality, integrity, availability, and other aspects of information security of information assets.

Basic Policy

  1. In order to protect information assets, we will formulate an information security policy and related regulations; and conduct business in accordance with this policy, as well as comply with legislaion, regulations, and other norms related to information security, as well as contractually-agreed terms with customers.
  2. We will determine the criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets, establish systematic risk assessment methods, and carry out risk assessments on a regular basis. Based on the results, we will implement necessary and appropriate security measures.
  3. We will establish an information security system centered on the officer in charge and clarify authority and responsibility for information security. In addition, all employees will be made aware of the importance of information security with regular education, training and development provided to ensure the proper handling of information assets.
  4. We will regularly inspect and audit the status of compliance with the information security policy and the handling of information assets, and promptly take corrective action for any deficiencies that are discovered or make improvements based on the inspection.
  5. In addition to taking appropriate measures against the occurrence of information security events and incidents, we will establish response procedures and protocols in advance such that in the unlikely event that an incident occurs, the damage will be minimized and all appropriate parties are notified as we respond and take appropriate corrective action. In addition, particularly for incidents related to business or service interruption, we will ensure business continuity by establishing a management framework and periodically reviewing it.
  6. We will establish and implement an information security management system with goals to realize our basic philosophy, while continuously reviewing and improving it.

Established September 30, 2022

Yaraku Inc.

Chief Executive Officer: Sakanishi Suguru