首页安全性政策

安全性政策

Yaraku翻译的安全体系

为了让您在业务场景中也能安心使用,Yaraku翻译建立了完善的信息管理体系,并始终审慎地运营服务。

安全特性

  • 按客户独立管理数据
  • 数据加密
  • 数据持续备份
  • 24/7系统监控
  • 漏洞与黑客攻击防护
  • SSO(Single Sign-On)
  • 私有云部署

合规计划

Yaraku翻译已获得以下认证。


ISMS(ISO/IEC 27001:2022)认证

八乐株式会社东京总部于2022年12月22日获得了信息安全管理体系(ISMS)国际标准ISO/IEC 27001:2022和JIS Q 27001:2023认证。

【认证注册概况】 注册组织:八乐株式会社 认证注册范围:多语言沟通工具的策划与开发,以及相关服务的提供 认证标准:ISO/IEC 27001:2022、JIS Q 27001:2023 证书编号:IS778669 认证注册日期:2022年12月22日 最新更新日期:2025年2月4日

Yaraku翻译的数据管理

Yaraku翻译对所存储的数据进行管理,以确保客户隐私得到妥善保护。

数据库

在Yaraku翻译中,每位客户的翻译数据均单独管理,因此第三方无法访问或修改数据库。八乐株式会社仅允许获得授权的员工访问数据库,且只能用于系统维护或故障排查。

除获得客户同意或法律法规要求等特定情况外,我们不会披露数据。

数据库中的数据会持续备份。如因人为错误导致数据丢失,可使用最近14天内保留的备份恢复系统中的数据。

加密

Yaraku翻译使用SSL(*)对所有通信数据进行加密,从而防止第三方查看或篡改内容。此外,密码等高度机密的数据也会在数据库中加密。

*SSL是Secure Sockets Layer的缩写,是一种广泛用于在线支付网页等场景的机制,可加密通信内容,防止窃听和篡改。

弱点与防骇对策

为了保护客户的重要数据,我们采取了多项漏洞与黑客攻击防护措施。

漏洞防护

为确认系统的安全性,我们会定期进行漏洞测试。我们还对系统进行全天候(24/7)监控,持续跟踪磁盘使用量、内存、CPU等运行状态,以便检测异常。

黑客攻击防护

我们的系统部署了防火墙,以防止未授权访问和其他安全威胁。

Yaraku翻译针对SQL注入、跨站脚本、OS命令注入、HTTP头注入、会话管理不当等问题,采取了多项措施,以降低服务器和数据库遭受黑客攻击的风险。

Yaraku翻译的基础设施

Yaraku翻译运行在满足严格安全要求的AWS基础设施上。

数据中心

Yaraku翻译使用Amazon Web Services(AWS)的数据中心。AWS服务器分布在多个数据中心,每个数据中心都配备独立的电源、空调和网络环境。如果某个数据中心发生故障,服务会自动切换到在其他数据中心运行的服务器,以持续提供服务。

AWS数据中心拥有独特的网站安全性、防灾对策与风险管理。 关于Amazon Web服务的详情,请参考AWS安全中心AWS安全中心的控管措施页面。

灵活适配安全性政策的多种选项

我们提供多种选项,帮助您放心采用Yaraku翻译。

安全选项

  • SSO:支持基于SAML(Security Assertion Markup Language)认证的单点登录,也可与Microsoft ADFS、Google Workspace等身份提供商集成。
  • IP地址限制:仅允许从指定的IP地址访问Yaraku翻译。
  • 密码强化设置:可设置定期更改密码、使用大小写字母和数字、密码长度等规则。
  • 文档自动删除:在设定期限后自动删除机密性较高的翻译文档。
  • 服务器选项: 我们也可配合客户的安全性需求,在私人云端(VPC)导入服务。详细内容,请透过联络洽询页面与我们联系。

集成合作伙伴

Sony Network Communications Inc.充分利用其作为互联网服务提供商积累的技术能力和专业经验,为稳健、安全地部署Yaraku翻译提供支持。

我们透过各种安全性对策,提供服务器设定等整合服务,以及符合客户各种需求的维护与运用服务。 详细内容请参考Sony Network Communications自动翻译Yaraku Translate导入支持页面

Information Security Policy

Basic Philosophy

Yaraku, Inc. (hereinafter referred to as “the company”) conducts business based on the philosophy of “enjoying global communication”.
The Information assets handled by the company, such as customer information, are extremely important to us as the foundation of our business.
To guard against the risk of leakage, damage, loss, etc., we recognize the importance of protecting information assests and all personnel who handle information assests, including officers of the company and any personnel responsible for information protection, must comply with the following policy to maintain the confidentiality, integrity, availability, and other aspects of information security of information assets.


Basic Policy

  1. In order to protect information assets, we will formulate an information security policy and related regulations; and conduct business in accordance with this policy, as well as comply with legislaion, regulations, and other norms related to information security, as well as contractually-agreed terms with customers.
  2. We will determine the criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets, establish systematic risk assessment methods, and carry out risk assessments on a regular basis. Based on the results, we will implement necessary and appropriate security measures.
  3. We will establish an information security system centered on the officer in charge and clarify authority and responsibility for information security. In addition, all employees will be made aware of the importance of information security with regular education, training and development provided to ensure the proper handling of information assets.
  4. We will regularly inspect and audit the status of compliance with the information security policy and the handling of information assets, and promptly take corrective action for any deficiencies that are discovered or make improvements based on the inspection.
  5. In addition to taking appropriate measures against the occurrence of information security events and incidents, we will establish response procedures and protocols in advance such that in the unlikely event that an incident occurs, the damage will be minimized and all appropriate parties are notified as we respond and take appropriate corrective action. In addition, particularly for incidents related to business or service interruption, we will ensure business continuity by establishing a management framework and periodically reviewing it.
  6. We will establish and implement an information security management system with goals to realize our basic philosophy, while continuously reviewing and improving it.

Established September 30, 2022

Yaraku Inc.

Chief Executive Officer: Sakanishi Suguru