Information Security Policy

Basic Philosophy

In the course of the business operations of Torifa Inc. (hereinafter referred to as “the Company”), the information assets we handle—including our customers’ information—are extremely important as the foundation of our corporate management.

All individuals who handle information assets, including officers and employees who recognize the importance of protecting information assets from risks such as leakage, damage, and loss, shall comply with this policy and engage in activities to maintain information security in terms of confidentiality, integrity, and availability.


Basic Policy

To protect our information assets, we will establish an information security policy and related regulations, conduct business in accordance with them, and comply with laws, regulations, and other standards related to information security, as well as contractual obligations with our customers.

We will clarify criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets and establish a systematic risk assessment method. We will conduct regular risk assessments and implement necessary and appropriate security measures based on the results.

We will establish an information security management structure centered on the responsible executive and clearly define the authorities and responsibilities related to information security. In addition, we will regularly provide education, training, and awareness programs to ensure that all personnel recognize the importance of information security and handle information assets appropriately.

We will regularly inspect and audit compliance with the information security policy and the handling of information assets. Any deficiencies or areas for improvement identified during these processes will be promptly corrected.

We will implement appropriate measures to address information security events and incidents. In the event such incidents occur, we will establish response procedures in advance to minimize potential damage, respond promptly, and take appropriate corrective actions. For incidents that may disrupt business operations in particular, we will establish a management framework and conduct periodic reviews to ensure business continuity.

We will establish an Information Security Management System (ISMS) with goals designed to realize our basic philosophy, implement it, and continuously review and improve it.


Enacted on November 12, 2025
Torifa Inc.
Representative Director, Masatoshi Kana

Basic Philosophy

In the course of the business operations of Torifa Inc. (hereinafter referred to as “the Company”), the information assets we handle—including our customers’ information—are extremely important as the foundation of our corporate management.

All individuals who handle information assets, including officers and employees who recognize the importance of protecting information assets from risks such as leakage, damage, and loss, shall comply with this policy and engage in activities to maintain information security in terms of confidentiality, integrity, and availability.


Basic Policy

To protect our information assets, we will establish an information security policy and related regulations, conduct business in accordance with them, and comply with laws, regulations, and other standards related to information security, as well as contractual obligations with our customers.

We will clarify criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets and establish a systematic risk assessment method. We will conduct regular risk assessments and implement necessary and appropriate security measures based on the results.

We will establish an information security management structure centered on the responsible executive and clearly define the authorities and responsibilities related to information security. In addition, we will regularly provide education, training, and awareness programs to ensure that all personnel recognize the importance of information security and handle information assets appropriately.

We will regularly inspect and audit compliance with the information security policy and the handling of information assets. Any deficiencies or areas for improvement identified during these processes will be promptly corrected.

We will implement appropriate measures to address information security events and incidents. In the event such incidents occur, we will establish response procedures in advance to minimize potential damage, respond promptly, and take appropriate corrective actions. For incidents that may disrupt business operations in particular, we will establish a management framework and conduct periodic reviews to ensure business continuity.

We will establish an Information Security Management System (ISMS) with goals designed to realize our basic philosophy, implement it, and continuously review and improve it.


Enacted on November 12, 2025
Torifa Inc.
Representative Director, Masatoshi Kana

Basic Philosophy

In the course of the business operations of Torifa Inc. (hereinafter referred to as “the Company”), the information assets we handle—including our customers’ information—are extremely important as the foundation of our corporate management.

All individuals who handle information assets, including officers and employees who recognize the importance of protecting information assets from risks such as leakage, damage, and loss, shall comply with this policy and engage in activities to maintain information security in terms of confidentiality, integrity, and availability.


Basic Policy

To protect our information assets, we will establish an information security policy and related regulations, conduct business in accordance with them, and comply with laws, regulations, and other standards related to information security, as well as contractual obligations with our customers.

We will clarify criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets and establish a systematic risk assessment method. We will conduct regular risk assessments and implement necessary and appropriate security measures based on the results.

We will establish an information security management structure centered on the responsible executive and clearly define the authorities and responsibilities related to information security. In addition, we will regularly provide education, training, and awareness programs to ensure that all personnel recognize the importance of information security and handle information assets appropriately.

We will regularly inspect and audit compliance with the information security policy and the handling of information assets. Any deficiencies or areas for improvement identified during these processes will be promptly corrected.

We will implement appropriate measures to address information security events and incidents. In the event such incidents occur, we will establish response procedures in advance to minimize potential damage, respond promptly, and take appropriate corrective actions. For incidents that may disrupt business operations in particular, we will establish a management framework and conduct periodic reviews to ensure business continuity.

We will establish an Information Security Management System (ISMS) with goals designed to realize our basic philosophy, implement it, and continuously review and improve it.


Enacted on November 12, 2025
Torifa Inc.
Representative Director, Masatoshi Kana

4F NT Building Gotanda, 1-18-9

Nishi-Gotanda, Shinagawa-ku, Tokyo

4F NT Building Gotanda, 1-18-9

Nishi-Gotanda, Shinagawa-ku, Tokyo

(

JA

|

EN

)

4F NT Building Gotanda, 1-18-9

Nishi-Gotanda, Shinagawa-ku, Tokyo