Policies
Information Security Policy
Established May 2, 2024 / Last revised April 1, 2026
1. Purpose
As a provider of compute infrastructure and AI services, Yolaiz Inc. ("the Company") regards the protection of the information assets entrusted to it by clients as a precondition of continuing in business. This policy sets out the basis of the Company's information security practice.
2. Scope
This policy applies to all officers and employees of the Company and to contractors performing work on its behalf. Covered information assets include client data entrusted to the Company, the compute platforms the Company builds and operates, and the Company's own systems and deliverables.
3. Governance
The Representative Director holds ultimate responsibility, and an Information Security Manager is appointed. The Manager is responsible for maintaining internal rules, conducting risk assessment and directing incident response.
4. Commitments
· We comply with applicable laws, standards and contractual obligations relating to information security.
· We assess risks to information assets periodically and apply controls proportionate to business impact.
· Access rights are granted at the minimum necessary for the work and reviewed periodically.
· All operations and configuration changes are recorded and remain traceable.
5. Handling of client data
· Client data is not used for any purpose beyond that stated in the contract.
· Client data is never used to train models, whether the Company's or a third party's.
· Storage location, retention period and deletion procedure are stated at the time of contracting.
· The scope and retention of inference input and output logs are set by agreement with the client.
6. Platform operations
· Tenant isolation is a design requirement, and dedicated configurations are offered.
· Infrastructure-as-code contains no credentials; references are made through a secrets manager.
· Automated scanning for confidential information is performed before delivery and periodically thereafter.
7. Incident response
On becoming aware of an information security event, the Company follows predefined procedures to identify scope, contain the event, report to affected clients and relevant authorities, and implement preventive measures without delay.
8. Training
All officers and employees receive information security training on joining and annually thereafter.
9. Continuous improvement
This policy and its supporting rules are reviewed periodically in light of changes in the business environment and in technology, and improved continuously.
Yolaiz Inc.