infomart

Security Supporting Business Continuity

Robust Infrastructure and Security as a Platform Company Supporting Economic Activity

As many commercial transactions move to the digital realm, we believe that the stable, continuous operation of our platform is directly linked to the sustainability of economic activity. In the face of various risks—such as increasingly sophisticated cyberattacks and large-scale natural disasters—we maintain a robust security framework with our top priority being "never stopping our clients' business" (maintaining availability). Furthermore, we will continue to invest in security and strengthen our countermeasures to keep pace with evolving external threats and new technological trends.

1.Disaster and System Failure Countermeasures

As an infrastructure supporting commercial transactions for over one million companies, we have built a multi-layered backup environment to ensure service continuity, even in the event of system failures or large-scale disasters. In addition to our primary operating environment, we maintain a robust system configuration that combines a "Standby Environment," a "DR (Disaster Recovery) Site," and an independent "Emergency Environment."

System Configuration

For our BtoB Platform services, we maintain a robust system architecture designed for system failures and disasters.In addition to our primary operating environment, we have established a "Standby Environment" and a "DR Site," both of which synchronize data in real time. Therefore, even if a failure occurs in the primary environment, users can continue using our services by switching over to these backup environments.

Furthermore, for BtoB Platform Ordering, we have an independent "Emergency Environment" dedicated exclusively to failure mitigation, ensuring that ordering and order-receiving operations can continue even if all the above environments become inoperable. We are currently considering implementing a similar environment for BtoB Platform Invoicing as well. Additionally, we conduct regular system failure drills to prepare for unexpected events.

1. Primary Operating Environment
Also referred to as the primary environment, this is the environment clients use on a daily basis.
All network equipment, servers, applications, and communication lines are designed with a redundant (dual) configuration. This ensures that system operations can continue even if a failure occurs in some equipment.
2. Standby Environment
Environment synchronizes data in preparation for failures in the primary operating environment.
Even if multiple devices fail at the same time, making it difficult to rely on the redundant configuration, the system is designed to maintain services by switching over to the Standby Environment.
3. DR Site (Remote Location)
Environment set up in a remote location that synchronizes data in preparation for large-scale disasters.
Even in the event of a major disaster such as a large earthquake, services can be continued by switching over to this remote disaster recovery environment.
4. Emergency Environment
An independent environment designed exclusively for failure countermeasures in the event that all other environments become unavailable.
Activated when a failure occurs that prevents the primary operating and Standby Environments from operating, and switching over to the DR Site is also impossible.
Supports only BtoB Platform Ordering, and synchronizes only partner and product information daily, maintaining a system where ordering and order-receiving operations can be continued. As an independent environment, transaction (slip) data generated here will not be synchronized back to the primary operating environment.

2.External and Internal Access Controls (Protection of Systems and Data)

To securely protect commercial transaction data across a vast number of companies, we have implemented an integrated security framework that combines "multi-layered defense" to prevent external cyberattacks with "strict access management" to mitigate internal risks.

As an infrastructure company, we comprehensively and rigorously enforce essential security measures, including detecting and blocking unauthorized intrusion via "multi-layered network security" optimized for cloud environments, encrypting transmitted and stored data, conducting regular vulnerability assessments by external entities, and restricting access rights to production environments.

3.Incident Response Framework and Drills Centered on the CSIRT

We have established a response framework centered on our CSIRT (Computer Security Incident Response Team) to ensure prompt and effective responses in the event of a security incident. In an emergency, under this structure, we execute a comprehensive process—from collaboration and information sharing with relevant departments to root-cause analysis and recurrence prevention, striving to ensure business continuity.

In addition to preventive measures based on past incidents, we participate as a member in annual exercises hosted by the Nippon CSIRT Association (NCA). By conducting incident response drills using scenarios that reflect the latest threats, we continually work to enhance our practical response capabilities for emergencies.

4.External Certifications and Memberships

We undergo rigorous audits by independent third-party expert organizations and have obtained numerous major security certifications to ensure that our clients can use our services with peace of mind. Furthermore, by joining and collaborating with major security organizations, we quickly capture the latest cyber threat information to continuously update our defense architecture.

Acquisition of Security Standards and Certifications

  • Government-approved cloud security standard "ISMAP"※1

  • International security standards "ISMS (ISO 27001)" and "ISMS Cloud Security (ISO 27017)"※2

  • Public certification "ASP/SaaS Safety and Reliability Information Disclosure Certification System" that meets government safety standards

※1 ISMAP registration applies to 4 services: BtoB Platform TRADE, Invoices, Contracts, and BP Workflow.

※2 The scope of ISMS certification covers 15 services: BtoB Platform Ordering, Ordering Lite, Database, Matching, TRADE, Invoices, Industry Channels, Estimates, Contracts, Ordering for Manufacturing, BtoB eSmart, V-Manage, BP Workflow, Early Payment of Electronic Invoices, and Credit Settlement.

Implementation of Internal Control Evaluations

  • Received "SOC 2" report evaluating internal controls by an independent auditor

Updating and sharing knowledge through memberships in industry organizations

  • Membership in the "Nippon CSIRT Association (NCA)," a collaborative community linking incident response organizations

  • Membership in the "Japan Cloud Industry Association (ASPIC)," an organization specializing in security and cloud services