Information Security Policy

Effective date: August 18, 2026

This English version is provided for reference only. The Japanese version is the official text, and it shall prevail in the event of any discrepancy between the two.

The Company establishes the following basic policy on information security in order to appropriately protect the information of customers who use the Service.

1. Basic Policy

GreatHack, Inc. (the "Company") recognizes that the information entrusted to us is highly sensitive, given that "Shinome" (the "Service") supports the activities of politicians and political organizations. The Company positions the appropriate protection of information assets as a key management priority, and establishes and adheres to this Policy.

2. Scope

This Policy applies to all information assets involved in providing the Service — information entrusted to us by customers, information held by the Company, and the equipment, systems, and storage media that handle such information — and to the Company's officers and everyone engaged in its operations.

3. Compliance with Laws and Other Standards

The Company complies with laws and regulations concerning information security, government guidelines, and its contractual obligations to customers. In particular, the handling of personal information follows the Act on the Protection of Personal Information and the Company's Privacy Policy.

4. Management Structure

The Company appoints a person responsible for information security and maintains a structure accountable for managing information assets, assessing risks, and implementing necessary measures.

5. Technical Security Measures

The Company implements the following technical measures in the Service.

  • Tenant separation: data is logically separated for each office (tenant) so that data from other offices cannot be accessed or intermixed.
  • Encryption of credentials: credentials used for social media integration and similar purposes are encrypted with AES-256-GCM before storage.
  • Password protection: passwords are not stored in plain text; they are hashed with PBKDF2-SHA256.
  • Encryption in transit: all communications between Users and the Service are encrypted with TLS.
  • Access control: administrative functions are limited to authorized personnel of the Company, and general Users cannot even see that those functions exist.

6. Organizational and Personnel Security Measures

The Company limits access rights to information assets to the minimum necessary for business purposes, and promptly revokes those rights upon resignation or termination of a contract. The Company also provides necessary information security awareness to everyone engaged in its operations.

7. Management of Subcontractors

When subcontracting part of its operations, the Company confirms the subcontractor's information security standards in advance, requires confidentiality and appropriate handling of information in the contract, and exercises necessary supervision.

8. Incident Response

If the Company becomes aware of an information security incident or the risk of one, it will promptly work to prevent the damage from spreading and to determine the cause, and will report to affected customers and to relevant authorities in accordance with laws and contractual obligations. The Company will also take the measures necessary to prevent recurrence.

9. Business Continuity

The Company maintains means of preserving and restoring data in preparation for a suspension of the Service due to failures or similar events.

10. Continuous Improvement

The Company periodically reviews and continuously improves this Policy and the measures it implements, in response to changes in the content of the Service, technological change, and the emergence of new threats.

11. Contact Point

For inquiries about this Policy, please contact: s.tanaka@great-hack.com

End of document