Composite Tailors Co., Ltd. (hereinafter "we," "us," or "the Company") positions the reliable protection of its information assets—including the design drawings and technical information entrusted to us by our customers—from various threats such as unauthorized access, leakage, and falsification as an important management priority. Based on this basic policy, we develop and operate an information security framework and rules that respond to the demands of society and changes in the technological environment, and we ensure that these are thoroughly observed by all officers and employees as well as related parties, including contractors.
1. Basic Approach
The Company recognizes that the appropriate protection of information assets is the foundation for living up to the trust of our customers and society and for continuously growing our business. Based on this recognition, we develop an information security framework from organizational, personnel, physical, and technical perspectives, and all officers and employees work together to ensure information security.
2. Information Security Basic Policy
Compliance with laws and standards and proper management
In handling all information assets, we comply with relevant laws and regulations, standards (such as guidelines), contractual matters agreed with customers, internal regulations, and the like, and we promote their proper use and management.
Confidentiality management of technical information, drawings, etc.
We appropriately protect confidential information entrusted to us by customers—such as design drawings, technical data, specifications, and prototypes—according to its level of importance. We limit those who can access it to the necessary scope, and we never use, reproduce, or provide it beyond the prescribed purposes.
Compliance with security export control
Based on the Foreign Exchange and Foreign Trade Act (the "Foreign Exchange Act") and other relevant laws and regulations, we appropriately manage goods and technologies that may be subject to regulation. We comply with export control procedures so as not to provide regulated technologies to foreign parties without authorization.
Establishment and thorough dissemination of the management framework
We appoint a manager responsible for information security and, through education and awareness-raising for all officers and employees as well as related parties including contractors, ensure thorough awareness of information security management.
Reasonable security measures for information assets
For the information assets we manage, we take reasonable security measures to prevent unauthorized access, loss, destruction, falsification, leakage, and the like, and we carry out corrective and preventive actions as appropriate.
Prompt response to incidents
In the event of an information security incident, we promptly report it to the person responsible for information security operations and respond to it, striving to prevent the spread of damage and to achieve early recovery.
Continuous improvement
Taking into account changes in the external environment, such as information technology and social trends, as well as changes in the internal environment, such as organizational changes, we continuously review and improve our information security framework, rules, and their operation.
Response to violations
In the event of any act that violates relevant laws and regulations, standards, contractual matters, internal regulations, or the like, we will deal with it in accordance with the provisions set forth in our work rules.
3. Information Security Management Structure
The Company designates its President as the chief officer responsible for information security and, under the President, appoints a person responsible for information security operations to oversee the development, operation, and improvement of internal information security measures. The person in charge in each department and all employees handle information assets in accordance with the established policies and rules, and promptly report any incident they discover to the manager responsible.
Effective: April 1, 2025
Composite Tailors Co., Ltd.
Kengo Yasuhira, President