Governance & Legal
Governance & Legal
Below is a summary of the applicable laws, regulations, and internal policies that govern our operations.
Payment Architecture and PCI-DSS Compliance
For payment processing in our services (such as HomeGrid VPN), we integrate with Stripe. We have architected our system so that highly sensitive payment information, including credit card numbers, never passes through or is stored on our own servers or databases. This ensures a secure payment environment that fully complies with PCI-DSS standards.
Log retention (Act on Prevention of Transfer of Criminal Proceeds)
In line with the Japanese Act on Prevention of Transfer of Criminal Proceeds and related guidance, identification and transaction-related logs are retained for at least three months, and longer where required.
Access logs, authentication logs, and configuration change logs are retained for periods aligned with applicable law and contractual requirements, in tamper-resistant storage.
Hardware procurement under Japanese regulation
Network and communications equipment provided in Japan is selected only from products carrying the Technical Conformity Mark (Giteki) under the Radio Act. Power supplies and electrical appliances are required to carry PSE certification under the Electrical Appliances and Materials Safety Act.
For imported equipment, compliance with Japanese regulations is verified in documentary form prior to deployment, and any product with unresolved compliance concerns is not adopted.