Information Security Policy
Last revised: 2026-06-23
AIRI (the “Service”) regards the protection of information belonging to our customers and handled through calls as a key responsibility, and works to ensure information security in line with the following basic policy.
This is a reference translation provided for convenience. If there is any discrepancy, the Japanese version prevails.
This page is under preparation. Its contents (in particular, business operator information and the particulars of each article) will be updated once confirmed through legal review.
1. Basic policy
To protect the information assets handled by the Service from leakage, falsification, loss, and other risks, we implement organizational, personnel, physical, and technical safeguards. We comply with applicable laws and our contractual obligations to customers, and strive to maintain and improve security at the level society expects.
2. Governance
- We appoint a person responsible for information security, who establishes, operates, and reviews this policy.
- We provide ongoing education and awareness activities for our employees on the proper handling of information.
- We define handling rules according to the sensitivity of each information asset and operate in accordance with them.
3. Access control and encryption
- Access to information is granted only to the minimum extent required for business purposes and is reviewed periodically (principle of least privilege).
- We implement technical measures to protect information in storage and in transit, such as encryption of communication channels.
- We take measures to prevent and detect unauthorized access, and appropriately manage records of operations.
Details of the categories and handling of personal information processed through calls are set out in the Privacy Policy.
4. Vendor management
The Service relies on external services for its delivery (voice AI processing, telephony and communications infrastructure, cloud providers, and the like). When selecting a vendor, we confirm that safeguards meeting the standards we require are in place, and we exercise necessary and appropriate supervision through contracts and other means. The specifics of external transmission and outsourcing are described in Section 4 of the Privacy Policy (External transmission, outsourcing, and provision to third parties).
5. Incident response
We maintain response procedures for identifying impact, preventing spread, recovering, and preventing recurrence in the event of an information security incident or a suspected incident. If customers may be affected, we will promptly notify them and make any required reports in accordance with our contracts and applicable laws.
6. Continuous improvement
We periodically review and continuously improve this policy and the related controls in light of changes in the information security landscape, changes to the Service, and amendments to laws and regulations.