Information Security Policy

Last updated: 9 September 2026

Our clients trust us with their systems, their documents and their institutional knowledge. Protecting that information is a condition of doing business, not an add-on to it.

This policy sets out how eBase Solutions, Inc. and the eBase Solutions Group approach information security across our own operations and the services we deliver.

Our commitment

The eBase Solutions Group is committed to protecting the confidentiality, integrity and availability of all information assets we own or are entrusted with — our clients’ information, our employees’ personal information, and our own business and technical information.

Management establishes, maintains and continually improves an information security management framework, allocates the resources needed to operate it, and reviews it regularly.

Scope

This policy applies to all directors, officers, employees, contractors and temporary staff of eBase Solutions, Inc. and its affiliated companies, and to all information assets we handle — whether in electronic, printed or spoken form, and whether held on our systems, on client systems, or with our service providers.

Principles

Compliance. We comply with applicable laws, regulations, standards and contractual obligations relating to information security in every jurisdiction where we operate, including the United States and Japan.

Risk management. We identify and assess risks to information assets, and apply controls proportionate to the value of the asset and the severity of the risk. Assessments are reviewed regularly and whenever significant change occurs.

Least privilege. Access to information and systems is granted on the basis of business need, is authorised, is reviewed periodically, and is revoked promptly when no longer required.

Client separation. Client environments and client data are logically separated. Information provided by one client is never used for the benefit of another, and is never used to train publicly available AI models.

People. All personnel receive information security training on joining and at regular intervals, are bound by confidentiality obligations, and are responsible for security within their role. Breaches of this policy are handled under our disciplinary procedures.

Suppliers. Third parties who handle information on our behalf are assessed before engagement and are bound by written security and confidentiality terms.

Technical and organisational measures

  • Encryption of data in transit and, where appropriate, at rest
  • Network security controls including firewalls, segmentation and monitoring
  • Identity and access management with authenticated, individually attributable accounts
  • Logging and review of access to sensitive systems and data
  • Vulnerability management, patching and change control
  • Backup, restoration testing and disaster-recovery planning
  • Physical security controls at our offices and facilities
  • Secure disposal of media and documents at end of life

Incident response

We maintain procedures for reporting, assessing, containing and resolving information security incidents. All personnel are required to report suspected incidents promptly. Where an incident affects client data or personal information, we notify affected parties and regulators as required by contract and applicable law, and we conduct a review to prevent recurrence.

Business continuity

We plan for the continuity of services our clients depend on, including 24×7 monitoring and support arrangements, documented recovery procedures, and periodic testing.

Certification

Our Japanese affiliates, eBase Solutions KK and eBase Solutions Laboratory, hold PrivacyMark (プライバシーマーカ) certification, Japan’s standard for the protection of personal information, and are subject to its periodic external audits.

Review

This policy is reviewed at least annually and whenever there is a significant change to our business, our technology or the legal environment in which we operate.

Contact

Security questions, vulnerability reports and requests for further detail can be sent to:

eBase Solutions, Inc.
Attn: Information Security
6754 Bernal Avenue, Ste 740110
Pleasanton, CA 94566, USA
info@ebase-solutions.com

Draft for review. This policy is a working template describing intended practice. It should be verified against our actual controls and reconciled with the Japanese group’s 情報セキュリティ方針 before publication on the live site.