Security Policy
The following sets forth the Company's information security policy. Recho, Inc. (the "Company") handles information assets belonging to many stakeholders, including our customers, through business activities centered on the development of voice-AI agents. We recognize the protection of these information assets as part of our social responsibility as a corporation, and we are committed to appropriate management and operation of information. To fulfill this responsibility, we establish and operate an Information Security Management System ("ISMS") based on JIS Q 27001 (ISO/IEC 27001), and strive to maintain and improve information security through continual improvement.
1. Information security management structure
To manage information security appropriately, the Company appoints an ISMS Manager and establishes and maintains a management structure in cooperation with relevant departments. Through the formulation and review of information-security policies and rules, we realize organization-wide information security management.
2. Information security education
The Company regularly provides training and education so that all employees understand the importance of information security and can respond appropriately.
3. Compliance with laws and regulations
The Company complies with laws, regulations, guidelines, and contractual obligations related to information security.
4. Response to violations and incidents
If a violation or incident related to information security occurs, the Company will respond promptly, working to minimize damage, investigate causes, and prevent recurrence. Response procedures and reporting channels are clearly defined, and we coordinate swiftly with relevant parties.
5. Continual improvement
The Company periodically inspects and evaluates the operation of the ISMS, and reviews it as necessary, in order to continually raise the level of information security.
6. Responsibilities as a cloud service provider
As a cloud service provider, the Company conducts risk assessments that take into account risks specific to cloud services in order to appropriately protect the information entrusted to us, and builds mechanisms so that users can safely utilize our services.