Information Security Basic Policy

GotoAI Inc. (“GotoAI,” “we”) builds AI systems using our clients’ data, and we therefore regard protecting the information entrusted to us as one of our most important management responsibilities. Through this Basic Policy, we make our approach to information security clear both within and outside the Company, and we aim to earn the trust of our clients and stakeholders and to grow sustainably.

1. Purpose

This Basic Policy is established to:

  • Clarify our direction on information security — how we protect the information assets we handle from all threats and achieve appropriate safeguards;
  • Foster shared awareness — a common understanding of, and culture of respect for, information security;
  • Strengthen stakeholder trust — demonstrating our approach to clients and partners;
  • Ensure compliance — observing applicable laws, contracts, and standards as the foundation of organizational risk management.

2. Scope

This Basic Policy applies to the Representative Director and everyone who works on GotoAI’s behalf, and covers all information assets and information systems we handle, in every form — electronic, physical, spoken, and visual.

3. Responsibility and Commitment

GotoAI’s Representative Director holds ultimate responsibility for information security, sets and approves this Basic Policy and its objectives, commits the resources necessary to achieve them, and oversees our efforts. Everyone who works on GotoAI’s behalf complies with this Basic Policy.

4. Information Security Management Structure

We establish and maintain a management structure with clearly defined roles and responsibilities to advance information security.

5. Protection of Information Assets

We implement the security measures necessary to protect the confidentiality, integrity, and availability of the information assets we hold and manage. In particular, for information entrusted to us by clients and for personal data, we apply appropriate organizational, human, physical, and technical safeguards to prevent unauthorized access, leakage, alteration, destruction, and loss.

6. Compliance with Laws, Contracts, and Standards

We comply with the laws, regulations, and industry guidelines governing information security and the protection of personal data, and we faithfully observe our contractual security obligations and applicable social standards. Where a contract sets stricter requirements, those requirements prevail.

7. Responsible Use of AI Services and Privacy Protection

We do not use client data for our own purposes without the client’s permission. Please also see our Responsible AI Principles and Privacy Policy.

8. Incident Response

If an information security incident occurs, we respond promptly, notify affected clients and relevant parties appropriately, and work to correct the cause and prevent recurrence.

9. Continual Improvement

We periodically evaluate the effectiveness of our information security management and revise this Basic Policy and our measures as necessary.

10. Awareness and Compliance

This Basic Policy is approved by the Representative Director and communicated to everyone who works on GotoAI’s behalf to ensure compliance.

This Policy is originally written in Japanese. In the event of any discrepancy between the Japanese and English versions, the Japanese version shall prevail.

Effective date: 2026-08-24
GotoAI Inc.
Congwei Dang, Representative Director and CEO

Scroll to Top