セキュリティと運営
誰が、どう守るのか。
このページで分かること
- サービスのセキュリティ実装(暗号化・監査・アクセス制御)
- リスク算定を支える学術的標準(ACRA / FAIR / Gordon-Loeb)
- 運営するサイバーセキュリティサービス専門企業の専門性
Security & TrustDecisions that drive the business —
Decisions that drive the business —
underwritten by implementation and academic grounding.
We publish the platform's own security implementation,
the academic basis of our risk analysis and economic models, and the company behind it.
Security implementation
- Multi-factor authentication
- Strong password policy
- Daily vulnerability scanning
- Browser-side security controls
- Per-feature rate limits
- Audit log retention & export
- Full data isolation across tenants
- Error monitoring
- Automated contract-expiry reminders
and more
Standards & academic basis
- FAIR (Factor Analysis of Information Risk)International standard for quantifying risk as a probability distribution (loss-distribution simulation)
- Gordon & Loeb (2002)The canonical optimal-investment model in information security economics
- MITRE ATT&CK / ATLASMapping to ATT&CK tactics and ATLAS (AI/ML attacks) (ACRA 4 phases)
- CIS Critical Security Controls (CIS Controls) v8.1.2Center for Internet Security
- NIST Cybersecurity Framework (CSF) 2.0National Institute of Standards and Technology (US)
- ISO/IEC 27001:2022International Organization for Standardization
- Supply-chain security evaluation scheme (SCS)METI / IPA (Japan)
- OWASP Top 10 for LLM 2025Generative-AI / LLM-application-specific cyber risk
- Domestic security incident loss dataMarket data on incident loss, used as input to ROI calculations
Built & operated by
Securebase Inc.
Securebase Inc.
Originating from security consulting,
a specialist in cyber risk governance for enterprises.
On expert-review-and-above plans, our security consultants sign off on the AI's first-pass assessment before finalization.
Statements reflect the implementation at the time of publication.
Third-party certifications such as SOC 2 / ISMAP are not currently held.
