Third Scope Logo Third Scope Logo
  • TOP
  • About Us
  • Service
  • Case
  • Media
  • Contact
  • 日本語
  • English
Third Scope Logo
  • TOP
  • About Us
  • Service
  • Case
  • Media
  • Contact
  • 日本語
  • English
  1. Top
  2. Information Security Policy

Information
Security Policy

Information Security Policy

Effective date: 1 August 2026


Preface

Third Scope Ltd. (Japan), Third Scope Asia PTE. LTD. (Singapore), and Third Scope Europe Ltd. (United Kingdom) (individually or collectively, "we", "us", "our", or the "Company") place technology and design at the core of our business, and we recognize that appropriately protecting the information assets entrusted to us by our customers, job applicants, business partners, and our own officers, employees, and contractors is fundamental to our business. On this basis, we set out this Information Security Policy ("Policy") and operate an Information Security Management System (ISMS) across the Group.


Part 1: Common Provisions

Article 1 (Basic Policy)

We promote information security based on the following principles:

  1. We appropriately protect the information assets we hold and process — including customer information, personal data, confidential business information, and system and network assets — from the perspectives of confidentiality, integrity, and availability.
  2. We comply with applicable laws, regulations, and contractual requirements relating to information security.
  3. We establish, and continuously operate and improve, an Information Security Management System (ISMS).
  4. We provide education and awareness training on the importance of information security to all officers, employees, and contractors.
  5. We work to prevent information security incidents before they occur, and respond promptly and appropriately when they do occur.

Article 2 (Scope)

This Policy applies to all information assets and information systems handled by officers and employees of Third Scope Ltd., Third Scope Asia PTE. LTD., and Third Scope Europe Ltd. (including full-time employees, contract staff, and personnel of engaged contractors).

Article 3 (ISMS Certification)

Third Scope Ltd. holds a certification based on ISO/IEC 27001, the international standard for information security management systems.

  • ISMS registration number: 50301700 ISMS22
  • Scope of certification: business activities at our head office (Tokyo)

Third Scope Asia PTE. LTD. and Third Scope Europe Ltd. manage information in accordance with Third Scope Ltd.'s ISMS operating policy, and will consider pursuing their own local certification in the future, having regard to the scale of their operations and local requirements.

Article 4 (Organizational Security Measures)

  1. We appoint an information security manager responsible for developing information security policy, overseeing implementation, and coordinating corrective actions.
  2. We manage access rights according to the sensitivity of information assets, and conduct periodic reviews of access rights.
  3. We maintain internal information security regulations and communicate them to our officers and employees.
  4. When selecting contractors, we evaluate their information security posture and require appropriate security measures under contract.

Article 5 (Personnel Security Measures)

  1. We provide information security education and training to officers and employees upon joining and on an ongoing basis.
  2. We enter into confidentiality agreements with officers, employees, and contractors.

Article 6 (Physical Security Measures)

We implement access control and other physical protective measures for office spaces and facilities such as servers that handle information assets.

Article 7 (Technical Security Measures)

  1. We implement technical measures, including firewalls, access controls, encryption, and log management, to protect our information systems from unauthorized access, computer viruses, and other threats.
  2. Where we use cloud services, we select providers based on an evaluation of their security standards and require appropriate security measures under contract.
  3. We perform appropriate backups of information assets and systems to support business continuity.

Article 8 (Incident Response)

  1. When we become aware of an information security incident (such as a data leak, unauthorized access, or system failure), we promptly investigate the scope of impact and take measures to contain the damage and restore normal operations.
  2. Where applicable law imposes a notification obligation, we provide appropriate notice to the relevant supervisory authority and affected individuals within the timeframe required by law.
  3. We analyze the root cause of incidents and implement measures to prevent recurrence.

Article 9 (Continuous Improvement)

We periodically assess the effectiveness of our Information Security Management System and pursue continuous improvement through internal audits and management review.

Article 10 (Contact Us)

For questions regarding this Policy, please contact:

  • Data Protection Officer, Third Scope Ltd. — Shuto Nakazato
  • Email: ga@third-scope.com

Part 2: Annexes

Annex A: Japan (Third Scope Ltd.)

Third Scope Ltd. holds ISMS registration number 50301700 ISMS22 and implements information security management under this Policy, centered on its head office (Tokyo). With respect to personal data, we implement the security control measures required under the APPI (including Article 23) within the framework of this Policy and our ISMS.

Annex B: Singapore (Third Scope Asia PTE. LTD.)

Third Scope Asia PTE. LTD. implements the Group-wide security measures set out in this Policy and complies with the reasonable security arrangements required under the PDPA's Protection Obligation.

Annex C: United Kingdom (Third Scope Europe Ltd.)

Third Scope Europe Ltd. implements the Group-wide security measures set out in this Policy and complies with the technical and organizational measures required under Article 32 of the UK GDPR to ensure a level of security appropriate to the risk.

Third Scope

About

  • About Us
  • Media
  • Service
  • Case
  • Contact

Locations

  • Tokyo
  • London
  • Singapore

Legal

  • Privacy Policy
  • Terms of Use
  • Information Security Policy
  • Cookie Policy

© Third Scope Inc.