Security Whitepaper
Publicly disclosable security controls for loFT LLC corporate information, development environments, cloud infrastructure, and inquiry data.
This document summarizes the publicly disclosable security controls adopted by loFT LLC (the “Company”) in a format intended to support customer and vendor security reviews. It is not a third-party certification, audit report, or guarantee for a particular engagement. Requirements in an individual contract take precedence.
1. Document information
| Item | Details |
|---|---|
| Document | loFT LLC Security Whitepaper |
| Version | 1.0 |
| Published and last reviewed | July 23, 2026 |
| Owner | Representative, Koushuu Matsubara |
| Classification | Public |
| Scope | Corporate information, inquiry information, Google Workspace, Google Cloud, AWS, Cloudflare, the Company on-premises development environment, source code and configuration, and the public website |
| Review cycle | Periodically and after material architecture or operational changes |
2. Organization and responsibility
The Company is operated by its representative, who serves as the information security owner, cloud administrator, development owner, and incident response owner. The permitted scope for collecting, using, storing, sharing, and deleting information is determined by its purpose and the needs of each engagement.
Access to customer environments, subcontracting, input to generative AI or LLM services, data location, backup objectives, and other engagement-specific matters are defined in the contract or at engagement initiation. This document alone does not authorize customer information to be entered into an external service or generative AI system.
3. Systems and information in scope
| System or location | Purpose | Primary controls |
|---|---|---|
| Public website | Company information and technical articles | Statically generated with Hugo and delivered through Cloudflare Pages. Cloudflare administrative access is protected by a YubiKey FIDO hardware security key. Inquiry content is not collected or stored by the site; users are redirected to Google Forms |
| Google Forms / Google Workspace | Inquiries, email, business documents, and contract-related documents | Administrative access protected by YubiKey. Documents managed electronically |
| Electronic contracting | Contract execution and retention | Agreements are handled electronically and retained separately from inquiry information |
| Google Cloud | Cloud infrastructure and development or operational workloads | Administrative access protected by YubiKey. IAM, logging, and backup are designed for each engagement |
| AWS | Cloud services used according to engagement requirements | Administrative access protected by a YubiKey FIDO hardware security key. Engagement-specific controls are designed for the target system |
| Company on-premises environment | Development, validation, and AI/LLM research | Administrative network access protected by YubiKey. Not used as the sole repository for corporate documents |
| Git | Version control for source code and applicable configuration | Changes tracked through commit history and diffs |
Inquiry information flow
- A user follows the link from the public website to Google Forms.
- Google Forms collects an email address, name, company name, inquiry details, and related fields.
- The response and related correspondence are managed in Google Workspace.
- If no contract is executed, the inquiry information is deleted three years after the final response.
- If a contract is executed, necessary information is separated into electronic contract, accounting, tax, or other records and follows the applicable retention period.
See the Privacy Policy for details.
4. Identity, authentication, and access control
- Administrative access to Google Workspace, Google Cloud, AWS, and Cloudflare uses YubiKey FIDO hardware security key authentication managed by the representative acting as cloud administrator.
- Administrative access to the Company on-premises network is also protected by YubiKey authentication.
- Access to information and systems is limited to accounts and permissions required for Company operations or the engagement.
- In customer-managed environments, we follow the customer’s identity policy, authorization, connection, and revocation procedures.
- Service accounts, API credentials, and cryptographic keys are treated separately from human administrator authentication, with controls selected for the target system.
The number of registered YubiKeys, recovery procedures, network architecture, and detailed access-control configuration are not published because disclosure could weaken the controls.
5. Data protection and encryption
- Business documents are managed electronically in Google Workspace, and agreements are handled through electronic contracting.
- We use encryption in transit and at rest provided by Google Workspace and Google Cloud.
- HTTPS protects access to the public website and Google Forms.
- Customer-controlled keys, data location, data separation, and transfer methods are designed for the applicable service and contractual requirements.
- Users are instructed not to submit passwords, private keys, tokens, or other authentication information in inquiry details.
For provider controls, see the Google Workspace Security Whitepaper and Google Cloud Security Overview.
6. Documents and physical media
- Business documents are electronic documents in Google Workspace by default.
- Agreements are handled only through electronic contracting.
- Persistent storage of paper agreements is not part of the normal process.
- If paper or physical media must be received, retention, digitization, return, or disposal is determined according to its content and necessity.
7. Development and change management
- Source code and applicable configuration are version-controlled in Git.
- Git commit history and diffs provide a chronological record of changes.
- Testing, review, approval, deployment, and rollback methods are selected according to system criticality and engagement requirements.
- Repositories are not intended to contain credentials or customer information; storage for required secrets is determined for each environment.
- The public website is delivered as statically generated output, with source content and configuration tracked in Git.
8. Logging, monitoring, and vulnerability management
Logging and audit capabilities provided by Google Workspace, Google Cloud, AWS, Cloudflare, and individual workloads are configured according to the importance of the information and engagement requirements. Logs retained by the Company are kept for one month. Alerting and monitoring coverage are defined per system.
The Company subscribes to CVE and security advisories from JPCERT/CC and other sources and compares them with official provider and vendor documentation to assess the impact on relevant operating systems, dependencies, containers, cloud configurations, and applications promptly. When an issue applies, the Company responds promptly according to severity, known exploitation, and the importance of the affected system.
9. Backup and business continuity
Google Workspace is the primary system of record for corporate documents, while Git is the primary change record for source code and configuration. A single on-premises device is not the sole repository for these records.
Backup scope, generations, location, restoration testing, recovery time objective (RTO), and recovery point objective (RPO) are defined for the target system and contractual requirements. Google or Cloudflare redundancy is not universally treated as a substitute for engagement-specific backups.
10. Incident response
If the Company identifies a data leak, unauthorized access, lost credential, malware infection, or other security event, the representative coordinates the following response:
- Confirm and record the event and identify its impact
- Contain the event, including disabling accounts or credentials and isolating affected resources
- Investigate the cause, restore operations, and prevent recurrence
- Notify affected individuals, customers, providers, or authorities according to law, contractual requirements, and impact
- Review controls and procedures after the response
When an individual contract defines a notification deadline or channel, that requirement applies.
11. External services and processors
The primary external services and related parties are:
- Google: Google Forms, Google Workspace, and Google Cloud
- AWS: cloud services used according to engagement requirements
- Cloudflare: public website delivery
- Electronic contracting provider: contract execution and retention when an inquiry proceeds to a contract
Administrative accounts for Google Workspace, Google Cloud, AWS, and Cloudflare are managed by the representative acting as cloud administrator and protected with YubiKey FIDO hardware security key authentication.
Use is scoped according to purpose, data type, contractual terms, published security information, and engagement requirements. If prior approval is required for a new processor or subprocessor handling customer data, we follow the applicable contract.
12. Security questionnaire response matrix
| Review topic | Classification | Public response |
|---|---|---|
| Security owner | Company baseline | The representative is the information security owner and cloud administrator |
| Personal information policy | Company baseline | Published; states purposes, three-year inquiry retention, and request procedures |
| Multi-factor and hardware-key authentication | Company baseline | YubiKey protects administrative access to Workspace, GCP, AWS, Cloudflare, and the on-premises network |
| Authorization | Company baseline + engagement-specific | Limited to required accounts and permissions; customer environments follow customer policy |
| Encryption in transit and at rest | Google-managed + engagement-specific | Workspace/GCP encryption is used; additional key requirements are engagement-specific |
| Document and agreement management | Company baseline | Electronic management in Workspace; agreements handled only through electronic contracting |
| Source and configuration history | Company baseline | Tracked through Git commit history and diffs |
| Logging and monitoring | Company baseline + engagement-specific | Logs retained by the Company are kept for one month; alerts and monitoring scope are set per system |
| Vulnerability intelligence and response | Company baseline + engagement-specific | CVE and security advisories from JPCERT/CC and other sources are checked against official documentation for prompt impact assessment and response |
| Backup, RTO, and RPO | Engagement-specific | Defined for the target system and contractual requirements |
| Incident notification | Company baseline + engagement-specific | Coordinated by the representative and communicated according to law, impact, and contractual deadlines |
| Data location | Engagement-specific | Confirmed and selected according to provider contracts, settings, and customer requirements |
| Subprocessing | Engagement-specific | Prior-approval requirements for customer data follow the contract |
| Generative AI or LLM input | Engagement-specific | Conditions are defined by contract or at initiation; this document is not authorization |
| Information security management framework | Company-defined | The representative defines and operates the controls described in this document |
| ISO/IEC 27001 (ISMS) certification | Not certified | No current plan to obtain certification |
13. Additional information and contact
Architecture, configuration, recovery procedures, and detailed network information that could weaken safeguards are not published. For an engagement-specific security questionnaire, additional information under a nondisclosure agreement, data-processing terms, or contractual requirements, use the contact form.