This document summarizes the publicly disclosable security controls adopted by loFT LLC (the “Company”) in a format intended to support customer and vendor security reviews. It is not a third-party certification, audit report, or guarantee for a particular engagement. Requirements in an individual contract take precedence.

1. Document information

ItemDetails
DocumentloFT LLC Security Whitepaper
Version1.0
Published and last reviewedJuly 23, 2026
OwnerRepresentative, Koushuu Matsubara
ClassificationPublic
ScopeCorporate information, inquiry information, Google Workspace, Google Cloud, AWS, Cloudflare, the Company on-premises development environment, source code and configuration, and the public website
Review cyclePeriodically and after material architecture or operational changes

2. Organization and responsibility

The Company is operated by its representative, who serves as the information security owner, cloud administrator, development owner, and incident response owner. The permitted scope for collecting, using, storing, sharing, and deleting information is determined by its purpose and the needs of each engagement.

Access to customer environments, subcontracting, input to generative AI or LLM services, data location, backup objectives, and other engagement-specific matters are defined in the contract or at engagement initiation. This document alone does not authorize customer information to be entered into an external service or generative AI system.

3. Systems and information in scope

System or locationPurposePrimary controls
Public websiteCompany information and technical articlesStatically generated with Hugo and delivered through Cloudflare Pages. Cloudflare administrative access is protected by a YubiKey FIDO hardware security key. Inquiry content is not collected or stored by the site; users are redirected to Google Forms
Google Forms / Google WorkspaceInquiries, email, business documents, and contract-related documentsAdministrative access protected by YubiKey. Documents managed electronically
Electronic contractingContract execution and retentionAgreements are handled electronically and retained separately from inquiry information
Google CloudCloud infrastructure and development or operational workloadsAdministrative access protected by YubiKey. IAM, logging, and backup are designed for each engagement
AWSCloud services used according to engagement requirementsAdministrative access protected by a YubiKey FIDO hardware security key. Engagement-specific controls are designed for the target system
Company on-premises environmentDevelopment, validation, and AI/LLM researchAdministrative network access protected by YubiKey. Not used as the sole repository for corporate documents
GitVersion control for source code and applicable configurationChanges tracked through commit history and diffs

Inquiry information flow

  1. A user follows the link from the public website to Google Forms.
  2. Google Forms collects an email address, name, company name, inquiry details, and related fields.
  3. The response and related correspondence are managed in Google Workspace.
  4. If no contract is executed, the inquiry information is deleted three years after the final response.
  5. If a contract is executed, necessary information is separated into electronic contract, accounting, tax, or other records and follows the applicable retention period.

See the Privacy Policy for details.

4. Identity, authentication, and access control

  • Administrative access to Google Workspace, Google Cloud, AWS, and Cloudflare uses YubiKey FIDO hardware security key authentication managed by the representative acting as cloud administrator.
  • Administrative access to the Company on-premises network is also protected by YubiKey authentication.
  • Access to information and systems is limited to accounts and permissions required for Company operations or the engagement.
  • In customer-managed environments, we follow the customer’s identity policy, authorization, connection, and revocation procedures.
  • Service accounts, API credentials, and cryptographic keys are treated separately from human administrator authentication, with controls selected for the target system.

The number of registered YubiKeys, recovery procedures, network architecture, and detailed access-control configuration are not published because disclosure could weaken the controls.

5. Data protection and encryption

  • Business documents are managed electronically in Google Workspace, and agreements are handled through electronic contracting.
  • We use encryption in transit and at rest provided by Google Workspace and Google Cloud.
  • HTTPS protects access to the public website and Google Forms.
  • Customer-controlled keys, data location, data separation, and transfer methods are designed for the applicable service and contractual requirements.
  • Users are instructed not to submit passwords, private keys, tokens, or other authentication information in inquiry details.

For provider controls, see the Google Workspace Security Whitepaper and Google Cloud Security Overview.

6. Documents and physical media

  • Business documents are electronic documents in Google Workspace by default.
  • Agreements are handled only through electronic contracting.
  • Persistent storage of paper agreements is not part of the normal process.
  • If paper or physical media must be received, retention, digitization, return, or disposal is determined according to its content and necessity.

7. Development and change management

  • Source code and applicable configuration are version-controlled in Git.
  • Git commit history and diffs provide a chronological record of changes.
  • Testing, review, approval, deployment, and rollback methods are selected according to system criticality and engagement requirements.
  • Repositories are not intended to contain credentials or customer information; storage for required secrets is determined for each environment.
  • The public website is delivered as statically generated output, with source content and configuration tracked in Git.

8. Logging, monitoring, and vulnerability management

Logging and audit capabilities provided by Google Workspace, Google Cloud, AWS, Cloudflare, and individual workloads are configured according to the importance of the information and engagement requirements. Logs retained by the Company are kept for one month. Alerting and monitoring coverage are defined per system.

The Company subscribes to CVE and security advisories from JPCERT/CC and other sources and compares them with official provider and vendor documentation to assess the impact on relevant operating systems, dependencies, containers, cloud configurations, and applications promptly. When an issue applies, the Company responds promptly according to severity, known exploitation, and the importance of the affected system.

9. Backup and business continuity

Google Workspace is the primary system of record for corporate documents, while Git is the primary change record for source code and configuration. A single on-premises device is not the sole repository for these records.

Backup scope, generations, location, restoration testing, recovery time objective (RTO), and recovery point objective (RPO) are defined for the target system and contractual requirements. Google or Cloudflare redundancy is not universally treated as a substitute for engagement-specific backups.

10. Incident response

If the Company identifies a data leak, unauthorized access, lost credential, malware infection, or other security event, the representative coordinates the following response:

  1. Confirm and record the event and identify its impact
  2. Contain the event, including disabling accounts or credentials and isolating affected resources
  3. Investigate the cause, restore operations, and prevent recurrence
  4. Notify affected individuals, customers, providers, or authorities according to law, contractual requirements, and impact
  5. Review controls and procedures after the response

When an individual contract defines a notification deadline or channel, that requirement applies.

11. External services and processors

The primary external services and related parties are:

  • Google: Google Forms, Google Workspace, and Google Cloud
  • AWS: cloud services used according to engagement requirements
  • Cloudflare: public website delivery
  • Electronic contracting provider: contract execution and retention when an inquiry proceeds to a contract

Administrative accounts for Google Workspace, Google Cloud, AWS, and Cloudflare are managed by the representative acting as cloud administrator and protected with YubiKey FIDO hardware security key authentication.

Use is scoped according to purpose, data type, contractual terms, published security information, and engagement requirements. If prior approval is required for a new processor or subprocessor handling customer data, we follow the applicable contract.

12. Security questionnaire response matrix

Review topicClassificationPublic response
Security ownerCompany baselineThe representative is the information security owner and cloud administrator
Personal information policyCompany baselinePublished; states purposes, three-year inquiry retention, and request procedures
Multi-factor and hardware-key authenticationCompany baselineYubiKey protects administrative access to Workspace, GCP, AWS, Cloudflare, and the on-premises network
AuthorizationCompany baseline + engagement-specificLimited to required accounts and permissions; customer environments follow customer policy
Encryption in transit and at restGoogle-managed + engagement-specificWorkspace/GCP encryption is used; additional key requirements are engagement-specific
Document and agreement managementCompany baselineElectronic management in Workspace; agreements handled only through electronic contracting
Source and configuration historyCompany baselineTracked through Git commit history and diffs
Logging and monitoringCompany baseline + engagement-specificLogs retained by the Company are kept for one month; alerts and monitoring scope are set per system
Vulnerability intelligence and responseCompany baseline + engagement-specificCVE and security advisories from JPCERT/CC and other sources are checked against official documentation for prompt impact assessment and response
Backup, RTO, and RPOEngagement-specificDefined for the target system and contractual requirements
Incident notificationCompany baseline + engagement-specificCoordinated by the representative and communicated according to law, impact, and contractual deadlines
Data locationEngagement-specificConfirmed and selected according to provider contracts, settings, and customer requirements
SubprocessingEngagement-specificPrior-approval requirements for customer data follow the contract
Generative AI or LLM inputEngagement-specificConditions are defined by contract or at initiation; this document is not authorization
Information security management frameworkCompany-definedThe representative defines and operates the controls described in this document
ISO/IEC 27001 (ISMS) certificationNot certifiedNo current plan to obtain certification

13. Additional information and contact

Architecture, configuration, recovery procedures, and detailed network information that could weaken safeguards are not published. For an engagement-specific security questionnaire, additional information under a nondisclosure agreement, data-processing terms, or contractual requirements, use the contact form.