セキュリティとインシデント対応 / Security & Incident Response
1. 安全管理の方針 / Security measures
- 通信は常時 TLS。個人情報(氏名・住所・メールアドレス)は保存時に AES-256-GCM で暗号化し、鍵はリポジトリにもデータベースにも置きません。
All traffic uses TLS. Personal data (name, address, email) is encrypted at rest with AES-256-GCM; keys are kept only in the app's secret store. - バックアップは暗号化(age)して保管し、テスト環境と本番環境を分離しています。
Backups are encrypted (age) before storage; test and production environments are separate. - 個人情報へのアクセスは記録(1年保持)し、開発者本人のみがアクセスできます。全アカウントで二要素認証を有効にしています。
Access to personal data is logged (kept one year) and limited to the developer; every account uses two-factor authentication. - アプリのログに個人情報を出力しません。
Application logs never contain personal data.
2. インシデント対応 / Incident response
- 検知 / Detection — ホスティング事業者のアラート、エラー監視、店舗からの報告。
Provider alerts, error monitoring and merchant reports. - 封じ込め(24時間以内)/ Containment within 24 hours — 認証情報の失効・鍵の更新、必要ならサービスの停止。
Revoke credentials, rotate keys, take the service offline if needed. - 影響の特定 / Assessment — 影響を受けた店舗・注文・データ項目を特定。
Identify affected stores, orders and data fields. - 通知(72時間以内)/ Notification within 72 hours — 影響を受ける店舗と Shopify に、事実・影響・対処を通知。
Notify affected merchants and Shopify with the facts, the impact and the remediation. - 再発防止 / Post-incident review — 原因の修正と、本ページの更新。
Fix the root cause and update this page.
3. 脆弱性の報告 / Reporting a vulnerability
メール / Email: yudevlabcom@gmail.com(件名に「Security」)。2営業日以内に返信します。
Please put "Security" in the subject. We reply within two business days.