Security Practices

Last updated: August 6, 2026

At Tachikoma AI, security is fundamental to everything we build. As the company behind BoutiqueDX, a platform trusted by leading luxury retail brands worldwide, we maintain rigorous security practices to protect our clients’ data and operations. This page outlines our approach to security across infrastructure, development, and organizational practices.

1. INFRASTRUCTURE SECURITY

Our platform runs on Amazon Web Services (AWS) cloud infrastructure, with our primary data center located in Tokyo, Japan. We deploy within a Virtual Private Cloud with perimeter firewalls and network segmentation to isolate workloads. Our architecture spans multiple Availability Zones to ensure high availability and resilience. CDN edge locations provide performance optimization and additional failover capabilities. Data residency is pinned per tenant to their designated region, ensuring that client data remains within the agreed-upon geographic boundaries.

2. DATA ENCRYPTION

All data at rest is encrypted using AES-256 encryption. All data in transit is protected with TLS 1.2 or higher. Full-disk encryption is mandatory on all employee devices. We use encrypted secrets management and maintain a strict policy against storing plaintext credentials in code repositories.

3. ACCESS CONTROL & AUTHENTICATION

We support Single Sign-On (SSO) and SAML for enterprise clients. Multi-factor authentication (MFA) is supported across all services. Each client’s data is logically isolated at the identity layer through per-tenant separation. Internal systems follow a need-to-share access principle, and role-based access control with least-privilege permissions is enforced throughout the organization. Access is promptly revoked upon employee departure.

4. DATA PRIVACY & COMPLIANCE

We are compliant with the General Data Protection Regulation (GDPR) in the European Union and the Act on Protection of Personal Information (APPI) in Japan. Data Processing Agreements (DPA) are available upon request for enterprise clients. We are actively pursuing SOC 2 Type II and ISO 27001 certifications to further demonstrate our commitment to security best practices.

5. DEVELOPMENT & DEPLOYMENT SECURITY

We maintain strictly separated environments for development, staging, and production. Staging and production use independent databases and configurations to ensure environment-level isolation. Security considerations are integrated into our development guidelines and code review processes. All releases follow semantic versioning.

6. VULNERABILITY MANAGEMENT

We conduct automated vulnerability scanning of our infrastructure and applications. Annual external security assessments are performed by independent experts. Identified vulnerabilities are remediated in a timely manner based on their severity classification.

7. INCIDENT RESPONSE

Our engineering team is trained and available to respond to security incidents. Incident management and escalation procedures are clearly defined and regularly reviewed. In accordance with GDPR requirements, we commit to breach notification within 72 hours of becoming aware of a qualifying incident. Post-incident reviews and remediation processes are conducted to prevent recurrence.

8. EMPLOYEE SECURITY

All employees receive security awareness training upon onboarding. Mandatory device security controls include disk encryption, automatic screen lock, and firewall activation. We are establishing background verification processes as part of our compliance program. Access privileges are reviewed regularly to ensure they remain appropriate.

9. THIRD-PARTY RISK MANAGEMENT

Due diligence and security assessments are required for all vendors and subprocessors before engagement. Written contracts include security and data protection requirements. End-to-end encryption is required for all third-party data connections. We conduct annual vendor security reviews and define geographic data storage restrictions in vendor agreements.

10. AI & DATA USAGE

AI features within our platform are optional and can be disabled on a per-tenant basis. Customer data is never used to train AI models. Sensitive fields are redacted before being processed by AI services to ensure privacy is maintained throughout.

Security Inquiries

For security-related questions or to report a vulnerability, please contact us:

Email: contact@tachikoma-ai.com

Headquarters

Tachikoma AI Pte. Ltd.
68 Circular Road #02-01, 049422, Singapore

Japan Subsidiary

Tachikoma AI K.K.
1-42-11 Uehara, Shibuya-ku, 151-0064 Tokyo, Japan