Security Practices
Last updated: August 6, 2026
At Tachikoma AI, security is fundamental to everything we build. As the company behind BoutiqueDX, a platform trusted by leading luxury retail brands worldwide, we maintain rigorous security practices to protect our clients’ data and operations. This page outlines our approach to security across infrastructure, development, and organizational practices.
Table of Contents
1. INFRASTRUCTURE SECURITY
Our platform runs on Amazon Web Services (AWS) cloud infrastructure, with our primary data center located in Tokyo, Japan. We deploy within a Virtual Private Cloud with perimeter firewalls and network segmentation to isolate workloads. Our architecture spans multiple Availability Zones to ensure high availability and resilience. CDN edge locations provide performance optimization and additional failover capabilities. Data residency is pinned per tenant to their designated region, ensuring that client data remains within the agreed-upon geographic boundaries.
2. DATA ENCRYPTION
All data at rest is encrypted using AES-256 encryption. All data in transit is protected with TLS 1.2 or higher. Full-disk encryption is mandatory on all employee devices. We use encrypted secrets management and maintain a strict policy against storing plaintext credentials in code repositories.
3. ACCESS CONTROL & AUTHENTICATION
We support Single Sign-On (SSO) and SAML for enterprise clients. Multi-factor authentication (MFA) is supported across all services. Each client’s data is logically isolated at the identity layer through per-tenant separation. Internal systems follow a need-to-share access principle, and role-based access control with least-privilege permissions is enforced throughout the organization. Access is promptly revoked upon employee departure.
4. DATA PRIVACY & COMPLIANCE
We are compliant with the General Data Protection Regulation (GDPR) in the European Union and the Act on Protection of Personal Information (APPI) in Japan. Data Processing Agreements (DPA) are available upon request for enterprise clients. We are actively pursuing SOC 2 Type II and ISO 27001 certifications to further demonstrate our commitment to security best practices.
5. DEVELOPMENT & DEPLOYMENT SECURITY
We maintain strictly separated environments for development, staging, and production. Staging and production use independent databases and configurations to ensure environment-level isolation. Security considerations are integrated into our development guidelines and code review processes. All releases follow semantic versioning.
6. VULNERABILITY MANAGEMENT
We conduct automated vulnerability scanning of our infrastructure and applications. Annual external security assessments are performed by independent experts. Identified vulnerabilities are remediated in a timely manner based on their severity classification.
7. INCIDENT RESPONSE
Our engineering team is trained and available to respond to security incidents. Incident management and escalation procedures are clearly defined and regularly reviewed. In accordance with GDPR requirements, we commit to breach notification within 72 hours of becoming aware of a qualifying incident. Post-incident reviews and remediation processes are conducted to prevent recurrence.
8. EMPLOYEE SECURITY
All employees receive security awareness training upon onboarding. Mandatory device security controls include disk encryption, automatic screen lock, and firewall activation. We are establishing background verification processes as part of our compliance program. Access privileges are reviewed regularly to ensure they remain appropriate.
9. THIRD-PARTY RISK MANAGEMENT
Due diligence and security assessments are required for all vendors and subprocessors before engagement. Written contracts include security and data protection requirements. End-to-end encryption is required for all third-party data connections. We conduct annual vendor security reviews and define geographic data storage restrictions in vendor agreements.
10. AI & DATA USAGE
AI features within our platform are optional and can be disabled on a per-tenant basis. Customer data is never used to train AI models. Sensitive fields are redacted before being processed by AI services to ensure privacy is maintained throughout.
Security Inquiries
For security-related questions or to report a vulnerability, please contact us:
Email: contact@tachikoma-ai.com
Headquarters
Tachikoma AI Pte. Ltd.
68 Circular Road #02-01, 049422, Singapore
Japan Subsidiary
Tachikoma AI K.K.
1-42-11 Uehara, Shibuya-ku, 151-0064 Tokyo, Japan