← AulaSys
日本語

セキュリティについて

最終更新: 2026年7月

1. インフラストラクチャ

AulaSys は Cloudflare のグローバルネットワーク上で稼働しています。アプリケーション(Cloudflare Workers)、データベース(D1)、ファイル保管(R2)のすべてが Cloudflare の管理する環境にあり、当社が独自にサーバーを運用することはありません。

2. スクールごとのデータ分離

スクールごとに専用のデータベースを用意しています。共有のテーブルに複数のスクールのデータを混在させ、プログラムで絞り込む方式ではありません。リクエストはドメイン名から対象スクールを判定し、そのスクール専用のデータベースにのみ接続します。設定ミスによって他のスクールのデータが見えるという事態が、構造上발생しません。

3. 通信と保管の暗号化

通信はすべて HTTPS(TLS)です。保管データは Cloudflare により暗号化されています。

4. パスワードの扱い

パスワードは復元できない形(ハッシュ)で保存します。PBKDF2-SHA256、10万回の反復、利用者ごとに異なるランダムなソルトを使用しています。当社の担当者を含め、誰も生徒のパスワードを読み取ることはできません。忘れた場合は再設定リンクをお送りする以外に方法はなく、これは意図した設計です。

管理者・生徒ともに、メールによる2段階認証をご利用いただけます。

5. アクセス権限

インストラクターの権限は役割ごとに設定でき、サーバー側で毎回検証されます。特権的な操作は監査ログに記録されます。パスワードを変更すると、既存のログインセッションはすべて無効になります。

6. お支払い情報

クレジットカード番号とセキュリティコードを当サービスが保持することはありません。決済は Square が処理し、カード本体の情報は Square が保管します。当サービスが保存するのは、金額・支払状況に加えて、カードをご本人が識別するためのブランド名・下4桁・有効期限、および Square 側の参照IDのみです。これらからカード番号を復元することはできません。

7. データの所在と委託先

Cloudflare(インフラ)、Square(決済)、Resend(メール送信)、GitHub(ソースコード管理・生徒データなし)。

8. バックアップ

データベースは Cloudflare R2 に定期的にバックアップしています。

9. インシデント対応

手順を文書化しています。個人データに影響する事案が発生した場合、確認でき次第、対象のスクールへご連絡します。個人情報保護法に基づく報告が必要な場合は、これを行います。生徒データに関わる事案を公表せずに処理することはありません。

10. 認証・監査の状況

正確にお伝えします。

SOC 2準備状況の評価は完了。Type II 取得を計画中です。現時点で監査報告書は保有していません。
ISO 27001/ISMS未取得。今後の検討事項です。
PCI DSS当サービスの対象外です(カード情報を保持しないため)。決済代行の Square が準拠しています。
社内規程アクセス管理・データ取扱い・インシデント対応の各規程を文書化済み。

取得していない認証を「取得済み」と表現することはいたしません。ご不明な点は下記までお問い合わせください。

11. 脆弱性のご報告

セキュリティ上の問題を発見された場合は info@aulasys.app までご連絡ください。誠意をもって対応し、ご報告者に法的措置をとることはありません。

← AulaSys トップへ
English

Security

Last updated: July 2026

1. Infrastructure

AulaSys runs entirely on Cloudflare’s global network — application (Workers), database (D1) and file storage (R2). We operate no servers of our own.

2. Separation between schools

Every school gets its own database. We do not put multiple schools in shared tables and filter them apart in code. A request identifies its school from the domain name and connects only to that school’s database. One school seeing another’s data is not something a misconfiguration can cause, because there is no shared table to leak across.

3. Encryption

All traffic is HTTPS (TLS). Stored data is encrypted at rest by Cloudflare.

4. Passwords

Passwords are stored in a form that cannot be reversed: PBKDF2-SHA256, 100,000 iterations, with a unique random salt per person. Nobody — including us — can read a member’s password. If someone forgets theirs, the only remedy is a reset link. That is deliberate, not a limitation.

Email-based two-factor authentication is available for administrators and members.

5. Access control

Instructor permissions are role-based and re-checked on the server for every request. Privileged actions are written to an audit log. Changing a password invalidates every existing session for that account.

6. Payment details

We never hold full card numbers or security codes. Square processes payments and stores the card itself. Alongside the amount and status we keep the card brand, last four digits and expiry — so a member can recognise which card is on file — plus Square’s own reference IDs. None of that can be turned back into a card number.

7. Where data lives, and who else touches it

Cloudflare (infrastructure), Square (payments), Resend (transactional email), GitHub (source code — no member data).

8. Backups

Databases are backed up to Cloudflare R2.

9. If something goes wrong

We have a documented incident response procedure. If an incident affects personal data we notify the affected schools as soon as we understand what happened, and we report to Japan’s Personal Information Protection Commission where required. We will not quietly fix a breach that touched member data.

10. Certifications — stated plainly

SOC 2Readiness assessment complete; Type II planned. We do not hold an audit report today.
ISO 27001 / ISMSNot certified. Under consideration.
PCI DSSOut of scope for us — we hold no card data. Square, our payment processor, is compliant.
Internal policiesAccess control, data handling and incident response are documented.

We will not describe ourselves as holding a certification we do not have. If your review needs more detail than this page, ask us — we keep a completed security questionnaire ready to send.

11. Reporting a vulnerability

Email info@aulasys.app. We will engage in good faith and will not pursue legal action against anyone who reports a genuine issue responsibly.

← Back to AulaSys