Last updated: October 8, 2026
Scope
This policy covers the public site on f-factory.co.jp, its content, delivery and maintenance, and its contact form. External services such as hosting, repositories, and email are managed through a combination of the provider's controls and our configuration.
Core Principles
We keep functionality and privileges to the minimum needed and separate public information from credentials and source data. We carry out updates, backups, change review, and log review, and reassess measures in light of threats, impact, and implementation.
Transport and Delivery
The production site is delivered over HTTPS, with certificate and domain renewal managed. Delivery settings are tested in the environment where they will be used before being applied. External links identify their destination so a user can check the domain and operator.
Credentials and Research Data
API keys, application passwords, social tokens, private keys, and database credentials are not stored in a public repository or HTML. Environment files, backups, raw analytical data, and personal information are separated from published artifacts.
Before releasing research data, we review provider conditions, de-identification, rights, and required approval.
Updates and Change Management
We monitor updates to the software and libraries used by the site and check their effects in a test environment before release. Changes are recorded, and obsolete features and files are removed after their effects have been checked.
Input and Enquiries
Before submission, details are held in memory while the page is open and are not saved in cookies, localStorage, or other persistent browser storage. When you send an enquiry, the details and consent are validated, displayed content is handled safely, and the details are emailed to our designated recipient. A visitor's email address is used only as the reply address, never as the sender. File attachments and automatic reply emails are not supported.
Origin checks, expiring submission tokens, and submission limits help reduce misuse and excessive requests. The signing key, token usage records, and rate-limit information based on an IP-derived hashed identifier are kept in dedicated files outside the public web directory. Tokens and rate limits expire after 15 minutes; expired records are removed during enquiry processing. Enquiry details are not stored in the receiving application's database, files, or logs. Entered details may be retained in mail queues, received emails, or provider logs. See the Privacy Policy for purposes of use, processors, retention, and handling of enquiries.
Do not send passwords or sensitive research data in an initial enquiry.
Backup and Recovery
Backups for public content, configuration, and databases are designed according to need and recovery objectives. They are kept out of public directories and repositories, access is restricted, and restoration steps are checked. A backup alone does not prove that recovery is possible. We also record versions, dependencies, and external services.
Monitoring and Incident Response
When we identify a fault, suspicious change, authentication attempt, dependency issue, or possible disclosure, we determine its scope. As needed, we may restrict access, change credentials, make corrections, restore the site, and contact affected parties or providers. Where applicable law requires reporting or individual notice, we confirm facts and respond accordingly.
Reporting a Vulnerability
Do not publish vulnerability details on social media or an unrelated third-party site. Use the Contact page to provide the URL, a concise description, minimum reproduction information, and a contact route. Do not obtain personal information, alter data, interrupt service, or establish persistent access in the course of testing. No public bounty program is offered.
User Precautions
Check the correct domain and HTTPS before browsing or submitting. If you encounter impersonation, a certificate warning, a suspicious download, or a request for credentials, stop and contact us through the official site. Users are also responsible for the security of their device, browser, and network.
Limits and Revisions
Security measures reduce risk but cannot prevent every attack, fault, or third-party outage. This policy is reviewed when architecture, threats, services, or applicable law changes, with a material revision shown by the last-updated date.