Security Checklist
Last updated: 31 July 2026
Item-by-item answers to the questions most commonly asked in vendor security reviews. Items marked [NDA] are disclosed after a non-disclosure agreement is in place. Contact help@sumarii.com.
Anchor links are provided per row so individual answers can be linked directly.
1. Service and operator
| # | Question | Answer |
|---|---|---|
| 1.1 | Service name | Sumarii |
| 1.2 | Operator | Sumarii (sole proprietorship). Legal name disclosed on request — see Specified Commercial Transactions notation. |
| 1.3 | Country of operation | Japan |
| 1.4 | Service start date | 18 July 2026 |
| 1.5 | Security contact | help@sumarii.com |
| 1.6 | Corporate status | Sole proprietorship. Not incorporated. |
2. Certifications
| # | Question | Answer |
|---|---|---|
| 2.1 | ISMS / ISO 27001 | Not held |
| 2.2 | ISO 27017 | Not held |
| 2.3 | Privacy Mark (Pマーク) | Not held |
| 2.4 | SOC 2 | Not held |
| 2.5 | SECURITY ACTION | Not yet obtained |
| 2.6 | Certifications held by underlying infrastructure | Our infrastructure providers hold ISO 27001 and related certifications. Details [NDA]. |
3. Data location
| # | Question | Answer |
|---|---|---|
| 3.1 | Where is meeting audio stored? | Japan (Tokyo region) |
| 3.2 | Where are transcripts and minutes stored? | Japan (Tokyo region) |
| 3.3 | Where are backups stored? | Japan (Tokyo region) |
| 3.4 | Is any processing performed outside Japan? | Yes. Speech recognition is performed in the United States. Transactional email delivery is performed in the United States. Payment processing is performed in the United States. All other processing is in the Tokyo region. |
| 3.5 | Legal basis for cross-border transfer | Contractual measures establishing a structure conforming to APPI Article 28(1) (基準適合体制) |
| 3.6 | Data centre operator | [NDA] |
4. Data handling and retention
| # | Question | Answer |
|---|---|---|
| 4.1 | Retention period for audio | Retained until deleted by the user. No automatic expiry. |
| 4.2 | Retention period for transcripts and minutes | Retained until deleted by the user. |
| 4.3 | Can users delete individual sessions? | Yes. Delete moves a session to Trash (restorable). Delete from Trash permanently removes it. |
| 4.4 | Is deletion immediate and permanent? | Trash is recoverable. Permanent deletion (from Trash, or via account deletion) destroys audio immediately; removes transcript, minutes, and metadata from the live system immediately; residual database-backup copies are purged within 7 days. No recovery after permanent deletion. |
| 4.5 | What happens on account deletion? | All customer data, workspace, and settings are permanently deleted. |
| 4.6 | Is anything retained after account deletion? | The registered email address only, retained for as long as necessary for this purpose, to prevent repeated use of the free tier through re-registration. It is not used for any other purpose. |
| 4.7 | Backup retention period | Daily database backups are retained for 7 days (aligned with Supabase Pro-plan daily backup window). Audio/media is not included in those database backups. |
| 4.8 | Export formats | docx, txt, srt, audio. PDF not currently supported. |
5. AI processing
| # | Question | Answer |
|---|---|---|
| 5.1 | Is customer data used to train AI models? | No. Not by us and not by any subprocessor. |
| 5.2 | Do AI providers retain input data? | No. AI subprocessors operate under zero-retention terms. |
| 5.3 | Are AI providers contractually bound on this? | Yes |
| 5.4 | Which AI vendors are used? | Categories and countries listed in section 9. Names [NDA]. |
| 5.5 | Is customer data used for product analytics or review by staff? | No |
6. Encryption
| # | Question | Answer |
|---|---|---|
| 6.1 | Encryption in transit | HTTPS / TLS 1.2 or higher |
| 6.2 | Encryption at rest | Yes. AES-256 (provided by underlying infrastructure for database and object storage) |
| 6.3 | Are audio files encrypted at rest? | Yes |
| 6.4 | Are audio files publicly accessible by URL? | No. Retrievable only through short-lived signed URLs. |
7. Authentication and access control
| # | Question | Answer |
|---|---|---|
| 7.1 | Authentication methods | Email/password, Google, Microsoft |
| 7.2 | Multi-factor authentication | Optional authenticator-app MFA (TOTP) via account settings. Accounts using Google or Microsoft sign-in may also inherit MFA configured on those provider accounts. |
| 7.3 | SAML single sign-on | Not supported |
| 7.4 | Password policy | Minimum 8 characters, and must include at least one uppercase letter, one lowercase letter, and one number |
| 7.5 | Session timeout | No idle timeout is currently enforced. Access tokens expire after about one hour and are refreshed automatically while the client remains active. Users remain signed in until they sign out or the refresh token is revoked. |
| 7.6 | Data isolation between customers | Per-workspace isolation enforced at the database layer through row-level security |
| 7.7 | Role and permission model | Team workspaces support owner, admin, and member. Owner and admin manage members and invites; owner manages admins and workspace deletion. Members have access to workspace content subject to workspace settings (e.g. sharing can be disabled by owner/admin). |
| 7.8 | Can an administrator revoke a member’s access immediately? | Yes. Owner or admin can remove a member from Settings → Members. Access ends when membership is removed. Pending invites can be revoked. |
| 7.9 | Can operator staff access customer data? | Only for support at the customer’s request, or for investigating a system fault. Not for any other purpose. |
| 7.10 | Is operator access logged? | Yes. Operator access via the infrastructure admin path is recorded in our database/auth provider’s logs. |
8. Logging and audit
| # | Question | Answer |
|---|---|---|
| 8.1 | What events are logged? | Authentication events and API/database access are recorded by our infrastructure provider (Supabase). Dedicated customer-facing application audit logs covering session creation, export, deletion, and similar actions are not currently offered. |
| 8.2 | Log retention period | 7 days (Supabase Pro plan default for API, database, and auth logs) |
| 8.3 | Can customers view audit logs? | Not currently |
9. Subprocessors
| # | Purpose | Processing region |
|---|---|---|
| 9.1 | Database, authentication, object storage (Supabase) | Japan (Tokyo) |
| 9.2 | Audio and media file storage | Japan (Tokyo) |
| 9.3 | Minutes generation and chat (via API) | Japan (Tokyo) |
| 9.4 | CDN and site security (Cloudflare) | Japan (Tokyo) |
| 9.5 | Speech recognition (via API) | United States |
| 9.6 | Transactional email | United States |
| 9.7 | Payment and subscription management (Stripe) | United States |
| # | Question | Answer |
|---|---|---|
| 9.8 | Named subprocessor list | Supabase, Cloudflare, and Stripe are named above. Speech recognition and AI inference vendors are disclosed under NDA. |
| 9.9 | Notification of subprocessor changes | Registered users are notified by email before a new subprocessor processing customer content is added. |
| 9.10 | Are subprocessors bound by contract on data handling? | Yes |
10. Legal and compliance
| # | Question | Answer |
|---|---|---|
| 10.1 | APPI compliance | Yes. See Privacy Policy. |
| 10.2 | Countries where personal data is handled (外的環境の把握) | Japan and the United States |
| 10.3 | GDPR | The service is intended for the Japanese market. We do not make a separate GDPR compliance claim. |
| 10.4 | Information Security Basic Policy | Published |
| 10.5 | Terms of Service | Published |
| 10.6 | Privacy Policy | Published |
| 10.7 | Notation under the Act on Specified Commercial Transactions | Published |
| 10.8 | Is a separate data processing agreement available? | Yes, available on request |
| 10.9 | Can an NDA be signed? | Yes |
11. Availability and incident response
| # | Question | Answer |
|---|---|---|
| 11.1 | Uptime target | 99.9% monthly uptime target (target, not a contractual SLA) |
| 11.2 | Historical uptime | Not currently published |
| 11.3 | Status page | Not currently offered |
| 11.4 | How are outages communicated? | Affected users are notified by email at the registered address |
| 11.5 | Database backup frequency | Daily |
| 11.6 | Media storage resilience | Replicated storage, resilient to underlying hardware failure |
| 11.7 | Incident notification commitment | Affected users are notified by email at the registered address within 72 hours of confirmation |
| 11.8 | Has a security incident occurred to date? | No |
12. Security practices
| # | Question | Answer |
|---|---|---|
| 12.1 | Vulnerability reporting process | help@sumarii.com. See the security page. |
| 12.2 | Dependency update policy | Dependencies are reviewed and updated on a weekly cadence as part of normal maintenance |
| 12.3 | Penetration testing | Not currently conducted on a scheduled basis |
| 12.4 | WAF or equivalent | Yes. Cloudflare Pro WAF (managed rules), plus DDoS mitigation and TLS termination at the edge |
| 12.5 | Are development and production environments separated? | Yes |
| 12.6 | Is customer data used in development or testing? | No |