最終更新: 2026年7月
AulaSys は Cloudflare のグローバルネットワーク上で稼働しています。アプリケーション(Cloudflare Workers)、データベース(D1)、ファイル保管(R2)のすべてが Cloudflare の管理する環境にあり、当社が独自にサーバーを運用することはありません。
スクールごとに専用のデータベースを用意しています。共有のテーブルに複数のスクールのデータを混在させ、プログラムで絞り込む方式ではありません。リクエストはドメイン名から対象スクールを判定し、そのスクール専用のデータベースにのみ接続します。設定ミスによって他のスクールのデータが見えるという事態が、構造上발생しません。
通信はすべて HTTPS(TLS)です。保管データは Cloudflare により暗号化されています。
パスワードは復元できない形(ハッシュ)で保存します。PBKDF2-SHA256、10万回の反復、利用者ごとに異なるランダムなソルトを使用しています。当社の担当者を含め、誰も生徒のパスワードを読み取ることはできません。忘れた場合は再設定リンクをお送りする以外に方法はなく、これは意図した設計です。
管理者・生徒ともに、メールによる2段階認証をご利用いただけます。
インストラクターの権限は役割ごとに設定でき、サーバー側で毎回検証されます。特権的な操作は監査ログに記録されます。パスワードを変更すると、既存のログインセッションはすべて無効になります。
クレジットカード番号とセキュリティコードを当サービスが保持することはありません。決済は Square が処理し、カード本体の情報は Square が保管します。当サービスが保存するのは、金額・支払状況に加えて、カードをご本人が識別するためのブランド名・下4桁・有効期限、および Square 側の参照IDのみです。これらからカード番号を復元することはできません。
Cloudflare(インフラ)、Square(決済)、Resend(メール送信)、GitHub(ソースコード管理・生徒データなし)。
データベースは Cloudflare R2 に定期的にバックアップしています。
手順を文書化しています。個人データに影響する事案が発生した場合、確認でき次第、対象のスクールへご連絡します。個人情報保護法に基づく報告が必要な場合は、これを行います。生徒データに関わる事案を公表せずに処理することはありません。
正確にお伝えします。
| SOC 2 | 準備状況の評価は完了。Type II 取得を計画中です。現時点で監査報告書は保有していません。 |
|---|---|
| ISO 27001/ISMS | 未取得。今後の検討事項です。 |
| PCI DSS | 当サービスの対象外です(カード情報を保持しないため)。決済代行の Square が準拠しています。 |
| 社内規程 | アクセス管理・データ取扱い・インシデント対応の各規程を文書化済み。 |
取得していない認証を「取得済み」と表現することはいたしません。ご不明な点は下記までお問い合わせください。
セキュリティ上の問題を発見された場合は info@aulasys.app までご連絡ください。誠意をもって対応し、ご報告者に法的措置をとることはありません。
← AulaSys トップへLast updated: July 2026
AulaSys runs entirely on Cloudflare’s global network — application (Workers), database (D1) and file storage (R2). We operate no servers of our own.
Every school gets its own database. We do not put multiple schools in shared tables and filter them apart in code. A request identifies its school from the domain name and connects only to that school’s database. One school seeing another’s data is not something a misconfiguration can cause, because there is no shared table to leak across.
All traffic is HTTPS (TLS). Stored data is encrypted at rest by Cloudflare.
Passwords are stored in a form that cannot be reversed: PBKDF2-SHA256, 100,000 iterations, with a unique random salt per person. Nobody — including us — can read a member’s password. If someone forgets theirs, the only remedy is a reset link. That is deliberate, not a limitation.
Email-based two-factor authentication is available for administrators and members.
Instructor permissions are role-based and re-checked on the server for every request. Privileged actions are written to an audit log. Changing a password invalidates every existing session for that account.
We never hold full card numbers or security codes. Square processes payments and stores the card itself. Alongside the amount and status we keep the card brand, last four digits and expiry — so a member can recognise which card is on file — plus Square’s own reference IDs. None of that can be turned back into a card number.
Cloudflare (infrastructure), Square (payments), Resend (transactional email), GitHub (source code — no member data).
Databases are backed up to Cloudflare R2.
We have a documented incident response procedure. If an incident affects personal data we notify the affected schools as soon as we understand what happened, and we report to Japan’s Personal Information Protection Commission where required. We will not quietly fix a breach that touched member data.
| SOC 2 | Readiness assessment complete; Type II planned. We do not hold an audit report today. |
|---|---|
| ISO 27001 / ISMS | Not certified. Under consideration. |
| PCI DSS | Out of scope for us — we hold no card data. Square, our payment processor, is compliant. |
| Internal policies | Access control, data handling and incident response are documented. |
We will not describe ourselves as holding a certification we do not have. If your review needs more detail than this page, ask us — we keep a completed security questionnaire ready to send.
Email info@aulasys.app. We will engage in good faith and will not pursue legal action against anyone who reports a genuine issue responsibly.
← Back to AulaSys