This Data Handling Policy (the "Policy") explains how Securious Lab G.K. handles data uploaded, entered, transmitted, or connected by users in FirstLook; findings, scores, summaries, reports, and other outputs generated by FirstLook and presented to users; operation logs; and other related data.
This Policy supplements the data handling, external service use, dangerous data, AI use, retention period, and deletion provisions set out in the FirstLook Terms of Use.
1. Basic Policy
- FirstLook handles data only to the extent necessary to support incident investigation, log analysis, digital forensics, IOC matching, and report preparation.
- Users must not upload personal information, credentials, decryption keys, excessively broad customer confidential information, or other highly sensitive data beyond the scope necessary for analysis.
- We do not use uploaded data to train or improve general-purpose AI models or other third-party AI models.
- As of the date this Policy is prepared, FirstLook's standard analysis functions do not send uploaded data to generative AI or LLM services for analysis.
- When external services or external APIs are used, we will identify, as clearly as reasonably possible, the categories of data sent, the purpose of transmission, and the data that is not sent, and will limit transmission to the minimum necessary scope.
- FirstLook accepts malware, suspicious files, exploit code, and other dangerous data only within the formats, handling methods, or analysis targets expressly supported by us.
2. Categories of Data Handled
FirstLook mainly handles the following categories of data.
| Category | Examples | Main Purposes |
|---|---|---|
| Account / contract information | User names, email addresses, organization, permissions, contract plan | Authentication, authorization, contract management, support |
| Uploaded data | Logs, events, artifacts, files, archives, IOCs, notes | Analysis, extraction, scoring, report generation |
| Analysis target metadata | File names, paths, hashes, timestamps, sizes, extensions, hostnames, IP addresses, domains, URLs | Detection, correlation, IOC matching, threat intelligence lookups |
| Findings / outputs | Findings, scores, detection reasons, summaries, reports, comments | Display to users, report preparation, review, quality confirmation |
| Operation / audit logs | Login, upload, viewing, editing, deletion, administrative actions | Security, audit, misuse investigation, support |
| System logs | Errors, processing time, job status, resource usage | Operations, incident investigation, performance improvement |
| Feedback | Inquiries, correction requests, review comments | Support, quality improvement, feature improvement |
3. Data Minimization Requested of Users
Before uploading data to FirstLook, users must confirm the following.
- The user has the necessary authority, contractual basis, internal approval, customer permission, or other lawful basis to handle the data to be uploaded.
- The data does not contain personal information, credentials, decryption keys, private keys, API keys, passwords, tokens, or excessively broad customer confidential information that is unnecessary for the analysis purpose.
- If customer data, entrusted data, or third-party data is handled, the user is responsible for determining whether the data may be brought into FirstLook, for providing required explanations, and for maintaining appropriate safeguards.
- Data unnecessary for FirstLook analysis is excluded or minimized to the extent reasonably possible.
This Policy does not impose a uniform masking obligation on users. However, users should endeavor not to upload information that is unnecessary for the analysis purpose.
4. Handling of Dangerous Data and Malware
Due to the nature of incident investigation, FirstLook may handle suspicious files, malicious scripts, exploit code, executable files, malware-related data, and other potentially dangerous data.
At present, FirstLook primarily targets logs, artifacts, metadata, archives, IOCs, analysis target files, and related structured data. Malware bodies, exploit code, dangerous scripts, executable files, and other dangerous data may be uploaded only within the formats, handling methods, or analysis targets expressly supported by us.
When handling dangerous data, we will consider or implement safety measures such as static analysis, isolated processing, non-execution processing, size limits, timeouts, privilege separation, and other appropriate controls. Specific handling methods may vary depending on the feature, contract, environment, and specifications at the time of provision.
5. External Services and External APIs
FirstLook may use external services or external APIs to the extent necessary to provide the Service, including for analysis, IOC matching, threat intelligence lookups, cloud infrastructure, operational monitoring, support, and related purposes.
Depending on the type of external service and feature, hash values, IP addresses, domains, URLs, IOCs, detection attributes, scores, findings, summaries, parts of other outputs presented to users, log fragments or metadata, and technical logs necessary for service operations may be sent.
For external threat intelligence lookups, we generally send IOCs such as hash values, IP addresses, domains, and URLs. File names, file paths, log bodies, and file bodies are not sent for external threat intelligence lookup purposes except where an expressly described feature, or the user's explicit operation or consent, provides otherwise.
When using external services, we endeavor not to send data unnecessary for the relevant purpose. In particular, we generally do not send credentials, passwords, private keys, decryption keys, API keys, access tokens, personal information unnecessary for analysis, full text of customer confidential information, full content of malware bodies or executable files, or full bodies of logs, emails, documents, or similar content.
However, where the user explicitly requests an investigation, where an expressly described feature is used, where an individual agreement applies, or where an external service integration requires a different handling, we may handle the above data differently after providing separate explanation or obtaining consent as appropriate.
External Service List
| Service Type | Candidates / Examples | Data That May Be Sent | Current Status |
|---|---|---|---|
| Cloud infrastructure | Google Cloud Platform (GCP) | Uploaded data, findings, scores, summaries, reports, system logs, operation / audit logs | Generally used in Japan regions |
| Threat intelligence / external reputation | VirusTotal, AbuseIPDB, GreyNoise, AlienVault OTX, MalwareBazaar, ThreatFox, Hashlookup, Shodan, Netlas, Censys, Spamhaus | IOCs such as hash values, IP addresses, domains, URLs, and related metadata | Used only when the feature is enabled and necessary. May be temporarily disabled due to development or operational rate limits and API limits |
| IP / ASN / Geo information | ip-api.com | IP addresses | Used only when the feature is enabled and necessary |
| Monitoring / error collection | FirstLook's own internal functions | Errors, technical logs, operation metadata, job status, resource usage | Performed within FirstLook |
| Email / notifications | Undetermined | Email addresses, notification content | To be identified if formally used |
| Generative AI / LLM | Not used by standard analysis functions at present | Uploaded data is not sent by standard analysis functions | Policy confirmed |
6. AI / LLM and Model Training
As of the date this Policy is prepared, FirstLook's standard analysis functions do not send uploaded data to generative AI or LLM services for analysis.
We do not use uploaded data to train or improve general-purpose AI models or other third-party AI models.
If we later add AI, LLM, AI API, AI-based summarization, report generation, explanation generation, or similar functions as standard FirstLook features, we will specify the categories of data sent, destination, purpose of use, retention, whether model training is involved, opt-in / opt-out, and whether user consent is required in this Policy or an attachment.
7. Data Storage Location
FirstLook's data storage location and management responsibility differ depending on the form of provision.
When we provide FirstLook as a cloud service, FirstLook data is stored or processed in databases, storage, backups, monitoring infrastructure, and other systems on Google Cloud Platform (GCP) managed by us. The main storage region is generally within Japan.
For backups, redundancy, disaster recovery, monitoring, maintenance, and other operationally necessary processing, data may be replicated, temporarily stored, or processed within the same country or within cloud environments managed by us. Specific backup methods, retention periods, deletion reflection timing, and other operational details will be defined in this Policy, individual agreements, or related documents after operational design is finalized.
When FirstLook is provided as Docker containers or in another format in the user's on-premises environment, a cloud environment contracted by the user, or another environment designated by the user, uploaded data, findings, scores, summaries, reports, operation logs, audit logs, backups, and other data are generally stored or processed within that user environment.
In this case, unless otherwise provided in an individual agreement, the user is responsible for the infrastructure, network, storage, backups, access control, audit logs, deletion, physical security, cloud contracts, external connection control, and other management of the user environment. If we access the user environment or data for support, maintenance, incident investigation, updates, or other purposes, the scope, method, period, and permissions will follow the individual agreement, support terms, or the user's consent.
If, in the cloud-provided version or on-premises / customer environment version, provision to a third party located outside Japan, processing by an entrusted party located outside Japan, or storage in a region outside Japan becomes necessary, we will provide necessary explanations, contractual measures, and other appropriate responses in accordance with laws and individual agreements.
8. Data Retention Periods
FirstLook's data retention periods vary depending on the form of provision, contract terms, plan, feature, user settings, and our operational settings. If an individual agreement provides otherwise, the individual agreement prevails.
| Data Category | Retention Policy | Notes |
|---|---|---|
| Uploaded data bodies | Retained for the period necessary for analysis processing, reanalysis, review, incident investigation, and other Service provision purposes. | As an initial operational guideline, the retention period is approximately one month after analysis completion or upload. After that period or after the relevant purpose ends, we may delete, archive, or make uploaded data bodies unavailable. |
| Extracted events, intermediate analysis data, analysis target metadata, and other detailed data | Retained for the period necessary for report generation, reanalysis, review, incident investigation, and other Service provision purposes. | As an initial operational guideline, the retention period is approximately one month after analysis completion or generation. After that period or after the relevant purpose ends, we may delete, aggregate, archive, or make these detailed data unavailable. |
| Findings, scores, summaries, reports, and other outputs presented to users | Retained to the extent necessary for display to users, review, report output, support, and contractual purposes. | May be retained during the contract term or until deleted by the user. |
| Operation / audit logs | Retained for security, audit, misuse investigation, and support. | The standard retention period is generally 730 days. |
| External API usage logs | Retained for rate limiting, usage management, audit, and misuse investigation. | Tenant, service used, usage count, and related information are recorded. Detailed retention periods follow operational settings. |
| Billing / credit usage history | Retained for billing, accounting, contract management, and audit. | Even if a case, report, or job is deleted, usage history may be retained after deleting or anonymizing the reference destination. |
| System logs / errors | Retained for operational monitoring, incident investigation, performance improvement, and security. | The retention period varies depending on log type and operational settings. |
| Backups | Retained as necessary for backups, redundancy, and disaster recovery. | Deletion from backups may lag behind ordinary deletion processing. Specific methods and periods follow operational design. |
| Support history | Retained as necessary for inquiry response, contract management, incident investigation, and dispute handling. | Materials and logs included in support requests are retained to the extent necessary for the relevant purpose. |
Orphan uploaded data not associated with analysis, such as where a user leaves before starting analysis, may be deleted within a short period.
For the on-premises / customer environment version, retention periods for uploaded data, findings, scores, summaries, reports, logs, audit logs, backups, and other data follow the user environment settings and user operations unless otherwise provided in an individual agreement. Data, logs, configuration information, and other materials obtained by us for support, maintenance, incident investigation, or other purposes are retained only for the period necessary for that purpose and deleted or made unavailable when no longer necessary.
Retention periods may be extended to the extent necessary due to individual agreements, laws, dispute handling, misuse investigations, security response, accounting, contract management, audit response, or other legitimate reasons.
9. Deletion
Users may be able to request or perform deletion of uploaded data, detailed data generated through analysis, findings, reports, and other data through FirstLook features or methods designated by us.
In the cloud-provided version, we delete, archive, aggregate, or make target data unavailable in accordance with user deletion operations, contract termination, individual agreements, expiration of retention periods, or our operational settings.
Uploaded data bodies, extracted events, intermediate analysis data, analysis target metadata, and other detailed data may be deleted, archived, aggregated, or made unavailable after analysis completion or after a certain period in accordance with the retention policy in the preceding section.
Findings, scores, summaries, reports, and other outputs presented to users may be retained during the contract term or until deleted by the user. If a user deletes a case, report, or related data, we will delete or make unavailable the uploaded data bodies, detailed data, findings, reports, and other related data included in the deletion target.
Even after deletion operations or contract termination, operation / audit logs, external API usage logs, billing / credit usage history, contract records, support history, backups, security response records, and other data necessary for laws, accounting, audit, misuse investigation, dispute handling, contract management, or security may be retained to the extent necessary.
Backup, redundancy, disaster recovery, and other operationally necessary replicated data will be deleted or overwritten after ordinary deletion processing in accordance with our backup rotation, retention periods, and recovery procedures. Deletion from backups may therefore lag behind ordinary deletion processing.
For the on-premises / customer environment version, data deletion, backup deletion, log deletion, contract-end data erasure, and other deletion procedures follow the user environment settings and user operations unless otherwise provided in an individual agreement. Data obtained by us for support, maintenance, incident investigation, or other purposes will be deleted or made unavailable after the period necessary for that purpose has elapsed.
10. Quality Improvement and Statistical Use
We may use data for providing FirstLook, analysis processing, report generation, support, security, quality improvement, product improvement, feature improvement, operational improvement, statistical analysis, and related purposes.
If information is used in public materials, sales materials, training materials, case studies, or other third-party-facing materials in a form that identifies an individual, company, organization, customer, or matter, we will obtain separate consent from the user.
We may use statistical information, trend information, and other information that cannot identify individuals or organizations for product improvement, internal analysis, explanatory materials, sales materials, investor materials, and other purposes.
11. Security Measures
We will endeavor to implement reasonable safeguards in providing FirstLook. Examples of measures include the following.
- Authentication and authorization management
- Tenant separation
- Access control
- Encryption in transit
- Protection of stored data
- Operation / audit logs
- Monitoring of misuse and excessive load
- Vulnerability response
- Backups
- Safe handling of dangerous data
We may consider ISMS, SOC 2 Type II, or other certifications or audits in the future. However, this Policy does not guarantee any specific certification, audit result, service level, or absence of incidents at present.
12. User Responsibilities
Users are responsible for the following.
- Ensuring authority, contractual basis, customer explanations, and internal approvals for handling uploaded data.
- Not uploading personal information, credentials, confidential information, or dangerous data unnecessary for analysis.
- Reviewing FirstLook findings, scores, summaries, reports, and other outputs presented to users as reference information rather than final determinations, and conducting expert confirmation, supplemental investigation, or correction as necessary.
- If submitting reports to customers, auditors, insurers, law enforcement, regulators, or other third parties, reviewing the contents and being accountable to the recipient.
- If an MSSP, DFIR vendor, consultant, or other third party uses FirstLook on behalf of a customer, obtaining necessary authority from the customer and ensuring compliance with this Policy, the Terms of Use, and individual agreements.
13. Revisions
We may revise this Policy in response to changes to FirstLook features, external services, laws, contract terms, security measures, or other circumstances. For material changes, we will notify users by notice within FirstLook, email, website posting, or other appropriate means, and will request renewed user consent where necessary.
