Last updated: July 16, 2026

FirstLook Data Handling Policy

The Japanese version of this page is the governing version. This English version and any other translation are provided for reference only. If there is any conflict or inconsistency between the Japanese version and a translation, the Japanese version prevails.

This Data Handling Policy (the "Policy") explains how Securious Lab G.K. handles data uploaded, entered, transmitted, or connected by users in FirstLook; findings, scores, summaries, reports, and other outputs generated by FirstLook and presented to users; operation logs; and other related data.

This Policy supplements the data handling, external service use, dangerous data, AI use, retention period, and deletion provisions set out in the FirstLook Terms of Use.

1. Basic Policy

  • FirstLook handles data only to the extent necessary to support incident investigation, log analysis, digital forensics, IOC matching, and report preparation.
  • Users must not upload personal information, credentials, decryption keys, excessively broad customer confidential information, or other highly sensitive data beyond the scope necessary for analysis.
  • We do not use uploaded data to train or improve general-purpose AI models or other third-party AI models.
  • As of the date this Policy is prepared, FirstLook's standard analysis functions do not send uploaded data to generative AI or LLM services for analysis.
  • When external services or external APIs are used, we will identify, as clearly as reasonably possible, the categories of data sent, the purpose of transmission, and the data that is not sent, and will limit transmission to the minimum necessary scope.
  • FirstLook accepts malware, suspicious files, exploit code, and other dangerous data only within the formats, handling methods, or analysis targets expressly supported by us.

2. Categories of Data Handled

FirstLook mainly handles the following categories of data.

CategoryExamplesMain Purposes
Account / contract informationUser names, email addresses, organization, permissions, contract planAuthentication, authorization, contract management, support
Uploaded dataLogs, events, artifacts, files, archives, IOCs, notesAnalysis, extraction, scoring, report generation
Analysis target metadataFile names, paths, hashes, timestamps, sizes, extensions, hostnames, IP addresses, domains, URLsDetection, correlation, IOC matching, threat intelligence lookups
Findings / outputsFindings, scores, detection reasons, summaries, reports, commentsDisplay to users, report preparation, review, quality confirmation
Operation / audit logsLogin, upload, viewing, editing, deletion, administrative actionsSecurity, audit, misuse investigation, support
System logsErrors, processing time, job status, resource usageOperations, incident investigation, performance improvement
FeedbackInquiries, correction requests, review commentsSupport, quality improvement, feature improvement

3. Data Minimization Requested of Users

Before uploading data to FirstLook, users must confirm the following.

  • The user has the necessary authority, contractual basis, internal approval, customer permission, or other lawful basis to handle the data to be uploaded.
  • The data does not contain personal information, credentials, decryption keys, private keys, API keys, passwords, tokens, or excessively broad customer confidential information that is unnecessary for the analysis purpose.
  • If customer data, entrusted data, or third-party data is handled, the user is responsible for determining whether the data may be brought into FirstLook, for providing required explanations, and for maintaining appropriate safeguards.
  • Data unnecessary for FirstLook analysis is excluded or minimized to the extent reasonably possible.

This Policy does not impose a uniform masking obligation on users. However, users should endeavor not to upload information that is unnecessary for the analysis purpose.

4. Handling of Dangerous Data and Malware

Due to the nature of incident investigation, FirstLook may handle suspicious files, malicious scripts, exploit code, executable files, malware-related data, and other potentially dangerous data.

At present, FirstLook primarily targets logs, artifacts, metadata, archives, IOCs, analysis target files, and related structured data. Malware bodies, exploit code, dangerous scripts, executable files, and other dangerous data may be uploaded only within the formats, handling methods, or analysis targets expressly supported by us.

When handling dangerous data, we will consider or implement safety measures such as static analysis, isolated processing, non-execution processing, size limits, timeouts, privilege separation, and other appropriate controls. Specific handling methods may vary depending on the feature, contract, environment, and specifications at the time of provision.

5. External Services and External APIs

FirstLook may use external services or external APIs to the extent necessary to provide the Service, including for analysis, IOC matching, threat intelligence lookups, cloud infrastructure, operational monitoring, support, and related purposes.

Depending on the type of external service and feature, hash values, IP addresses, domains, URLs, IOCs, detection attributes, scores, findings, summaries, parts of other outputs presented to users, log fragments or metadata, and technical logs necessary for service operations may be sent.

For external threat intelligence lookups, we generally send IOCs such as hash values, IP addresses, domains, and URLs. File names, file paths, log bodies, and file bodies are not sent for external threat intelligence lookup purposes except where an expressly described feature, or the user's explicit operation or consent, provides otherwise.

When using external services, we endeavor not to send data unnecessary for the relevant purpose. In particular, we generally do not send credentials, passwords, private keys, decryption keys, API keys, access tokens, personal information unnecessary for analysis, full text of customer confidential information, full content of malware bodies or executable files, or full bodies of logs, emails, documents, or similar content.

However, where the user explicitly requests an investigation, where an expressly described feature is used, where an individual agreement applies, or where an external service integration requires a different handling, we may handle the above data differently after providing separate explanation or obtaining consent as appropriate.

External Service List

Service TypeCandidates / ExamplesData That May Be SentCurrent Status
Cloud infrastructureGoogle Cloud Platform (GCP)Uploaded data, findings, scores, summaries, reports, system logs, operation / audit logsGenerally used in Japan regions
Threat intelligence / external reputationVirusTotal, AbuseIPDB, GreyNoise, AlienVault OTX, MalwareBazaar, ThreatFox, Hashlookup, Shodan, Netlas, Censys, SpamhausIOCs such as hash values, IP addresses, domains, URLs, and related metadataUsed only when the feature is enabled and necessary. May be temporarily disabled due to development or operational rate limits and API limits
IP / ASN / Geo informationip-api.comIP addressesUsed only when the feature is enabled and necessary
Monitoring / error collectionFirstLook's own internal functionsErrors, technical logs, operation metadata, job status, resource usagePerformed within FirstLook
Email / notificationsUndeterminedEmail addresses, notification contentTo be identified if formally used
Generative AI / LLMNot used by standard analysis functions at presentUploaded data is not sent by standard analysis functionsPolicy confirmed

6. AI / LLM and Model Training

As of the date this Policy is prepared, FirstLook's standard analysis functions do not send uploaded data to generative AI or LLM services for analysis.

We do not use uploaded data to train or improve general-purpose AI models or other third-party AI models.

If we later add AI, LLM, AI API, AI-based summarization, report generation, explanation generation, or similar functions as standard FirstLook features, we will specify the categories of data sent, destination, purpose of use, retention, whether model training is involved, opt-in / opt-out, and whether user consent is required in this Policy or an attachment.

7. Data Storage Location

FirstLook's data storage location and management responsibility differ depending on the form of provision.

When we provide FirstLook as a cloud service, FirstLook data is stored or processed in databases, storage, backups, monitoring infrastructure, and other systems on Google Cloud Platform (GCP) managed by us. The main storage region is generally within Japan.

For backups, redundancy, disaster recovery, monitoring, maintenance, and other operationally necessary processing, data may be replicated, temporarily stored, or processed within the same country or within cloud environments managed by us. Specific backup methods, retention periods, deletion reflection timing, and other operational details will be defined in this Policy, individual agreements, or related documents after operational design is finalized.

When FirstLook is provided as Docker containers or in another format in the user's on-premises environment, a cloud environment contracted by the user, or another environment designated by the user, uploaded data, findings, scores, summaries, reports, operation logs, audit logs, backups, and other data are generally stored or processed within that user environment.

In this case, unless otherwise provided in an individual agreement, the user is responsible for the infrastructure, network, storage, backups, access control, audit logs, deletion, physical security, cloud contracts, external connection control, and other management of the user environment. If we access the user environment or data for support, maintenance, incident investigation, updates, or other purposes, the scope, method, period, and permissions will follow the individual agreement, support terms, or the user's consent.

If, in the cloud-provided version or on-premises / customer environment version, provision to a third party located outside Japan, processing by an entrusted party located outside Japan, or storage in a region outside Japan becomes necessary, we will provide necessary explanations, contractual measures, and other appropriate responses in accordance with laws and individual agreements.

8. Data Retention Periods

FirstLook's data retention periods vary depending on the form of provision, contract terms, plan, feature, user settings, and our operational settings. If an individual agreement provides otherwise, the individual agreement prevails.

Data CategoryRetention PolicyNotes
Uploaded data bodiesRetained for the period necessary for analysis processing, reanalysis, review, incident investigation, and other Service provision purposes.As an initial operational guideline, the retention period is approximately one month after analysis completion or upload. After that period or after the relevant purpose ends, we may delete, archive, or make uploaded data bodies unavailable.
Extracted events, intermediate analysis data, analysis target metadata, and other detailed dataRetained for the period necessary for report generation, reanalysis, review, incident investigation, and other Service provision purposes.As an initial operational guideline, the retention period is approximately one month after analysis completion or generation. After that period or after the relevant purpose ends, we may delete, aggregate, archive, or make these detailed data unavailable.
Findings, scores, summaries, reports, and other outputs presented to usersRetained to the extent necessary for display to users, review, report output, support, and contractual purposes.May be retained during the contract term or until deleted by the user.
Operation / audit logsRetained for security, audit, misuse investigation, and support.The standard retention period is generally 730 days.
External API usage logsRetained for rate limiting, usage management, audit, and misuse investigation.Tenant, service used, usage count, and related information are recorded. Detailed retention periods follow operational settings.
Billing / credit usage historyRetained for billing, accounting, contract management, and audit.Even if a case, report, or job is deleted, usage history may be retained after deleting or anonymizing the reference destination.
System logs / errorsRetained for operational monitoring, incident investigation, performance improvement, and security.The retention period varies depending on log type and operational settings.
BackupsRetained as necessary for backups, redundancy, and disaster recovery.Deletion from backups may lag behind ordinary deletion processing. Specific methods and periods follow operational design.
Support historyRetained as necessary for inquiry response, contract management, incident investigation, and dispute handling.Materials and logs included in support requests are retained to the extent necessary for the relevant purpose.

Orphan uploaded data not associated with analysis, such as where a user leaves before starting analysis, may be deleted within a short period.

For the on-premises / customer environment version, retention periods for uploaded data, findings, scores, summaries, reports, logs, audit logs, backups, and other data follow the user environment settings and user operations unless otherwise provided in an individual agreement. Data, logs, configuration information, and other materials obtained by us for support, maintenance, incident investigation, or other purposes are retained only for the period necessary for that purpose and deleted or made unavailable when no longer necessary.

Retention periods may be extended to the extent necessary due to individual agreements, laws, dispute handling, misuse investigations, security response, accounting, contract management, audit response, or other legitimate reasons.

9. Deletion

Users may be able to request or perform deletion of uploaded data, detailed data generated through analysis, findings, reports, and other data through FirstLook features or methods designated by us.

In the cloud-provided version, we delete, archive, aggregate, or make target data unavailable in accordance with user deletion operations, contract termination, individual agreements, expiration of retention periods, or our operational settings.

Uploaded data bodies, extracted events, intermediate analysis data, analysis target metadata, and other detailed data may be deleted, archived, aggregated, or made unavailable after analysis completion or after a certain period in accordance with the retention policy in the preceding section.

Findings, scores, summaries, reports, and other outputs presented to users may be retained during the contract term or until deleted by the user. If a user deletes a case, report, or related data, we will delete or make unavailable the uploaded data bodies, detailed data, findings, reports, and other related data included in the deletion target.

Even after deletion operations or contract termination, operation / audit logs, external API usage logs, billing / credit usage history, contract records, support history, backups, security response records, and other data necessary for laws, accounting, audit, misuse investigation, dispute handling, contract management, or security may be retained to the extent necessary.

Backup, redundancy, disaster recovery, and other operationally necessary replicated data will be deleted or overwritten after ordinary deletion processing in accordance with our backup rotation, retention periods, and recovery procedures. Deletion from backups may therefore lag behind ordinary deletion processing.

For the on-premises / customer environment version, data deletion, backup deletion, log deletion, contract-end data erasure, and other deletion procedures follow the user environment settings and user operations unless otherwise provided in an individual agreement. Data obtained by us for support, maintenance, incident investigation, or other purposes will be deleted or made unavailable after the period necessary for that purpose has elapsed.

10. Quality Improvement and Statistical Use

We may use data for providing FirstLook, analysis processing, report generation, support, security, quality improvement, product improvement, feature improvement, operational improvement, statistical analysis, and related purposes.

If information is used in public materials, sales materials, training materials, case studies, or other third-party-facing materials in a form that identifies an individual, company, organization, customer, or matter, we will obtain separate consent from the user.

We may use statistical information, trend information, and other information that cannot identify individuals or organizations for product improvement, internal analysis, explanatory materials, sales materials, investor materials, and other purposes.

11. Security Measures

We will endeavor to implement reasonable safeguards in providing FirstLook. Examples of measures include the following.

  • Authentication and authorization management
  • Tenant separation
  • Access control
  • Encryption in transit
  • Protection of stored data
  • Operation / audit logs
  • Monitoring of misuse and excessive load
  • Vulnerability response
  • Backups
  • Safe handling of dangerous data

We may consider ISMS, SOC 2 Type II, or other certifications or audits in the future. However, this Policy does not guarantee any specific certification, audit result, service level, or absence of incidents at present.

12. User Responsibilities

Users are responsible for the following.

  • Ensuring authority, contractual basis, customer explanations, and internal approvals for handling uploaded data.
  • Not uploading personal information, credentials, confidential information, or dangerous data unnecessary for analysis.
  • Reviewing FirstLook findings, scores, summaries, reports, and other outputs presented to users as reference information rather than final determinations, and conducting expert confirmation, supplemental investigation, or correction as necessary.
  • If submitting reports to customers, auditors, insurers, law enforcement, regulators, or other third parties, reviewing the contents and being accountable to the recipient.
  • If an MSSP, DFIR vendor, consultant, or other third party uses FirstLook on behalf of a customer, obtaining necessary authority from the customer and ensuring compliance with this Policy, the Terms of Use, and individual agreements.

13. Revisions

We may revise this Policy in response to changes to FirstLook features, external services, laws, contract terms, security measures, or other circumstances. For material changes, we will notify users by notice within FirstLook, email, website posting, or other appropriate means, and will request renewed user consent where necessary.