Security Policy

Purpose

This Policy forms the basis of the information security approach of FOLIO Holdings Co., Ltd. (“Company”) and is intended to set forth fundamental concepts necessary for us to maintain and enhance our information security management.

Definitions

As used in this Policy, the following terms will have the definitions set forth below:

Information

“Information” means any and all information concerning business operations including trade secrets, information on customers and personnel affairs, and confidential information for information system operation such as passwords, and includes not only data stored in computer systems and electronic media, but also any and all data printed on paper and image and voice data.

Information System

The “information system” collectively refers to an integrated set of components that work together to process business tasks. It encompasses hardware of a computer system, such as the computer itself, ancillary equipment, terminal devices, and printers, as well as software, and network equipment, network software, circuits, and other devices for connecting computer systems.

Information Security

“Information security” means the assurance and maintenance of the confidentiality, integrity, and availability of information assets. i. “Confidentiality” means a condition in which only authorized users may access information assets. ii. “Integrity” means a condition in which the content of information assets is consistent and accurate without being altered or destroyed. iii. “Availability” means a condition in which authorized users may access information assets as necessary.

Applicable Scope

This Policy is applicable to all information assets owned by the Company, and to information assets of the Company, which will be handled by an outsourcee to which all or part of our business operations are outsourced.

Applicable Persons

This Policy is applicable to our employees, which means all persons engaged in the Company’s business operations, including directors, audit & supervisory board members, regular employees, part-timers, and temporary employees, and an outsourcing company’s employees who are engaged in the Company’s business operations within its office (collectively, “Employees, etc.”).

Management System

We will establish a management system to promote the maintenance and enhancement of our information security. The chief executive responsible for the implementation of information security measures will be the Representative Director.

Protection of Information Assets

Information assets are important assets and must be protected adequately since loss of their validity or reliability is highly likely to have a serious effect on corporate management. We will take necessary measures to eliminate the possibility of such information assets sustaining damage from various threats, such as malfunction, disaster, erroneous processing, unauthorized use, destruction, theft, and information leakage.

Management of Information Assets

We will manage information assets properly according to the level of importance, taking into account such factors as confidentiality, purpose of use, and effects of information leakage.

Formulation of Information Security Measures

In formulating information security measures, we will perform risk analyses and other assessments on our information assets based on which we will consider the effectiveness, cost-effectiveness, and easiness of implementation of such measures.

Training and Communication

We will ensure that all our Employees, etc. comply with this Policy and the rules and regulations set forth hereunder by providing training and communicating the importance of compliance to them.

Compliance Obligations

Our Employees, etc. will recognize the importance of information security management, and will comply with this Policy and the rules, regulations, and standards set forth hereunder.

Audits

The effectiveness and appropriateness of information security measures will be verified through voluntary inspections and internal audits, and through external audits as necessary.

Penalties

Any Employee, etc. who fails to comply with this Policy or any of the rules and regulations set forth hereunder may face disciplinary action under the Company’s working regulations or legal punishment.

Contact

You may report a security vulnerability or other problems with the Company’s security system via security@folio-sec.com.