AgreePack Trust Center
Review verifiable information about AgreePack security, data handling, reliability, and incident response. Active controls are clearly distinguished from work in progress, with a visible review date.
Trust at a glance
A concise view of the information commonly used for vendor review and service-adoption decisions.
Related documents
Open the public documents commonly needed for security review and adoption decisions.
Current implementation status
This page reports verifiable operating facts and does not imply a certification or independent assessment that has not been completed.
External availability monitoring
The landing page, login page, application, and database health endpoint are monitored externally.
Database backups
Daily production backups are confirmed and successful runs are recorded by an external heartbeat.
Restore testing
The backup restore procedure has been verified. Last verified: 2026.08.15
Incident and maintenance communications
Targets are defined for initial, ongoing, and resolved incident notices.
Dedicated security contact
A dedicated address is available for reporting vulnerabilities and unintended data exposure.
Independent security assessment
An independent web application vulnerability assessment has not yet been completed. Scope and quotation requirements are being prepared.
Data and security
The information processed by the service and the safeguards currently implemented.
Data handling
Data is handled only as necessary to provide the service. See the Privacy Policy for details.
- Account, workspace, uploaded document, and document-version information is processed.
- Information entered by consent recipients, consent time, IP address, and user-agent data may be stored as consent records.
- Important actions such as document updates, permission changes, and evidence-pack exports are recorded in audit logs.
- Data handling after cancellation, purposes of use, and third-party disclosures follow the Terms and Privacy Policy.
- AgreePack does not describe all stored data as encrypted unless the applicable method and scope have been verified.
Security controls
- HTTPS for browser-to-service communications
- Passwords stored using a non-reversible method
- Workspace membership and role-based access control
- Separation of customer and operator functions
- Rate limits for login, password reset, and public consent actions
- Security headers on public consent pages
- Extension and MIME validation plus a virus-scanning mechanism for PDF uploads
- Recording and alerting for exceptions, failed jobs, and mail-delivery failures
Reliability and incident response
Backup, recovery verification, and communication practices for incidents and maintenance.
Reliability and backups
The database is configured for daily backup at 04:10 UTC with 30-day retention. Successful runs send an external heartbeat.
Last restore test: 2026.08.15
External monitoring history is published on the service-status page.
Backups improve the ability to recover from failures but do not guarantee complete restoration in every situation. Export and retain important records such as evidence packs as appropriate.
Incident and maintenance notices
These are communication targets, not an SLA. Safe recovery and accurate impact assessment take priority.
- Broad service outage: initial notice targeted within 60 minutes after impact is confirmed
- Major degradation or partial outage: initial notice targeted within 120 minutes after impact is confirmed
- Ongoing major incident: update every 120 minutes or when material progress occurs
- Planned maintenance: normally announced at least 3 business days in advance; emergency work may be announced later
- A resolution notice is posted after recovery is confirmed, with cause and preventive action added when appropriate
Operations and service providers
Operator details, key external service providers, and open improvement items.
Operator and service
AgreePack is a consent collection and evidence management SaaS developed and operated by Tsugaru Design Studio.
- Operator
- Tsugaru Design Studio
- Service
- AgreePack (consent collection and evidence management SaaS)
- Location
- Aomori City, Aomori, Japan
- Contact
- [email protected]
Key service providers
The following external services are used as necessary to provide AgreePack. This page is updated when the service architecture changes.
Open items and planned improvements
Items in progress are not represented as completed. This page will be updated as their status changes.
- Complete an independent web application vulnerability assessment and post-remediation retest
Report a security issue
If you discover a vulnerability, unintended data exposure, or signs of unauthorized access, contact the dedicated address below.
Include the affected URL, time observed, reproduction steps, and potential impact where possible. Do not access additional real data or modify data.
View security.txt