AGREEPACK / TRUST CENTER

AgreePack Trust Center

Review verifiable information about AgreePack security, data handling, reliability, and incident response. Active controls are clearly distinguished from work in progress, with a visible review date.

Operated by Tsugaru Design Studio Last reviewed: 2026.08.15
OVERVIEW

Trust at a glance

A concise view of the information commonly used for vendor review and service-adoption decisions.

Operator Tsugaru Design Studio
Active or published 5 of 6 controls
Service-status page Published externally
Last reviewed 2026.08.15
POLICIES & RESOURCES

Related documents

Open the public documents commonly needed for security review and adoption decisions.

CURRENT CONTROLS

Current implementation status

This page reports verifiable operating facts and does not imply a certification or independent assessment that has not been completed.

Active or published

External availability monitoring

The landing page, login page, application, and database health endpoint are monitored externally.

Active or published

Database backups

Daily production backups are confirmed and successful runs are recorded by an external heartbeat.

Active or published

Restore testing

The backup restore procedure has been verified. Last verified: 2026.08.15

Active or published

Incident and maintenance communications

Targets are defined for initial, ongoing, and resolved incident notices.

Active or published

Dedicated security contact

A dedicated address is available for reporting vulnerabilities and unintended data exposure.

In preparation

Independent security assessment

An independent web application vulnerability assessment has not yet been completed. Scope and quotation requirements are being prepared.

DATA & SECURITY

Data and security

The information processed by the service and the safeguards currently implemented.

Data handling

Data is handled only as necessary to provide the service. See the Privacy Policy for details.

  • Account, workspace, uploaded document, and document-version information is processed.
  • Information entered by consent recipients, consent time, IP address, and user-agent data may be stored as consent records.
  • Important actions such as document updates, permission changes, and evidence-pack exports are recorded in audit logs.
  • Data handling after cancellation, purposes of use, and third-party disclosures follow the Terms and Privacy Policy.
  • AgreePack does not describe all stored data as encrypted unless the applicable method and scope have been verified.

Security controls

  • HTTPS for browser-to-service communications
  • Passwords stored using a non-reversible method
  • Workspace membership and role-based access control
  • Separation of customer and operator functions
  • Rate limits for login, password reset, and public consent actions
  • Security headers on public consent pages
  • Extension and MIME validation plus a virus-scanning mechanism for PDF uploads
  • Recording and alerting for exceptions, failed jobs, and mail-delivery failures
RELIABILITY

Reliability and incident response

Backup, recovery verification, and communication practices for incidents and maintenance.

Reliability and backups

The database is configured for daily backup at 04:10 UTC with 30-day retention. Successful runs send an external heartbeat.

Last restore test: 2026.08.15

External monitoring history is published on the service-status page.

Backups improve the ability to recover from failures but do not guarantee complete restoration in every situation. Export and retain important records such as evidence packs as appropriate.

Incident and maintenance notices

These are communication targets, not an SLA. Safe recovery and accurate impact assessment take priority.

  • Broad service outage: initial notice targeted within 60 minutes after impact is confirmed
  • Major degradation or partial outage: initial notice targeted within 120 minutes after impact is confirmed
  • Ongoing major incident: update every 120 minutes or when material progress occurs
  • Planned maintenance: normally announced at least 3 business days in advance; emergency work may be announced later
  • A resolution notice is posted after recovery is confirmed, with cause and preventive action added when appropriate
Investigating Identified / working on a fix Monitoring after recovery Resolved
OPERATIONS

Operations and service providers

Operator details, key external service providers, and open improvement items.

Operator and service

AgreePack is a consent collection and evidence management SaaS developed and operated by Tsugaru Design Studio.

Operator
Tsugaru Design Studio
Service
AgreePack (consent collection and evidence management SaaS)
Location
Aomori City, Aomori, Japan

Key service providers

The following external services are used as necessary to provide AgreePack. This page is updated when the service architecture changes.

Sakura Internet Inc. Japan-hosted VPS, network, and infrastructure
Cloudflare DNS, reverse proxy, CDN, WAF, and DDoS mitigation
Stripe paid-plan payment, billing, and subscription management
Resend authentication and notification email delivery
Sentry error and incident detection and investigation
UptimeRobot external monitoring of public endpoints and scheduled tasks, plus the service-status page
Google Analytics public website usage analytics

Open items and planned improvements

Items in progress are not represented as completed. This page will be updated as their status changes.

  • Complete an independent web application vulnerability assessment and post-remediation retest
SECURITY CONTACT

Report a security issue

If you discover a vulnerability, unintended data exposure, or signs of unauthorized access, contact the dedicated address below.

Include the affected URL, time observed, reproduction steps, and potential impact where possible. Do not access additional real data or modify data.

View security.txt