Skip to main content
Talk to Sales

Security & Compliance

The standard for Japan's most regulated industries.

Banks and financial institutions adopt generative AI only when they can answer the hard questions: where does the data live, who can reach it, and how is it audited? This page documents how Tara Cloud answers them — engineered into the platform, not bolted on.

Talk to our team

Detailed documentation — security questionnaire responses, audit reports, and BCP plans — is available under NDA.

Data residency

Your data never leaves Japan — on Tara Cloud-hosted infrastructure.

On Tara Cloud-hosted infrastructure, GPU compute, open-weight LLM inference, and all customer data are processed and stored in Japan. Frontier models (OpenAI, Anthropic) are served through the vendors' official APIs; their inference may occur outside Japan — see the LLM API Endpoint page for details.

For regulated workloads, there is no cross-border transfer — a contractual commitment, not a configuration option.

Tara Cloud-hosted GPUs in Japan

Training and inference compute runs on Tara Cloud-hosted infrastructure physically located in Japan.

Open-weight LLM inference in Japan

Open-weight model inference is processed on Japanese endpoints and stays in the country.

Customer data stored in Japan

Customer data is stored and processed within Japanese borders on Tara Cloud-hosted services.

Data handling

Your data is used only to serve your business — never to train models.

Tara Cloud makes explicit, contractual commitments about how customer data is handled across every service line.

Never used for training

Customer data — prompts, completions, and artifacts — is never used to train or fine-tune shared models.

Zero-retention mode

LLM API traffic can be processed in zero-retention mode, where nothing is logged or persisted.

Documented deletion

On contract termination, data deletion follows a documented, executed procedure with attestation.

Tenant isolation

Dedicated infrastructure. No shared compromise.

Regulated workloads run on infrastructure that is exclusively yours.

Single-tenant environments

Regulated workloads run on dedicated, single-tenant GPU environments.

Private networking

VPC peering and private endpoints connect your systems without traversing the public internet.

No shared infrastructure

Regulated workloads share no compute, storage, or network resources with other customers.

Security architecture

Defense in depth, documented.

Every layer of the platform is engineered and monitored to an institutional standard.

Encryption in transit

TLS 1.2 or higher on every connection.

Encryption at rest

AES-256 for all stored customer data.

Network segmentation

Workloads isolated by security zone and policy.

Multi-factor authentication

MFA required for all administrative access.

SSO / SAML

Enterprise identity federation for your team.

Role-based access control

Least-privilege access for every user and role.

Auditability

Every action leaves a record.

Your security team should never have to wonder what happened in your environment. Tara Cloud records it.

Full audit logging

Infrastructure and API activity are logged end to end, from provisioning to inference.

SIEM export

Logs export to your SIEM for correlation, alerting, and investigation.

Tamper-evident storage

Audit records are protected against modification and deletion.

Compliance posture

Registered. Assessed. Aligned.

Our security program is validated against international and Japanese frameworks. Reports are available under NDA.

Registered

ISO 27001

Information security management system registered to ISO/IEC 27001.

Registered

SOC 2 Type II

Independently audited SOC 2 Type II report available under NDA.

Registered

ISMAP

Registered with Japan's Information system Security Management and Assessment Program.

Compliant

APPI

Personal information handling aligned with Japan's Act on the Protection of Personal Information.

Aligned

FISC Safety Guidelines

Architecture aligned with the safety guidelines of the Center for Financial Industry Information Systems.

Resilience

Built to stay up. Built to recover.

Availability is a security property. Your workloads are designed for continuity in every scenario.

In-Japan redundancy

Compute is distributed across redundant availability zones within Japan.

Documented BCP

A business continuity plan defines recovery targets and procedures for every service.

Shared under NDA

Specific RTO and RPO commitments are shared with customers under NDA.

A named team aligned to your business hours.

Support that operates like a partner — reachable, accountable, and Japanese-language fluent.

  • 24/7 support under enterprise agreements

    Enterprise agreements include 24/7 Japanese-language support, with English available on request.

  • Named technical account manager

    A dedicated technical account manager who knows your environment and your roadmap.

  • Incident SLAs

    Contractual incident-response commitments, monitored and reported.

Built for institutional procurement.

The documentation your vendor assessment and legal teams need — ready when you are.

  • Security questionnaires

    Detailed responses to your vendor security assessment, on your schedule.

  • Enterprise MSA

    A master services agreement structured for institutional buyers.

  • Insurance documentation

    Certificates of insurance available on request.

Put your security team at ease.

Tell us about your workloads, data requirements, and compliance constraints. A senior security engineer will respond within one business day.