On-Demand Security Testingオンデマンド・セキュリティテスト

VAPT & Penetration TestingVAPT・侵入テスト

Comprehensive Vulnerability Assessment and Penetration Testing across your US and Japan operations — bilingual reporting, real manual testing, no false-positive padding.米国・日本両拠点にわたる包括的な脆弱性診断・侵入テスト。バイリンガルレポート、実際の手動テスト、誤検知の水増しなし。

Sound Familiar?こんなお悩みはありませんか?

If Any of This Is True Right Now今まさに、こんな状況ではありませんか

You're a CISO with a regulatory deadline inside 60 days, still building compliance documentation by hand.60日以内の規制対応期限が迫っているのに、コンプライアンス文書をまだ手作業で作成しているCISOの方。

Your security team is watching phishing campaigns impersonate your own brand, with no formal takedown process in place.自社ブランドを騙るフィッシングキャンペーンを目にしながら、正式なテイクダウン対応プロセスを持たないセキュリティチームの方。

You're trying to hire contract penetration testers and waiting weeks for vetted candidates to come through.契約ベースのペネトレーションテスターを採用しようとして、審査済み候補者が出てくるまで数週間も待っている方。

This is exactly what our on-demand model is built to fix.まさにこのような課題を解決するために、当社のオンデマンド型サービスは設計されています。

Overview概要

One Test, Two Regions, Zero Gaps1回のテストで、2つの地域を、抜け漏れなく

If your company operates in both the US and Japan, a security gap in one region can compromise your entire global posture. We conduct thorough Vulnerability Assessment and Penetration Testing (VAPT) across your US headquarters and Japan subsidiary environments — testing web applications, APIs, mobile apps, and network infrastructure for real-world vulnerabilities, with a detailed, actionable remediation roadmap delivered in both English and Japanese.貴社が米国と日本の両方で事業を展開している場合、一方の地域のセキュリティギャップが、グローバル全体のセキュリティ態勢を損なう可能性があります。当社は、米国本社と日本子会社の環境全体にわたる徹底的な脆弱性診断・侵入テスト(VAPT)を実施します。Webアプリケーション、API、モバイルアプリ、ネットワークインフラを対象に実際の脆弱性を検証し、英語・日本語両方で具体的な改善ロードマップをご提供します。

Unlike many providers, we don't rely on automated scanning alone — every engagement combines automated tooling with genuine manual penetration testing to avoid false positives and surface the vulnerabilities that actually matter.多くのプロバイダーとは異なり、自動スキャンのみに依存することはありません。すべての案件において、自動化ツールと実際の手動侵入テストを組み合わせ、誤検知を避けながら本当に重要な脆弱性を明らかにします。

Automated + manual vulnerability scanning自動+手動による脆弱性スキャン
Real-world penetration testing, not just scan outputスキャン結果だけでない、実際の侵入テスト
Executive summary + technical report with remediation stepsエグゼクティブサマリー+改善策を含む技術レポート
Post-remediation retest validation included改善後の再テスト検証を含む
Bilingual report (English + Japanese)バイリンガルレポート(英語・日本語)
Compliance mapping available (CMMC, DFARS, SEC, APPI)コンプライアンスマッピング対応(CMMC、DFARS、SEC、APPI)
Pricing料金

VAPT Pricing TiersVAPT料金プラン

TierPrice (USD)Price (JPY, approx.)What's Included
Standard$12,000¥1,800,000Single web app or API test (US or Japan). 5–7 business days. Automated + manual testing. Detailed report with remediation. Retest included.
Premium$25,000¥3,750,000Full-scope VAPT across both US and Japan environments. Web apps, APIs, mobile, and internal network. 10–15 business days. Bilingual executive and technical reports. Retest included.
EnterpriseQuote-based要見積りRed team exercise or enterprise-wide assessment. Custom scope. Compliance mapping (CMMC, DFARS, SEC, and others).
Add-on: Annual Retainer (3 tests/year)追加オプション:年間リテイナー(年3回)
$30,600/year (¥4,590,000/年) — Premium tier, 15% savings
Add-on: Japan-Only Assessment追加オプション:日本限定アセスメント
$8,000 (¥1,200,000) Standard / $18,000 (¥2,700,000) Premium
Who This Is For対象となる企業様

US companies with Japan subsidiaries needing unified security testing across both regions — particularly useful ahead of compliance audits and investor due diligence.両地域にわたる統一的なセキュリティテストを必要とする、日本子会社を持つ米国企業様。特にコンプライアンス監査や投資家によるデューデリジェンスの前に有用です。

JPY figures shown are approximate conversions at ¥150/$1 for reference only — actual invoicing currency and final scope-based pricing are confirmed in writing before any engagement begins.表示されている円換算額は、参考として1ドル=¥150で算出した概算です。実際の請求通貨および最終的なスコープに基づく料金は、契約開始前に書面にてご確認いただきます。

FAQよくある質問

Common Questionsよくあるご質問

How long does the assessment take?アセスメントにはどのくらいの期間がかかりますか?

Standard tier: 5–7 business days. Premium tier: 10–15 business days.スタンダードプラン:5〜7営業日。プレミアムプラン:10〜15営業日。

Do you provide a retest after remediation?改善後の再テストは提供されますか?

Yes — we retest all identified vulnerabilities after remediation, included in both Standard and Premium tiers.はい。改善後、特定されたすべての脆弱性を再テストいたします。スタンダード・プレミアム両プランに含まれます。

What compliance standards do you map to?どのコンプライアンス基準にマッピング対応していますか?

CMMC, DFARS, ITAR, SEC rules, APPI (Japan's privacy law), ISO 27001, and NIST CSF.CMMC、DFARS、ITAR、SEC規則、APPI(日本の個人情報保護法)、ISO 27001、NIST CSFに対応しています。

Is this automated scanning, or genuine manual testing?これは自動スキャンですか、それとも実際の手動テストですか?

Both — every engagement combines automated tooling with manual penetration testing performed by our team, avoiding the false positives that pure automated scans often produce.両方です。すべての案件で、自動化ツールと当社チームによる手動侵入テストを組み合わせ、自動スキャンのみでは生じやすい誤検知を回避します。

Can you test both our US and Japan environments in one engagement?1回の案件で米国・日本両方の環境をテストできますか?

Yes — this is specifically what the Premium tier is built for, with bilingual reporting covering both regions.はい。まさにこのためにプレミアムプランが設計されており、両地域を対象とするバイリンガルレポートをご提供します。

How quickly can we get started?どのくらいのスピードで開始できますか?

Book a 30-minute sync directly — we'll confirm scope and can typically begin within days of a signed agreement, not weeks.直接30分の相談をご予約ください。スコープを確認の上、契約締結後は通常数週間ではなく数日以内に開始可能です。

Do you offer a red team exercise instead of standard VAPT?標準的なVAPTではなく、レッドチーム演習の提供はありますか?

Yes — this is scoped under our Enterprise tier, with custom scope and compliance mapping tailored to your organization.はい。エンタープライズプランにて、貴社の組織に合わせたカスタムスコープとコンプライアンスマッピングでご提供します。

Is pricing negotiable for multi-year engagements?複数年契約の場合、料金交渉は可能ですか?

Ask us directly — our Annual Retainer add-on already reflects a 15% savings versus one-off Premium engagements, and further multi-year terms can be discussed.直接ご相談ください。年間リテイナーの追加オプションは、単発のプレミアム案件と比較して既に15%の割引を反映しており、複数年の条件についてもご相談可能です。

Next Step次のステップ

Book a 30-Minute Sync30分の相談を予約する

No lengthy sales process — a direct 30-minute call to understand your situation and confirm scope and pricing.長い営業プロセスは不要です。貴社の状況を理解し、スコープと料金を確認するための、直接的な30分間の通話です。

Book a 30-Min Sync30分の相談を予約

Prefer email? hello@globalaccessjapan.comメールでのご連絡は hello@globalaccessjapan.com