Frequently asked questions

Short answers for the questions we hear from foreign-owned subsidiaries in Japan, vendors selling into Japanese enterprises, and the MSPs who serve them. If yours is not here, ask it in the message field of the star check form.

What is the SCS scheme?

Japan's supply-chain security evaluation scheme. METI (the Ministry of Economy, Trade and Industry) and the Cabinet Secretariat's National Cyber Office published the build policy on 27 March 2026; IPA (the Information-technology Promotion Agency) publishes the requirements. It rates a company's security posture in stars so that buyers can see it. ★1 and ★2 correspond to SECURITY ACTION, IPA's existing self-declaration. ★3 is a self-assessment with expert review: 26 requirements, 81 criteria, valid one year. ★4 is a third-party assessment plus technical testing: 43 requirements, 153 criteria, valid three years, with an on-site audit. Applications are expected to open around March 2027.

Is ★3 mandatory?

No law requires it. But large Japanese buyers are expected to name ★3 as a condition of doing business, so in practice the request arrives inside a vendor questionnaire or a contract renewal. If you sell into a Japanese enterprise's supply chain, or you are the Japan subsidiary of a foreign group, plan on being asked. ★3 wants months of records behind you, so the useful time to start is before applications open, not after.

We already have SOC 2 or ISO 27001. Do we still need ★3?

If a customer asks for ★3, a SOC 2 report is not what they asked for. The scheme has its own criteria and its own assessment; whether a particular customer will accept another framework instead is a question for that customer. The good news is that the evidence overlaps heavily. What you already collect for CC6, CC7 and CC8, or for Annex A, is most of what ★3's device-level requirements want. The control mapping shows where.

Is Kana itself SOC 2 certified?

No. Kana does not have a SOC 2 report or an ISO 27001 certificate to show you, and we will not imply one. What we publish is a mapping from the evidence the agent collects to SOC 2 Trust Services Criteria and ISO/IEC 27001:2022 Annex A controls, and the agent's queries themselves. Both are on the security and compliance page.

Does Kana replace CrowdStrike, Defender or our antivirus?

No. Existing protection stays. On the Evidence plan ($4 per device per month) the agent records whether malware protection is present and running, which is what the ★3 criteria want to see, and leaves your product alone. The Protection plan ($7) adds EPP and EDR, licensed from Endpoint Solutions, Inc. in the United States, for devices that have nothing.

Does it replace Intune or Jamf?

No. MDM stays: Intune, Jamf, CLOMO, or Apple Business, which Apple launched on 14 April 2026 with MDM included at no cost. Kana runs alongside it and puts the evidence layer on top.

Where is our data stored?

In Japan. Support and monitoring are in Japanese. An assessor, a customer or your own auditor can be given an assessor account to view the evidence without you exporting anything.

What does the agent collect, and can we see for ourselves?

Encryption state, screen lock, local accounts and privileges, patch state, installed software, malware protection status and device activity logs, once a day. The agent is built on osquery, and every query it runs is published as a config file. If a query is not in the file, the agent does not run it.

What do we hand the assessor?

The console screen or an exported PDF, with the evidence stored against each ★3 requirement. Or an account of their own. The register you used to keep by hand goes away.

What does it cost, and how do we pay?

The star check is free. Evidence is $4, Protection $7 and Monitored $13 per device per month, no minimum, annual or monthly. Prices on this site are in US dollars. If you buy through a channel partner, their name is on the invoice, not ours.

Can our MSP or reseller run this for us?

Yes. The console is free and multi-tenant; a partner loads as many customers as they like and invoices under their own name. If you already have an MSP in Japan, point them at the partner section. If you are the MSP: the free star check is the quote, and you do not need a demo.