トラストセンターに戻る

脆弱性開示

Version: v1.0 | Last Updated: January 2026

脆弱性開示ポリシー

SimplyPNGのセキュリティ維持にご協力いただくセキュリティ研究コミュニティの皆様に感謝いたします。

How to Report

Please send vulnerability reports to:

security@simplypng.app

Please include as much detail as possible to help us understand and reproduce the issue.

What to Include in Your Report

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any proof-of-concept code or screenshots
  • Your contact information for follow-up

対応時間

24 hours
Initial acknowledgment of your report
72 hours
Initial assessment and triage
14 days
Target for remediation (may vary based on severity and complexity)

セーフハーバー

善意で脆弱性を報告し、責任ある開示慣行に従う研究者に対して法的措置を取ることはありません。

  • Make good faith efforts to avoid privacy violations and data destruction
  • Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
  • Give us reasonable time to address the issue before public disclosure
  • Do not access or modify data belonging to other users

対象外

The following are generally considered out of scope:

  • • Denial of service attacks
  • • Social engineering attacks against our employees
  • • Physical attacks against our infrastructure
  • • Issues in third-party applications or services we use
  • • Spam or social engineering techniques
  • • Missing security headers that don't lead to exploitable vulnerabilities
  • • Rate limiting or brute force issues on non-authentication endpoints

Bug Bounty Program

We do not currently offer a formal bug bounty program with monetary rewards. However, we deeply appreciate responsible disclosure and will acknowledge researchers who help us improve our security (with permission).

A formal bug bounty program may be considered in the future as the company grows.

Questions about this policy? Contact our security team