Please include as much detail as possible to help us understand and reproduce the issue.
What to Include in Your Report
A clear description of the vulnerability
Steps to reproduce the issue
Potential impact of the vulnerability
Any proof-of-concept code or screenshots
Your contact information for follow-up
対応時間
24 hours
Initial acknowledgment of your report
72 hours
Initial assessment and triage
14 days
Target for remediation (may vary based on severity and complexity)
セーフハーバー
善意で脆弱性を報告し、責任ある開示慣行に従う研究者に対して法的措置を取ることはありません。
✓Make good faith efforts to avoid privacy violations and data destruction
✓Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
✓Give us reasonable time to address the issue before public disclosure
✓Do not access or modify data belonging to other users
対象外
The following are generally considered out of scope:
• Denial of service attacks
• Social engineering attacks against our employees
• Physical attacks against our infrastructure
• Issues in third-party applications or services we use
• Spam or social engineering techniques
• Missing security headers that don't lead to exploitable vulnerabilities
• Rate limiting or brute force issues on non-authentication endpoints
Bug Bounty Program
We do not currently offer a formal bug bounty program with monetary rewards. However, we deeply appreciate responsible disclosure and will acknowledge researchers who help us improve our security (with permission).
A formal bug bounty program may be considered in the future as the company grows.