1. Reporting a vulnerability
Use the private security-report channel with the subject Security report: [product name]. Include the affected product and version, potential impact, safe reproduction steps, and whether any customer data may be involved. Do not create a public issue or include credentials, access tokens, private identifiers, confidential customer content, or live customer data. We will arrange a safer method if sensitive evidence is necessary.
2. Testing boundaries
Use only accounts, sites, projects, workspaces, and data you own or are expressly authorized to test. Keep testing proportionate and minimize access, modification, and retention. Stop immediately and report privately if you encounter another person’s data or gain unintended access.
Do not perform denial-of-service or load testing, social engineering, phishing, malware delivery, physical attacks, credential attacks, destructive testing, privacy violations, data exfiltration, or testing against a customer production environment without written authorization. Do not publicly disclose a suspected issue before the Provider has had a reasonable opportunity to investigate and remediate it. These guidelines do not authorize conduct that is unlawful or prohibited by a hosting, distribution, or other applicable agreement.
3. Common security baseline
- Use the minimum permissions and data necessary for documented functionality.
- Prefer platform-hosted or first-party processing where practical, and disclose product-specific hosting, external connections, and service providers.
- Keep credentials and confidential customer content out of operational logs and ordinary support messages.
- Use dependency pinning, automated verification, code review, and release checks proportionate to the product and its risk.
- Investigate credible reports and provide security fixes or mitigations according to severity, feasibility, and applicable contractual or platform obligations.
Only supported versions obtained through an official distribution channel are covered unless product documentation expressly says otherwise.
4. Response and remediation
Reports are reviewed in Japanese on a reasonable-efforts basis, primarily on Japan business days. We may acknowledge, request more information, reproduce, assess severity, prepare a fix or mitigation, and coordinate disclosure. Security and data-integrity risks are prioritized when reasonably possible, but no acknowledgement, remediation, release, recovery, or disclosure timeline is guaranteed. Product-specific documentation may state a non-binding target.
There is no monetary bug-bounty or reward program unless agreed in writing before testing. Submission of a report does not create a contract, employment relationship, entitlement to payment, or obligation to publish credit.
5. Security limitations
No software, hosting platform, transmission, or storage method is completely secure. This policy is not a certification, audit report, warranty, insurance commitment, safe-harbor promise, or representation of participation in any vendor trust, bug-bounty, or certification program unless a product’s current documentation expressly says so. Service use remains subject to the Product Terms.