MONJI+

User Support

Your go-to support page for troubleshooting and getting the most out of MONJI+

Vulnerability Disclosure Policy

ALAKI Inc. (“we”, “our”, or “us”) accepts vulnerability reports to improve the security of MONJI, MONJI+, and all related websites, applications, APIs, and information systems operated by us.
We respect responsible disclosure made in good faith and will review and respond to reports submitted in accordance with this policy within a reasonable scope.

1. Reporting Channel

Please report vulnerabilities through the following dedicated contact:
To avoid delays, please do not use other channels (such as contact forms, sales channels, social media, or third parties).

2. Scope

This policy applies to assets operated and managed by us, including:
  • Websites under the monji.tech domain
  • MONJI
  • MONJI+
  • Production web applications, APIs, and admin panels provided by us
The following may be considered out of scope:
  • Third-party services not controlled by us
  • Services managed independently by external vendors
  • Test, development, or non-public environments
  • Any assets we reasonably determine to be out of scope

3. Required Information

When submitting a report, please provide as much of the following information as possible:
  • Affected URL, screen, feature, or API endpoint
  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Non-destructive proof of concept (PoC) or references
  • Date and time of discovery
  • Contact information
  • Whether any data belonging to us, users, or third parties was accessed, and if so, details of such access
Incomplete reports may delay investigation and response.

4. Allowed Testing

Testing is permitted only under the following conditions:
  • Use only accounts you own or control
  • Do not impact other users or third parties
  • Limit testing to the minimum necessary to confirm the vulnerability
  • If you access personal or sensitive data, stop immediately and report it

5. Confidentiality and Disclosure

We follow a coordinated disclosure approach.
Do not disclose or share any vulnerability details with third parties until we have provided a fix or mitigation, or until a mutually agreed disclosure date.
We may request additional information or assistance as needed.

6. Prohibited Activities

The following activities are strictly prohibited:
  • Accessing, retrieving, modifying, deleting, retaining, or disclosing data belonging to us, users, or third parties
  • Attempting privilege escalation
  • Bypassing authentication, session hijacking, or account takeover
  • Causing service disruption, degradation, or excessive load
  • Destructive scanning or excessive automated access
  • Social engineering, phishing, impersonation, or physical attacks
  • Uploading, distributing, or executing malware
  • Spam, abuse of forms, or mass submissions
  • Violating laws, contracts, or third-party rights
  • Disclosing vulnerability information without prior written approval or agreed disclosure timing
  • Any other activity we deem inappropriate
All testing must be non-destructive and limited to the minimum required.

7. Our Response

We aim to:
  • Acknowledge receipt within 7 business days
  • Review and triage the report
  • Request additional information if needed
  • Take appropriate remediation or mitigation actions
  • Notify you upon completion when appropriate
Response times may vary depending on complexity and volume.

8. No Reward

We do not provide any rewards, compensation, reimbursements, or any form of monetary payment for vulnerability reports.
By submitting a report, you agree that:
  • Your report is provided voluntarily and without expectation of compensation
  • You will not claim or request any fees, damages, or compensation
  • We are not liable for any costs, losses, or damages related to your report
  • You will not request payment unless explicitly agreed in writing in advance

9. Disclaimer and Rights

This policy does not grant permission for unrestricted testing, access, intrusion, data extraction, or load testing.
We reserve the right to take appropriate action against violations of this policy, illegal activities, or actions that may cause harm to us or third parties.
We do not grant any authorization or protection regarding third-party systems or services.

10. Acknowledgment

We appreciate responsible disclosure made in good faith. With your consent, we may acknowledge your contribution.

11. Changes

We may update this policy at any time without prior notice. The latest version will be published on this page.

12. Safe Harbor

If you act in good faith, follow this policy, and stay within the defined scope, we will not pursue legal action against you.
However, this does not apply to violations of this policy, malicious activities, or actions that impact third-party data or systems.
Last Updated: April 20, 2026