Vulnerability Disclosure Policy
This Vulnerability Disclosure Policy applied from April 20, 2026 to September 17, 2026 (JST).
1. Reporting Channel
2. Scope
- Websites under the monji.tech domain
- MONJI
- MONJI+
- Production web applications, APIs, and admin panels provided by us
- Third-party services not controlled by us
- Services managed independently by external vendors
- Test, development, or non-public environments
- Any assets we reasonably determine to be out of scope
3. Required Information
- Affected URL, screen, feature, or API endpoint
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Non-destructive proof of concept (PoC) or references
- Date and time of discovery
- Contact information
- Whether any data belonging to us, users, or third parties was accessed, and if so, details of such access
4. Allowed Testing
- Use only accounts you own or control
- Do not impact other users or third parties
- Limit testing to the minimum necessary to confirm the vulnerability
- If you access personal or sensitive data, stop immediately and report it
5. Confidentiality and Disclosure
6. Prohibited Activities
- Accessing, retrieving, modifying, deleting, retaining, or disclosing data belonging to us, users, or third parties
- Attempting privilege escalation
- Bypassing authentication, session hijacking, or account takeover
- Causing service disruption, degradation, or excessive load
- Destructive scanning or excessive automated access
- Social engineering, phishing, impersonation, or physical attacks
- Uploading, distributing, or executing malware
- Spam, abuse of forms, or mass submissions
- Violating laws, contracts, or third-party rights
- Disclosing vulnerability information without prior written approval or agreed disclosure timing
- Any other activity we deem inappropriate
7. Our Response
- Acknowledge receipt within 7 business days
- Review and triage the report
- Request additional information if needed
- Take appropriate remediation or mitigation actions
- Notify you upon completion when appropriate
8. No Reward
- Your report is provided voluntarily and without expectation of compensation
- You will not claim or request any fees, damages, or compensation
- We are not liable for any costs, losses, or damages related to your report
- You will not request payment unless explicitly agreed in writing in advance
9. Disclaimer and Rights
10. Acknowledgment
11. Changes
12. Safe Harbor
Version History
- Version 1.0 — April 20, 2026 (JST), Established and effective
- Version 2.0 — September 18, 2026 (JST), Revised and effective