# RASENWATCH Security Vulnerability Disclosure # RFC 9116 (https://www.rfc-editor.org/rfc/rfc9116.html) Contact: mailto:santou.masaya@rasencorp.com Expires: 2027-04-27T00:00:00.000Z Preferred-Languages: ja, en Canonical: https://rasenwatch.com/.well-known/security.txt Canonical: https://rasenwatch.vercel.app/.well-known/security.txt # Reporting Guidelines (Japanese) # 脆弱性を発見された場合、上記のメールアドレスまでご連絡ください。 # 報告内容: 影響範囲・再現手順・影響を受ける URL や機能・PoC(可能であれば) # 公開前に修正できるよう、修正完了まで第三者への公開はお控えください。 # 善意の報告者に対して法的措置を取ることはありません。 # Reporting Guidelines (English) # If you discover a security vulnerability, please report it to the email above. # Include: scope, reproduction steps, affected URL or feature, PoC if available. # Please refrain from public disclosure until the issue is resolved. # We will not pursue legal action against good-faith researchers. # Out of Scope # - Social engineering against staff or users # - Physical attacks on data centers (managed by Google Cloud / Vercel) # - Denial of Service (DoS) attacks # - Reports from automated scanners without verified impact