セキュリティ責任者 / Security Lead
綿村 一彦 / Kazuhiko Watamura
株式会社gotton(pricetarの開発・運用・セキュリティを担当)
pricetarのセキュリティは株式会社gottonが担当しています。
The security of pricetar is managed by Gotton Inc.
脆弱性の報告 / Reporting a Vulnerability
pricetarのセキュリティ上の問題を見つけた場合は、下記までご連絡ください。
If you believe you have found a security vulnerability in pricetar, please contact us at:
security@gotton.net
報告には、可能な範囲で次の内容を含めてください。
- 問題の概要と影響
- 再現手順
- 対象のURLや機能
- 連絡先
Please include, where possible: a description and impact, steps to reproduce, affected URLs or features, and your contact information.
対応方針 / Our Commitment
- 報告の受領を、3営業日以内にお知らせします。
- 調査の結果と対応の見込みを、順次ご連絡します。
- 修正が完了するまで、問題の公表は控えていただくようお願いします。公表の時期はご相談のうえで決めます。
- 本方針に沿って誠実に行われた報告については、報告者に対して法的措置をとりません。
- We will acknowledge your report within 3 business days.
- We will keep you informed of our investigation and remediation progress.
- We ask that you refrain from public disclosure until the issue has been fixed, and we will coordinate disclosure timing with you.
- We will not pursue legal action against researchers who report vulnerabilities in good faith in accordance with this policy.
禁止事項 / Please Do Not
- 他のユーザーのデータへのアクセス、変更、削除
- サービスの運用を妨げる行為(DoS攻撃、大量のリクエストなど)
- ソーシャルエンジニアリングや物理的な攻撃
- 確認に必要な範囲を超える調査
- Access, modify, or delete other users' data
- Disrupt the service (e.g., denial-of-service or high-volume automated requests)
- Use social engineering or physical attacks
- Go beyond what is necessary to demonstrate the issue
報奨金について / Rewards
現在、報奨金制度(バグバウンティ)は設けていません。
We do not currently operate a paid bug bounty program.