Security Policy
Vulnerability Disclosure Policy
This English version is provided for convenience. If there is any discrepancy, the Japanese version prevails.
Delight, Inc. ("we") accepts vulnerability reports from outside researchers and users to improve the security of Agentino (the "Service"). This policy defines how to report, how we respond, and the conditions under which reporters are protected.
1. Scope
https://agentinos.app(this site)https://console.agentinos.app(the Service application)https://api-console.agentinos.app(the Service API)
Test only within your own account and the organization (org) you belong to.
2. Out of Scope
- Testing and non-production environments
- Third-party services we use (authentication, payments, browser infrastructure, AI model providers, Google, and others). Please report vulnerabilities in those services to their own programs
- Actions that disrupt the Service or generate excessive load (DoS, load testing, high-volume automated scanning, and similar)
- Social engineering, phishing, and physical intrusion
- Intentionally accessing other users' accounts or data. If you encounter another user's data during testing, stop immediately, do not store or share it, and report it to us (reporting the fact that you encountered it is welcome)
- Operations that affect third parties through the Service (for example, testing by having the AI send email to, or operate websites of, third parties)
- Findings based solely on public information (version disclosure, deviation from best practices, and similar) without a demonstrable impact
3. How to Report
- Email: security@ai-delight.com
- Language: Japanese or English
- Please include: the affected URL or feature / steps to reproduce / expected impact / the account or org used (if applicable) / proof of concept or screenshots (if any) / how to reach you
We do not currently offer an encrypted channel (such as PGP). If your report contains sensitive details, please send a summary first; we will arrange a way to exchange the details.
4. Our Response
- Acknowledgment: within 3 business days (Japanese business days; the same applies below) of receiving your report
- Initial assessment: within 10 business days as a guideline, we will let you know whether the report is in scope and whether we will fix it
- Fix: handled according to severity and impact. We cannot commit to a fix date in advance, but we will keep you informed of progress
- Completion notice: we will notify you once the fix is live in the Service
- Disclosure: after the fix is complete, we may publish details in agreement with you. If we publish, our guideline is within 90 days of the report. If you wish to publish, please wait for the fix to be complete and for our agreement
5. Rewards and Acknowledgments
We do not currently offer a bug bounty. If you wish, we will thank you in our completion notice. We do not maintain a public acknowledgments page.
6. Safe Harbor
For research and reports conducted in good faith and in accordance with this policy, we:
- will not treat your actions as a violation of Article 20 (Prohibited Acts) of the Terms of Service (available in Japanese)
- will not pursue legal action against you
- will let this policy take precedence over the Terms of Service where the two conflict, for research and reports that follow this policy
The following are not protected under this section:
- Actions listed as out of scope in Section 2
- Intentionally obtaining other users' data, or retaining or sharing data you encountered by accident
- Using a vulnerability to disrupt or tamper with the Service
- Demanding money or anything else in exchange for a report
- Disclosure without our agreement
Please note that we cannot bind third parties or law enforcement authorities.
7. Your Personal Information
Personal information included in a report is handled under our Privacy Policy and used only to respond to the report.
8. Changes to This Policy
We may change this policy. Changes take effect when posted on this page.
Machine-Readable Contact
The contact in this policy is also published at /.well-known/security.txt (RFC 9116).