Agentino

Security Policy

Vulnerability Disclosure Policy

This English version is provided for convenience. If there is any discrepancy, the Japanese version prevails.

Delight, Inc. ("we") accepts vulnerability reports from outside researchers and users to improve the security of Agentino (the "Service"). This policy defines how to report, how we respond, and the conditions under which reporters are protected.

1. Scope

Test only within your own account and the organization (org) you belong to.

2. Out of Scope

3. How to Report

We do not currently offer an encrypted channel (such as PGP). If your report contains sensitive details, please send a summary first; we will arrange a way to exchange the details.

4. Our Response

5. Rewards and Acknowledgments

We do not currently offer a bug bounty. If you wish, we will thank you in our completion notice. We do not maintain a public acknowledgments page.

6. Safe Harbor

For research and reports conducted in good faith and in accordance with this policy, we:

The following are not protected under this section:

Please note that we cannot bind third parties or law enforcement authorities.

7. Your Personal Information

Personal information included in a report is handled under our Privacy Policy and used only to respond to the report.

8. Changes to This Policy

We may change this policy. Changes take effect when posted on this page.

Machine-Readable Contact

The contact in this policy is also published at /.well-known/security.txt (RFC 9116).