ALAKI Inc. (“ALAKI,” “we,” “us,” or “our”) welcomes good-faith reports of security vulnerabilities affecting MONJI, MONJI+, and related production systems that we operate. This policy defines the limited authorization, scope, testing conditions, reporting process, and safe-harbor terms applicable to security research concerning those systems.
Important: This policy is not a bug-bounty program and does not authorize unrestricted testing, access, exploitation, data extraction, or disruption.
1. Purpose and Relationship to Other MONJI Terms
This policy is a specific, limited authorization for security research that strictly complies with its scope and conditions. Testing outside this policy is not authorized by this policy.
The then-current MONJI Terms of Service continue to apply to use of MONJI. To the extent the Terms prohibit vulnerability scanning, penetration testing, unauthorized access, circumvention, AI/MCP abuse, or similar conduct, activity that fully complies with this policy is treated as expressly authorized only within the limited scope stated here. Activity that exceeds this policy remains subject to the Terms and applicable law.
Nothing in this policy expands eligibility to use MONJI in a Restricted Region or overrides the Restricted Regions List, export-control or sanctions restrictions, third-party terms, or applicable law.
The Privacy Policy governs ALAKI’s handling of personal information submitted with a vulnerability report. The DPA applies only where its scope is otherwise satisfied by a Team Customer relationship and does not convert an independent researcher into a Team Customer or data processor.
For purposes of this policy, “User” means an individual MONJI account holder; “Team” means a collaboration unit in MONJI; “Team Customer” means the business entity using a Team; “User Content” means content, data, or information submitted, stored, transmitted, or processed through MONJI by or for a User or Team Customer; “Third-Party Service” means a service not operated and controlled by ALAKI; “AI Client” means a User-selected generative-AI service or external tool connected to MONJI; “AI Integration Features” means MONJI integration functionality using MCP, APIs, plugins, extensions, or similar methods; and “Write Operations” means supported operations that create, modify, delete, change status, assign responsibility, or otherwise change data or state. These definitions apply only to this policy and do not cause a later Terms version to take effect before its stated effective date.
2. Reporting Channel
Please submit vulnerability reports through our dedicated reporting channel:
To reduce delay and protect sensitive information, please do not submit vulnerability details through sales inquiries, general contact forms, social media, public issue trackers, or unrelated third parties.
3. Scope
In-scope assets include production assets operated and controlled by ALAKI, including:
- websites and production web applications under the monji.tech domain that are operated by ALAKI;
- MONJI and MONJI+ production applications and administrative interfaces operated by ALAKI;
- ALAKI-operated production APIs, authentication and authorization endpoints, and related backend services; and
- ALAKI-operated production MCP endpoints and other components of MONJI AI Integration Features, including authorization and permission flows that ALAKI controls.
The following are out of scope unless ALAKI gives prior written authorization:
- Third-Party Services, AI Clients, cloud providers, payment providers, email providers, analytics providers, or other systems not operated and controlled by ALAKI, even if they integrate with MONJI;
- customer-owned websites, customer infrastructure, third-party websites, or external resources viewed, referenced, or connected through MONJI;
- test, development, staging, internal, non-public, or employee-only environments;
- physical premises, employee devices, social-engineering targets, and telecommunications providers; and
- any asset that ALAKI reasonably identifies as out of scope.
4. Limited Authorization and Testing Conditions
Security testing is authorized under this policy only if all of the following conditions are satisfied:
- Use only accounts, Teams, projects, content, credentials, permissions, and data that you own or are expressly authorized to control for testing.
- Limit testing to the minimum reasonably necessary to identify and demonstrate the vulnerability. Use non-destructive techniques and avoid persistence.
- Do not access, retrieve, copy, retain, alter, delete, disclose, or otherwise use information belonging to another User, Team Customer, Team, or third party.
- If you unexpectedly encounter personal information, confidential information, credentials, secrets, or other non-public information that you are not authorized to access, stop testing immediately, do not retain or disclose the information, and report the issue promptly.
- Do not materially degrade the Service, create excessive load, bypass rate limits for the purpose of generating load, or interfere with another person’s use of the Service.
- Automated requests must be low-volume, non-destructive, and reasonably necessary to confirm a vulnerability. High-volume scanning, broad automated enumeration, stress testing, and load testing require prior written authorization.
- Authentication and authorization-boundary testing must remain within your own test accounts and data. Do not use a suspected bypass to obtain control of, or information from, another person’s account or Team.
- For AI Integration Features, MCP, APIs, plugins, or similar features, testing must use only your own authorized data and permissions. Do not intentionally cause an AI Client or MONJI to access or modify information outside your authorized scope.
- Use the minimum proof of concept necessary. Do not install backdoors, create persistent access, establish command-and-control capability, or maintain unauthorized access after testing.
5. AI and MCP Security Research
Because MONJI may provide AI Integration Features through MCP, APIs, plugins, extensions, or similar mechanisms, security research may include authorization-boundary and integration testing subject to Section 4. In particular:
- Limited testing of prompts, tool calls, authorization flows, or integration behavior using your own test data and permissions is permitted when it is non-destructive and does not cross an authorization boundary.
- Prompt injection, jailbreak, tool poisoning, or similar techniques are not authorized when used to obtain confidential or unauthorized information, bypass another user’s permissions, cause unintended or unauthorized Write Operations, or affect ALAKI, another User, a Team Customer, or a third party beyond your own authorized test environment.
- Do not use AI or MCP testing to exfiltrate secrets, tokens, credentials, system prompts containing non-public information, customer data, or other information that you are not authorized to access.
- Do not test the security of a third-party AI Client or Third-Party Service through MONJI unless that third party independently authorizes such testing.
6. Prohibited Activities
The following activities are not authorized by this policy:
- denial-of-service, distributed denial-of-service, stress testing, traffic flooding, or intentional service degradation;
- accessing, downloading, retaining, modifying, deleting, disclosing, or publicly demonstrating another person’s data or credentials;
- credential theft, session hijacking, account takeover, lateral movement, persistence, or privilege escalation beyond your own authorized test environment;
- malware deployment, ransomware, destructive payloads, cryptomining, or code intended to cause harm;
- social engineering, phishing, pretexting, impersonation, spam, physical attacks, or attempts to obtain employee credentials;
- mass form submissions, mass account creation, broad scraping, or excessive automated enumeration;
- testing third-party systems, AI Clients, providers, or infrastructure without their authorization;
- using a vulnerability for extortion, coercion, commercial leverage, competitive intelligence, or any unlawful purpose;
- public disclosure contrary to Section 8; and
- any activity that violates applicable law or third-party rights.
7. Information to Include in a Report
Please provide enough information for us to understand and reproduce the issue, including where reasonably available:
- the affected URL, host, screen, feature, API endpoint, MCP tool or resource, or authorization flow;
- a clear description of the vulnerability and the security impact;
- step-by-step reproduction instructions;
- a minimal, non-destructive proof of concept, screenshots, request/response examples, or references;
- the date and time of discovery and testing;
- your preferred contact information; and
- whether any ALAKI, User, Team Customer, Team, or third-party data was unexpectedly accessed, and if so, the minimum details necessary for us to assess the incident without reproducing unnecessary personal or confidential information.
Incomplete, duplicate, unverifiable, or out-of-scope reports may be closed or may take longer to review.
8. Confidentiality and Coordinated Disclosure
Do not publicly disclose, publish, sell, transfer, or share non-public vulnerability details, exploit code, proof-of-concept material, or affected data before ALAKI has implemented a fix or mitigation, or before a disclosure date is separately agreed in writing.
If you believe disclosure is required by law, you should notify ALAKI in advance where legally permitted so that we can take appropriate protective measures.
ALAKI may share a report and related information with personnel, service providers, professional advisers, or affected third parties to the extent reasonably necessary to investigate, remediate, secure the Service, comply with law, or protect rights and interests.
9. How We Handle Reports
We will review reports submitted through the designated channel within a reasonable scope and may request additional information or clarification.
Response, triage, remediation, and disclosure timing depends on severity, reproducibility, technical complexity, affected systems, third-party dependencies, report volume, and other circumstances. We do not guarantee a specific acknowledgement, remediation, or disclosure timeline.
We may determine that a report is duplicate, informational, not reproducible, out of scope, already known, or does not present a security vulnerability, and may close the report on that basis.
We are not required to disclose internal investigation details, security architecture, remediation methods, logs, customer information, or other confidential information to a reporter.
10. No Reward, Compensation, or Public Acknowledgment Commitment
MONJI does not operate a bug-bounty program under this policy. We do not promise rewards, fees, compensation, reimbursements, or other monetary payment for vulnerability reports.
We do not promise public acknowledgment, a Hall of Fame listing, a security acknowledgment page, a reference, or other public recognition.
Any exception must be expressly agreed by ALAKI in writing in advance. Submitting a report does not create any right to payment or recognition.
11. Safe Harbor for Compliant Research
If you act in good faith, stay within the in-scope assets, comply with all testing conditions and confidentiality requirements in this policy, and promptly report the vulnerability, ALAKI will not bring a civil claim against you solely on the basis of that compliant security research.
This safe harbor does not restrict ALAKI from preserving evidence, responding to legal process or regulatory requests, making reports or disclosures required by law, or taking steps reasonably necessary to protect ALAKI, Users, Team Customers, or third parties.
This safe harbor applies only to conduct that is authorized by this policy. It does not apply to activity that exceeds the scope, violates this policy, intentionally harms ALAKI or another person, accesses or uses unauthorized data, violates applicable law, or affects third-party systems without authorization.
This policy cannot bind law-enforcement agencies, regulators, third-party service providers, Team Customers, or other third parties, and ALAKI cannot grant authorization or immunity on their behalf.
If you are uncertain whether a planned test is permitted, request clarification through the Vulnerability Report Form before performing the test.
12. Privacy and Handling of Report Information
Do not include passwords, access tokens, private keys, unnecessary personal information, or unrelated User Content in a report. Redact sensitive information wherever possible.
Information submitted with a report may be used to investigate, reproduce, remediate, document, and prevent security issues; communicate with the reporter; protect the Service and users; and comply with legal obligations.
Personal information submitted with a report is handled in accordance with the then-current MONJI Privacy Policy, subject to applicable law.
13. Changes to This Policy
We may update this policy to reflect changes in the Service, security practices, AI Integration Features, law, or operational needs. The latest version will be published on the MONJI website with its effective or last-updated date.
A later version of this policy will not retroactively remove the safe-harbor protection applicable to security research that was completed in compliance with the version in effect at the time of that research.
Version History
- Version 1.0 — April 20, 2026 (JST), Established and effective
- Version 2.0 — September 18, 2026 (JST), Revised and effective