Saltar al contenido

Vulnerability Disclosure Policy

Kotoba Labs Inc. is committed to the security of Mithril's users and their information. This policy describes what systems and types of research it covers, how to send us vulnerability reports, and what you can expect from us.

Authorization

If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Kotoba Labs Inc. will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities conducted in accordance with this policy, we will make this authorization known.

Guidelines

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command-line access, or pivot to other systems.
  • If you encounter anyone else's data, stop, report it to us, and do not keep or share it.
  • Give us reasonable time to resolve the issue before you disclose it publicly.

Test methods not authorized

  • Denial of service (DoS or DDoS) and load testing
  • Physical testing (office access, open doors, tailgating)
  • Social engineering (phishing, vishing) and any other non-technical testing

Scope

mithril.fund and its subdomains (including console.mithril.fund, api.mithril.fund, app.mithril.fund, auth.mithril.fund and graph.mithril.fund), and kotoba.cloud. Third-party services we use are out of scope; report their vulnerabilities to their operators. Use of the Security Research tier's models is governed by its Acceptable Use Policy, and this policy authorizes no testing of anyone else's systems.

How to report

Send reports to security@mithril.fund by email, in English or Japanese. Reports may be anonymous. Please include where the vulnerability was found, its potential impact, and the technical detail needed to reproduce it (steps, proof-of-concept). There is no bug bounty.

What you can expect from us

  • We will acknowledge your report within 3 business days.
  • To the best of our ability, we will confirm the existence of the vulnerability and be as transparent as possible about the steps we take to remediate it.
  • We will maintain an open dialogue to discuss issues.

Related

Effective 2026-09-25