Security and vulnerability disclosure

HORIZON SHIELD, The HORIZONs Co., Ltd. Last updated 2026-10-03. 日本語は下にあります。

Report to

contact@the-horizons-innovation.com, subject starting with [security]. English or Japanese. Machine-readable contact: /.well-known/security.txt (RFC 9116).

Include what you did, the exact URL or endpoint, what you saw, and from where you measured it. A report that contradicts our own measurement is the most useful kind.

In scope

We treat these as security problems, not support tickets: a verdict or record that is wrong, a signature or hash that verifies when it should not (or fails when it should verify), a break in the ledger chain or its anchoring, a way to make the gate record something the measured server did not do, and any personal data or secret on a public surface.

Out of scope

Denial of service and load testing, social engineering, physical attacks, and findings that need a compromised device of the reporter. Reports from automated scanners without a demonstrated impact.

Safe harbor

If you act in good faith, stay within this page, do not access or keep more data than needed to show the problem, do not degrade the service, and give us a reasonable time to fix before publishing, we will not pursue or support legal action against you for that research.

What happens next

Signing keys

Every public key we sign with, when it began and its status, is at gate.horizonshield.dev/.well-known/key-history.json (key-history-v1). A key not listed there is not ours. The list is fixed outside our servers: its SHA-256 d479e3e036625b87e40cc1d0882e7f569843939d34f193e9e4da9b033559b7a9 is JIDEC ledger entry 60, anchored in Bitcoin block 968923 (2026-09-28) by OpenTimestamps. The list's bytes and the proof are also deposited outside our domain at Zenodo, doi:10.5281/zenodo.23122049, so you can check this without trusting us or our servers. If a signature verifies against a key that is not in the list, report it here.

日本語

脆弱性や、判定・記録の誤りは contact@the-horizons-innovation.com へ、件名の頭に [security] を付けて送ってください。何をしたか、対象の URL、見えたもの、どこから測ったかを書いてください。こちらの測定と食い違う報告が、いちばん役に立ちます。

対象は、このサイト、horizonshield.dev の下のすべてのサービス(MCP サーバー、検証の扉、JIDEC 台帳、A2A の agent card)、公開データ JCCDB と USCCDB、配布物 nenrin-verify です。判定や記録の誤り、通るはずのない署名やハッシュが通ること、台帳の鎖や錨の破れ、公開面に個人情報や鍵が出ていることは、問い合わせではなくセキュリティの問題として扱います。

サービスを止める試験、人を騙す手口、物理的な攻撃は対象外です。善意で、この範囲の中で、必要以上のデータに触れず、直すための時間をくださる限り、その調査について法的な手段はとりません。

署名に使う公開鍵の一覧(いつからか、今の状態)は key-history.json にあります。載っていない鍵は、私たちの鍵ではありません。この一覧は私たちのサーバーの外で固定してあります。一覧の SHA-256 は JIDEC 台帳の 60 番として、OpenTimestamps で Bitcoin のブロック 968923(2026-09-28)に錨付けされています。一覧の中身と証明は、私たちのドメインの外の Zenodo(doi:10.5281/zenodo.23122049)にも置いてあり、私たちもサーバーも信用せずに確かめられます。

受け取ってから 3 営業日以内に返事をすることを目標にしています。直しは公開のリポジトリで行い、判定や記録を変えた報告は、こちらの誤りであっても公開します。ご希望がなければお名前を記して感謝を残します。現在、報奨金の制度はありません。

HORIZON SHIELD