Security and vulnerability disclosure
Report to
contact@the-horizons-innovation.com, subject starting with [security]. English or Japanese. Machine-readable contact: /.well-known/security.txt (RFC 9116).
Include what you did, the exact URL or endpoint, what you saw, and from where you measured it. A report that contradicts our own measurement is the most useful kind.
In scope
- shield.the-horizons-innovation.com (the site, its data files and the diagnosis flow)
- Every service under horizonshield.dev: the MCP servers (mcp, ccdb, hearing, web, p001, p002), the verification gate (gate), the JIDEC ledger (ledger, jidec) and their A2A agent cards
- The published datasets JCCDB and USCCDB (Zenodo, Hugging Face, GitHub) and the npm and PyPI package nenrin-verify
We treat these as security problems, not support tickets: a verdict or record that is wrong, a signature or hash that verifies when it should not (or fails when it should verify), a break in the ledger chain or its anchoring, a way to make the gate record something the measured server did not do, and any personal data or secret on a public surface.
Out of scope
Denial of service and load testing, social engineering, physical attacks, and findings that need a compromised device of the reporter. Reports from automated scanners without a demonstrated impact.
Safe harbor
If you act in good faith, stay within this page, do not access or keep more data than needed to show the problem, do not degrade the service, and give us a reasonable time to fix before publishing, we will not pursue or support legal action against you for that research.
What happens next
- We aim to acknowledge within 3 business days and to tell you what we will do.
- Fixes are made in the public repository, and the fix commit is named in the record. Findings that changed a verdict or a record are published, including ones that make us look wrong.
- We credit reporters by name unless you ask us not to. Past outside findings and who made them are listed in the README and THIRD-PARTY.md.
- There is no paid bug bounty at present. We say so here rather than leave it unclear.
Signing keys
Every public key we sign with, when it began and its status, is at gate.horizonshield.dev/.well-known/key-history.json (key-history-v1). A key not listed there is not ours. The list is fixed outside our servers: its SHA-256 d479e3e036625b87e40cc1d0882e7f569843939d34f193e9e4da9b033559b7a9 is JIDEC ledger entry 60, anchored in Bitcoin block 968923 (2026-09-28) by OpenTimestamps. The list's bytes and the proof are also deposited outside our domain at Zenodo, doi:10.5281/zenodo.23122049, so you can check this without trusting us or our servers. If a signature verifies against a key that is not in the list, report it here.
日本語
脆弱性や、判定・記録の誤りは contact@the-horizons-innovation.com へ、件名の頭に [security] を付けて送ってください。何をしたか、対象の URL、見えたもの、どこから測ったかを書いてください。こちらの測定と食い違う報告が、いちばん役に立ちます。
対象は、このサイト、horizonshield.dev の下のすべてのサービス(MCP サーバー、検証の扉、JIDEC 台帳、A2A の agent card)、公開データ JCCDB と USCCDB、配布物 nenrin-verify です。判定や記録の誤り、通るはずのない署名やハッシュが通ること、台帳の鎖や錨の破れ、公開面に個人情報や鍵が出ていることは、問い合わせではなくセキュリティの問題として扱います。
サービスを止める試験、人を騙す手口、物理的な攻撃は対象外です。善意で、この範囲の中で、必要以上のデータに触れず、直すための時間をくださる限り、その調査について法的な手段はとりません。
署名に使う公開鍵の一覧(いつからか、今の状態)は key-history.json にあります。載っていない鍵は、私たちの鍵ではありません。この一覧は私たちのサーバーの外で固定してあります。一覧の SHA-256 は JIDEC 台帳の 60 番として、OpenTimestamps で Bitcoin のブロック 968923(2026-09-28)に錨付けされています。一覧の中身と証明は、私たちのドメインの外の Zenodo(doi:10.5281/zenodo.23122049)にも置いてあり、私たちもサーバーも信用せずに確かめられます。
受け取ってから 3 営業日以内に返事をすることを目標にしています。直しは公開のリポジトリで行い、判定や記録を変えた報告は、こちらの誤りであっても公開します。ご希望がなければお名前を記して感謝を残します。現在、報奨金の制度はありません。