This policy applies to all public repositories under github.com/larai-w and the VEAI LAB. websites (veai.jp, veai-projects.com, hire-veai.com).
If you believe you have found a security vulnerability, please report it privately — do not open a public issue.
- Email: security@veai.jp
- Or use GitHub's private "Report a vulnerability" form on the affected repository, if enabled.
Please include, where possible:
- The repository (or site URL) and version/commit affected
- A description of the issue and its potential impact
- Steps to reproduce, or a proof of concept
- We aim to acknowledge reports within 7 days. VEAI LAB. is a small research lab, so please bear with us on complex issues.
- We will keep you informed while we investigate, and let you know when a fix or mitigation ships.
- With your permission, we are happy to credit you in the release notes.
- There is currently no bug bounty program; reports are handled on a best-effort basis.
- Findings that require physical access to a user's device
- Vulnerabilities in third-party services we do not operate (please report those upstream)
- Automated scanner output without a demonstrated impact
Thank you for helping keep caregivers' data safe.