This is a translation provided for convenience. The Korean version is the authoritative text and prevails in case of conflict.
Vulnerability Management Policy
Purpose
How Rexplore finds, triages and fixes security vulnerabilities in Nakama.
Identification
We monitor security advisories for our platform dependencies (Chrome extension APIs, Node.js, hosting platform) and review code changes for security impact. The extension's minimal-dependency design keeps the surface small.
Reporting channel
Anyone can report a suspected vulnerability to help@rexplore.xyz. We acknowledge reports within 3 business days.
Triage and severity
Reports are triaged by impact and exploitability into critical, high, medium and low.
Remediation targets
Critical: fix or mitigation within 72 hours. High: within 7 days. Medium: within 30 days. Low: next regular release. Chrome's extension auto-update delivers fixes to users without action on their part.
Coordinated disclosure
We ask reporters to allow up to 90 days for a fix before public disclosure, and we credit reporters who wish to be named.
Language
The Korean-language version of this policy is the authoritative text. All other language versions, including this English version, are translations provided for convenience only, and the Korean version prevails in the event of any conflict, inconsistency or ambiguity.
Governing law and jurisdiction
This policy is governed by the laws of the Republic of Korea, without regard to conflict-of-laws rules. The Seoul Central District Court (서울중앙지방법원) has exclusive jurisdiction as the court of first instance over any dispute arising out of or relating to this policy. This does not affect mandatory consumer-protection rights, or the right to bring proceedings in your country of residence, which are preserved where applicable law so requires.