Effective date: 8 August 2026
Taemachim Co., Ltd. accepts reports about security issues found on its public website at security@taemachim.com. The Representative, 안지수, is responsible for security management.
What to include
- The affected URL or function
- Reproduction steps
- Expected and actual behaviour
- The impact observed
- Relevant environment details such as browser and operating system
- An email address for a reply
Do not include passwords, API keys, authentication tokens, national identifiers, payment data, raw customer data or personal information unnecessary to verify the issue. If sensitive information appears on screen, redact it and send only the minimum evidence.
Boundaries
- Do not cause service interruption, high-volume traffic, DDoS, spam, social engineering or physical intrusion.
- Do not access accounts or data beyond the minimum needed to establish the issue.
- Do not copy, alter, delete, publish or disclose information found during testing.
- Stop further access and notify us immediately if personal or confidential information is encountered.
- Comply with applicable law and avoid affecting another user.
Handling
The Company assesses reproducibility, impact and priority, then takes appropriate containment, repair and deployment steps. We may contact the reporter for additional information. The timing and scope of disclosure are determined with regard to user protection, risk of exploitation and applicable law.
The Company does not currently operate a reward programme, fixed response-time commitment or general safe-harbour programme. This policy does not authorise unlawful or destructive testing.
Contact
- Security reports: security@taemachim.com
- Responsible officer: 안지수, Representative
Public deployment includes /.well-known/security.txt with the security contact and disclosure instructions.