generated: '2026-08-23' method: searched source: https://layerx.co.jp/security_policy/ api: n/a program: published: true type: security-contact contact_email: security@layerx.co.jp contact_page: https://layerx.co.jp/security_policy/ http_status: 200 probed: '2026-08-23' note: >- LayerX publishes a named security contact for vulnerability reports and security-related enquiries on its corporate 情報セキュリティ基本方針 page. It is a contact, not a program: there is no published disclosure policy, no coordinated disclosure timeline, no safe-harbour statement and no scope definition. security_txt: present: false probed_paths: - url: https://layerx.co.jp/.well-known/security.txt status: 404 - url: https://bakuraku.jp/.well-known/security.txt status: 404 - url: https://api.bakuraku.layerx.jp/.well-known/security.txt status: 404 - url: https://getaiworkforce.com/.well-known/security.txt status: 404 - url: https://bakuraku-status.jp/.well-known/security.txt status: 404 probed: '2026-08-23' note: >- The contact exists but is not machine-discoverable. An RFC 9116 security.txt at layerx.co.jp carrying Contact: mailto:security@layerx.co.jp and Policy: pointing at the existing security_policy page would publish the same fact in a form a scanner can read, and costs nothing beyond serving one text file. bug_bounty: present: false platforms_checked: - HackerOne - Bugcrowd - Intigriti note: No public bug bounty or VDP listing found for LayerX or Bakuraku. internal_program: penetration_testing: >- Bakuraku's security page states third-party penetration tests are run regularly with prompt remediation of findings, and that intrusion-detection controls are in place. ciso: true source: https://bakuraku.jp/security/