Skip to content
NQ Solution

Security at
NQ Solution

How to reach our security officer, how to report a vulnerability in our services, and how we handle security while we build.

Last updated: October 8, 2026.

1. Security officer and contact

NQ Solution has designated a security officer who receives security reports and oversees how we handle them.

Security officer
Seolwon Kim · Director
Security contact
seolwon@nqsolution.kr
Company
NQ Solution
Business Reg. No.
867-36-01532

When you report an issue, please include:

  • The affected URL or service
  • A description of the issue and its potential impact
  • Steps to reproduce it, with any requests, screenshots or proof of concept
  • How we can reach you for follow-up questions

We acknowledge reports we receive and work on fixes for confirmed issues. We do not commit to a fixed response deadline.

Questions about personal data go to our privacy officer, Deokwoong Kim (CEO) — see section 8 of our Privacy Policy.

2. Reporting a vulnerability

Scope: nqsolution.kr, its subdomains, and the services we operate on them. If you find an issue in a system we built that is owned and operated by a client, please contact that client.

While researching, please:

  • Do not access, modify or delete data that is not yours; stop and report as soon as you see other people's data
  • Do not run denial-of-service tests, social engineering or physical attacks
  • Give us reasonable time to fix the issue before you disclose it publicly

We will not initiate legal action against anyone who reports a vulnerability while acting in good faith within this policy.

We do not run a bug bounty program and do not offer rewards at this time.

3. How we build

We check security as part of development, not as a separate step at the end:

  • Access control and least privilege — people and services get only the access they need
  • Input validation on what users and other systems send in
  • Dependency updates and security patches applied as they come out
  • Secrets and credentials kept out of source code
  • Exposure checks before each release
  • Code review — we develop with an AI coding agent, and a person reviews every change before it ships
  • Personal data handled under Korea’s Personal Information Protection Act and our Privacy Policy

4. Certifications

We do not currently hold ISO/IEC 27001 or SOC 2 certification.

5. Updates to this policy

Last updated: October 8, 2026. This policy is published at https://nqsolution.kr/en/security, and a machine-readable contact file is at https://nqsolution.kr/.well-known/security.txt. Changes are announced on this page.