Security disclosure policy

Last reviewed: 22 August 2026

Please report a vulnerability privately to [email protected]. Do not open a public issue for an exploitable finding. We welcome good-faith research that stays within this policy.

What to include

  • The affected URL or feature and whether an account was involved.
  • Steps that reproduce the issue without accessing another person's data.
  • What happened, what you expected, and your assessment of the impact.
  • A safe proof of concept, request, or screenshot where useful.

What to expect

We aim to acknowledge a report within three working days and provide an initial assessment within seven. Confirmed high-impact findings take priority over normal product work. We will keep you informed when a fix ships and credit you if you want to be named.

JumpBump does not operate a paid bug bounty. Please do not make payment a condition of disclosing enough information for us to protect users.

Safe harbour

We will not pursue legal action against good-faith research conducted within this policy. To remain in scope:

  • Use only accounts, sessions, content, and devices you control.
  • Stop once you have demonstrated the issue; do not increase its impact.
  • Do not read, alter, retain, or publish another person's data.
  • Do not disrupt the service, degrade it for other people, or create abusive traffic.
  • Report privately and allow a reasonable period for remediation before publication.

Prohibited testing

  • Denial of service, load testing, or high-volume automated scanning.
  • Spam, social engineering, phishing, credential stuffing, or password spraying.
  • Physical attacks, attacks on staff or users, or testing third-party merchants.
  • Changing or deleting data that is not your own.
  • Uploading malware or attempting persistence after proving execution.

Usually out of scope

Missing-header reports without demonstrated impact, automated scanner output without a reproducible issue, self-XSS, clickjacking on pages with no sensitive action, username or email enumeration that reveals no private data, and vulnerabilities in a merchant or other third-party service are generally not actionable here.

Machine-readable contact

The canonical security contact is published at /.well-known/security.txt in the RFC 9116 format. This page is its public policy URL.