Security disclosure policy
Last reviewed: 22 August 2026
Please report a vulnerability privately to [email protected]. Do not open a public issue for an exploitable finding. We welcome good-faith research that stays within this policy.
What to include
- The affected URL or feature and whether an account was involved.
- Steps that reproduce the issue without accessing another person's data.
- What happened, what you expected, and your assessment of the impact.
- A safe proof of concept, request, or screenshot where useful.
What to expect
We aim to acknowledge a report within three working days and provide an initial assessment within seven. Confirmed high-impact findings take priority over normal product work. We will keep you informed when a fix ships and credit you if you want to be named.
JumpBump does not operate a paid bug bounty. Please do not make payment a condition of disclosing enough information for us to protect users.
Safe harbour
We will not pursue legal action against good-faith research conducted within this policy. To remain in scope:
- Use only accounts, sessions, content, and devices you control.
- Stop once you have demonstrated the issue; do not increase its impact.
- Do not read, alter, retain, or publish another person's data.
- Do not disrupt the service, degrade it for other people, or create abusive traffic.
- Report privately and allow a reasonable period for remediation before publication.
Prohibited testing
- Denial of service, load testing, or high-volume automated scanning.
- Spam, social engineering, phishing, credential stuffing, or password spraying.
- Physical attacks, attacks on staff or users, or testing third-party merchants.
- Changing or deleting data that is not your own.
- Uploading malware or attempting persistence after proving execution.
Usually out of scope
Missing-header reports without demonstrated impact, automated scanner output without a reproducible issue, self-XSS, clickjacking on pages with no sensitive action, username or email enumeration that reveals no private data, and vulnerabilities in a merchant or other third-party service are generally not actionable here.
Machine-readable contact
The canonical security contact is published at /.well-known/security.txt in the RFC 9116 format. This page is its public policy URL.