Report a Vulnerability

If you think you have found a security vulnerability in Jsonify, we want to hear about it. This page explains how to report it, what is in scope, what we ask of you while you research, and what you can expect from us.

Report it using the form below, or email paul@jsonify.com with “Vulnerability report” in the subject. Please don’t report vulnerabilities through Jason, support chats, social media or public issue trackers.

What to include

  • The affected URL, endpoint, app or component.
  • The type of issue and what an attacker could do with it.
  • Step-by-step instructions to reproduce it, with any requests, payloads or screenshots that help.
  • Whether you accessed, changed or kept any data that isn’t yours, and what it was.
  • How you’d like to be credited, if at all.

Scope

In scope:

  • jsonify.com and www.jsonify.com
  • factory.jsonify.com, including its APIs and the Jason assistant
  • The Jsonify connector for AI assistants (MCP)

Out of scope:

  • Services run by third parties, including our subprocessors. Please report those to the provider.
  • Denial of service, load testing, or anything that degrades the service for others.
  • Social engineering, phishing, or physical attacks on Jsonify staff, offices or customers.
  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Missing security headers, cookie flags, SPF, DKIM or DMARC settings without a working attack.
  • Clickjacking on pages with no sensitive actions, self-XSS, and CSRF on logout or other actions with no security impact.
  • Rate limits on non-sensitive endpoints, and software version disclosure.
  • Issues that need a rooted or jailbroken device, an outdated browser, or physical access to a victim’s device.

Concerns about Jsonify collecting from a website or app you operate aren’t vulnerabilities; see For website and app owners. To access or delete personal data, use Remove my data.

Research rules

  • Use accounts and data you own or have permission to use. Create your own test accounts where you can.
  • If you reach data that isn’t yours, including customer data or personal data, stop, don’t keep a copy, and tell us what you saw.
  • Do only what you need to demonstrate the issue. Don’t change or delete data, move deeper into our systems, or keep access open.
  • Don’t run high-volume automated scanning, and don’t do anything that affects availability for other users.
  • Keep the details confidential until we have fixed the issue, or until 90 days after your report, whichever comes first. If we need longer, we’ll explain why and agree a date with you.
  • Follow applicable law.

What you can expect from us

  • We aim to acknowledge your report within three business days.
  • We’ll confirm whether we can reproduce the issue, tell you how we assess its severity, and keep you updated until it is resolved.
  • We’ll let you know when it is fixed, and credit you publicly if you’d like us to.

Safe harbour

If you make a good-faith effort to follow this policy, we consider your research authorised. We won’t pursue legal action or make a complaint to law enforcement about it, and we waive the restrictions in our Acceptable Use Policy and Terms that would otherwise prohibit it, to the extent needed for your research under this policy. If a third party takes legal action against you for research you carried out under this policy, we’ll make it known that you acted in line with it.

This covers Jsonify’s own systems only. We can’t authorise testing of third-party services. If you’re unsure whether something is allowed, ask us first.

Rewards

We don’t run a paid bug bounty programme and don’t promise payment for reports. We review each valid report case by case, and may choose to offer a reward or other thanks for a previously unknown issue with meaningful impact. Any reward is at our discretion.

Report a vulnerability

Don’t include passwords, API keys or other people’s personal data. If you have files to share, say so and we’ll reply with a way to send them.

Connect your data assistant

Build datasets and work with your data in Claude, ChatGPT, Copilot or another assistant.

Connect in Claude

  1. Open the Jsonify connector: Open on Claude.ai ↗
  2. Select Connect and sign in to Jsonify.
  3. In a chat, enable Jsonify under + → Connectors and describe the data you need.
Advanced

Team or Enterprise account? Your workspace owner enables Jsonify once for everyone from Admin settings → Connectors. Jsonify is a community connector in the directory — some admins allow those by default, some review them first.

No directory? Add it by hand: Settings → Connectors → + Add custom connector, name it Jsonify, paste the server URL below, then Connect.

Server URLhttps://factory.jsonify.com/mcp

Official Claude custom-connector guide ↗

Then say: “build me a dataset of competitor product prices and availability, refreshed daily”. Full instructions per client on /connect.