Report a Vulnerability
Last updated: September 2026
If you think you have found a security vulnerability in Jsonify, we want to hear about it. This page explains how to report it, what is in scope, what we ask of you while you research, and what you can expect from us.
Report it using the form below, or email paul@jsonify.com with “Vulnerability report” in the subject. Please don’t report vulnerabilities through Jason, support chats, social media or public issue trackers.
What to include
- The affected URL, endpoint, app or component.
- The type of issue and what an attacker could do with it.
- Step-by-step instructions to reproduce it, with any requests, payloads or screenshots that help.
- Whether you accessed, changed or kept any data that isn’t yours, and what it was.
- How you’d like to be credited, if at all.
Scope
In scope:
- jsonify.com and www.jsonify.com
- factory.jsonify.com, including its APIs and the Jason assistant
- The Jsonify connector for AI assistants (MCP)
Out of scope:
- Services run by third parties, including our subprocessors. Please report those to the provider.
- Denial of service, load testing, or anything that degrades the service for others.
- Social engineering, phishing, or physical attacks on Jsonify staff, offices or customers.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags, SPF, DKIM or DMARC settings without a working attack.
- Clickjacking on pages with no sensitive actions, self-XSS, and CSRF on logout or other actions with no security impact.
- Rate limits on non-sensitive endpoints, and software version disclosure.
- Issues that need a rooted or jailbroken device, an outdated browser, or physical access to a victim’s device.
Concerns about Jsonify collecting from a website or app you operate aren’t vulnerabilities; see For website and app owners. To access or delete personal data, use Remove my data.
Research rules
- Use accounts and data you own or have permission to use. Create your own test accounts where you can.
- If you reach data that isn’t yours, including customer data or personal data, stop, don’t keep a copy, and tell us what you saw.
- Do only what you need to demonstrate the issue. Don’t change or delete data, move deeper into our systems, or keep access open.
- Don’t run high-volume automated scanning, and don’t do anything that affects availability for other users.
- Keep the details confidential until we have fixed the issue, or until 90 days after your report, whichever comes first. If we need longer, we’ll explain why and agree a date with you.
- Follow applicable law.
What you can expect from us
- We aim to acknowledge your report within three business days.
- We’ll confirm whether we can reproduce the issue, tell you how we assess its severity, and keep you updated until it is resolved.
- We’ll let you know when it is fixed, and credit you publicly if you’d like us to.
Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorised. We won’t pursue legal action or make a complaint to law enforcement about it, and we waive the restrictions in our Acceptable Use Policy and Terms that would otherwise prohibit it, to the extent needed for your research under this policy. If a third party takes legal action against you for research you carried out under this policy, we’ll make it known that you acted in line with it.
This covers Jsonify’s own systems only. We can’t authorise testing of third-party services. If you’re unsure whether something is allowed, ask us first.
Rewards
We don’t run a paid bug bounty programme and don’t promise payment for reports. We review each valid report case by case, and may choose to offer a reward or other thanks for a previously unknown issue with meaningful impact. Any reward is at our discretion.
Report a vulnerability
Report received. Thank you. We aim to reply within three business days.