---
title: "Report a Vulnerability"
description: "How to report a security vulnerability in Jsonify responsibly: what to include, what is in scope, how we respond, and our safe harbour for good-faith research."
url: "https://www.jsonify.com/security"
---

# Report a Vulnerability

Last updated: September 2026

If you think you have found a security vulnerability in Jsonify, we want to hear about it. This page explains how to report it, what is in scope, what we ask of you while you research, and what you can expect from us.

Report it using the form below, or email [paul@jsonify.com](mailto:paul@jsonify.com?subject=Vulnerability%20report) with “Vulnerability report” in the subject. Please don’t report vulnerabilities through Jason, support chats, social media or public issue trackers.

## What to include

*   The affected URL, endpoint, app or component.
*   The type of issue and what an attacker could do with it.
*   Step-by-step instructions to reproduce it, with any requests, payloads or screenshots that help.
*   Whether you accessed, changed or kept any data that isn’t yours, and what it was.
*   How you’d like to be credited, if at all.

## Scope

In scope:

*   jsonify.com and www.jsonify.com
*   factory.jsonify.com, including its APIs and the Jason assistant
*   The Jsonify connector for AI assistants (MCP)

Out of scope:

*   Services run by third parties, including our [subprocessors](https://www.jsonify.com/legal/subprocessors). Please report those to the provider.
*   Denial of service, load testing, or anything that degrades the service for others.
*   Social engineering, phishing, or physical attacks on Jsonify staff, offices or customers.
*   Reports from automated scanners without a demonstrated, exploitable impact.
*   Missing security headers, cookie flags, SPF, DKIM or DMARC settings without a working attack.
*   Clickjacking on pages with no sensitive actions, self-XSS, and CSRF on logout or other actions with no security impact.
*   Rate limits on non-sensitive endpoints, and software version disclosure.
*   Issues that need a rooted or jailbroken device, an outdated browser, or physical access to a victim’s device.

Concerns about Jsonify collecting from a website or app you operate aren’t vulnerabilities; see [For website and app owners](https://www.jsonify.com/legal/site-owners). To access or delete personal data, use [Remove my data](https://www.jsonify.com/legal/remove-my-data).

## Research rules

*   Use accounts and data you own or have permission to use. Create your own test accounts where you can.
*   If you reach data that isn’t yours, including customer data or personal data, stop, don’t keep a copy, and tell us what you saw.
*   Do only what you need to demonstrate the issue. Don’t change or delete data, move deeper into our systems, or keep access open.
*   Don’t run high-volume automated scanning, and don’t do anything that affects availability for other users.
*   Keep the details confidential until we have fixed the issue, or until 90 days after your report, whichever comes first. If we need longer, we’ll explain why and agree a date with you.
*   Follow applicable law.

## What you can expect from us

*   We aim to acknowledge your report within three business days.
*   We’ll confirm whether we can reproduce the issue, tell you how we assess its severity, and keep you updated until it is resolved.
*   We’ll let you know when it is fixed, and credit you publicly if you’d like us to.

## Safe harbour

If you make a good-faith effort to follow this policy, we consider your research authorised. We won’t pursue legal action or make a complaint to law enforcement about it, and we waive the restrictions in our [Acceptable Use Policy](https://www.jsonify.com/legal/acceptable-use) and [Terms](https://www.jsonify.com/legal/terms) that would otherwise prohibit it, to the extent needed for your research under this policy. If a third party takes legal action against you for research you carried out under this policy, we’ll make it known that you acted in line with it.

This covers Jsonify’s own systems only. We can’t authorise testing of third-party services. If you’re unsure whether something is allowed, ask us first.

## Rewards

We don’t run a paid bug bounty programme and don’t promise payment for reports. We review each valid report case by case, and may choose to offer a reward or other thanks for a previously unknown issue with meaningful impact. Any reward is at our discretion.

## Report a vulnerability



Name Optional Email

Affected URL or component Type of issue 

Description and steps to reproduce Impact Optional  Credit me publicly when the issue is fixed  I followed the research rules on this page

Don’t include passwords, API keys or other people’s personal data. If you have files to share, say so and we’ll reply with a way to send them.

Report received. Thank you. We aim to reply within three business days.

[Privacy](https://www.jsonify.com/legal/privacy)[Terms](https://www.jsonify.com/legal/terms)[Acceptable use](https://www.jsonify.com/legal/acceptable-use)[DPA](https://www.jsonify.com/legal/dpa)[Subprocessors](https://www.jsonify.com/legal/subprocessors)[Legal FAQ](https://www.jsonify.com/legal/faq)[Remove my data](https://www.jsonify.com/legal/remove-my-data)[Site owners](https://www.jsonify.com/legal/site-owners)
