✦ SECURITY POLICY

Vulnerability Disclosure & Security Policy

RFC 9116 COMPLIANT • UPDATED SEPTEMBER 2026

At JarMind.ai, security, determinism, and data sovereignty are fundamental architectural invariants. We take the safety and integrity of our systems seriously and welcome coordinated vulnerability disclosures from security researchers and developers worldwide.

Safe Harbor Commitment

If you make a good faith effort to comply with this policy during your security research, we consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and JarMind.ai will not pursue legal action against you.

Guidelines & Rules of Engagement

Under this policy, "good faith" research means you agree to:

Scope

In-Scope Targets

  • All subdomains under *.jarmind.ai
  • Public Edge API endpoints (https://jarmind.ai/api/*)
  • Core web applications and static client surfaces

Out-of-Scope Targets

  • Denial of Service (DoS / DDoS) vulnerabilities
  • Social engineering, spear-phishing, or physical infrastructure attacks
  • Vulnerabilities in third-party services that do not directly affect JarMind systems
  • Spam or automated high-volume form submission testing

How to Report a Vulnerability

To report a security issue, please send a detailed summary to our security inbox:

Email: [email protected]

Please include in your report:

Response & Remediation Timelines

Thank you for helping keep JarMind.ai and our community safe and sovereign.