At JarMind.ai, security, determinism, and data sovereignty are fundamental architectural invariants. We take the safety and integrity of our systems seriously and welcome coordinated vulnerability disclosures from security researchers and developers worldwide.
Safe Harbor Commitment
If you make a good faith effort to comply with this policy during your security research, we consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and JarMind.ai will not pursue legal action against you.
Guidelines & Rules of Engagement
Under this policy, "good faith" research means you agree to:
- Protect User Data: Do not access, download, modify, or destroy any user data or proprietary information. If you encounter user data, stop immediately and report it.
- Avoid Disruption: Do not degrade user experience or perform denial-of-service (DoS/DDoS) attacks.
- No Social Engineering: Do not execute phishing, social engineering, or physical attacks against JarMind personnel or infrastructure.
- Coordinated Disclosure: Give us a reasonable period of time to investigate and remediate the issue before disclosing any details publicly.
Scope
In-Scope Targets
- All subdomains under
*.jarmind.ai - Public Edge API endpoints (
https://jarmind.ai/api/*) - Core web applications and static client surfaces
Out-of-Scope Targets
- Denial of Service (DoS / DDoS) vulnerabilities
- Social engineering, spear-phishing, or physical infrastructure attacks
- Vulnerabilities in third-party services that do not directly affect JarMind systems
- Spam or automated high-volume form submission testing
How to Report a Vulnerability
To report a security issue, please send a detailed summary to our security inbox:
Email: [email protected]
Please include in your report:
- A clear description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or a minimal proof of concept.
- Target URL, request headers, or affected endpoints.
Response & Remediation Timelines
- Initial Acknowledgement: We aim to acknowledge receipt of your report within 24 business hours.
- Validation: We will confirm the vulnerability and provide an estimated remediation timeline.
- Remediation: Critical vulnerabilities are treated as highest-priority engineering fixes.
Thank you for helping keep JarMind.ai and our community safe and sovereign.