SECURITY & VULNERABILITY DISCLOSURE

Help us keep JibeONE safe.

Report a vulnerability. Get a fast, respectful response. We do not litigate good-faith research.

Draft for legal review. Subject to revision. Last updated: 5 July 2026.

We welcome reports from security researchers and take them seriously. This page describes how to report a suspected vulnerability in JibeONE, what is in and out of scope, and the protections we extend to good-faith researchers.

1. Report a vulnerability

Email security@jibe.one. For sensitive reports, please encrypt using the PGP key published at /.well-known/pgp-key.txt. Include enough detail to reproduce the issue: affected component or URL, steps, impact, and any proof-of-concept. Our machine-readable policy is published at /.well-known/security.txt per RFC 9116.

2. In scope

The JibeONE platform and this website, and services JibeONE operates and controls.

3. Out of scope

  • Denial-of-service testing, volumetric or resource-exhaustion attacks.
  • Social engineering of JibeONE personnel, customers, or users.
  • Physical attacks against facilities or hardware.
  • Testing of third-party services or infrastructure JibeONE does not control (including a customer's own on-premises or private-cloud environment).
  • Findings that require a compromised device, a rooted/jailbroken environment, or a user acting against their own interest.

4. Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. This authorization is limited to activity that stays within scope, does not access or modify data beyond what is necessary to demonstrate the issue, does not degrade the service, and does not disclose the issue publicly before we have resolved it. If legal action is initiated by a third party against you for activity conducted under this policy, we will make our authorization known.

5. Our commitments

  • Acknowledgement: we aim to acknowledge a report within three business days.
  • Assessment: we will triage, validate, and keep you informed of progress.
  • Resolution: we will work to remediate confirmed vulnerabilities on a timeline commensurate with severity.
  • Credit: with your permission, we will publicly credit researchers who report valid issues. We do not currently operate a paid bug-bounty program.

6. Coordinated disclosure

Please give us a reasonable opportunity to remediate before any public disclosure, and coordinate timing with us. We will not add contractual or legal terms that limit your ability to report.

7. Exclusions and governing law

This policy does not grant permission to act in any way that is inconsistent with the law or that would cause JibeONE to breach an obligation to a third party. Nothing here waives any right or remedy where activity falls outside the safe-harbor conditions above. Questions about this policy: security@jibe.one.