SECURITY & VULNERABILITY DISCLOSURE
Help us keep JibeONE safe.
Report a vulnerability. Get a fast, respectful response. We do not litigate good-faith research.
Draft for legal review. Subject to revision. Last updated: 5 July 2026.
We welcome reports from security researchers and take them seriously. This page describes how to report a suspected vulnerability in JibeONE, what is in and out of scope, and the protections we extend to good-faith researchers.
1. Report a vulnerability
Email security@jibe.one. For sensitive reports, please encrypt using the PGP key published at /.well-known/pgp-key.txt. Include enough detail to reproduce the issue: affected component or URL, steps, impact, and any proof-of-concept. Our machine-readable policy is published at /.well-known/security.txt per RFC 9116.2. In scope
The JibeONE platform and this website, and services JibeONE operates and controls.3. Out of scope
- Denial-of-service testing, volumetric or resource-exhaustion attacks.
- Social engineering of JibeONE personnel, customers, or users.
- Physical attacks against facilities or hardware.
- Testing of third-party services or infrastructure JibeONE does not control (including a customer's own on-premises or private-cloud environment).
- Findings that require a compromised device, a rooted/jailbroken environment, or a user acting against their own interest.
4. Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. This authorization is limited to activity that stays within scope, does not access or modify data beyond what is necessary to demonstrate the issue, does not degrade the service, and does not disclose the issue publicly before we have resolved it. If legal action is initiated by a third party against you for activity conducted under this policy, we will make our authorization known.5. Our commitments
- Acknowledgement: we aim to acknowledge a report within three business days.
- Assessment: we will triage, validate, and keep you informed of progress.
- Resolution: we will work to remediate confirmed vulnerabilities on a timeline commensurate with severity.
- Credit: with your permission, we will publicly credit researchers who report valid issues. We do not currently operate a paid bug-bounty program.