Responsible disclosure policy

SecurityResponsible disclosure policy

We audit other people’s systems every day, so we know what it takes to find a flaw and how awkward it is to report one without knowing whether anyone will listen. If you have found a vulnerability in our systems, this page tells you exactly how to reach us and what you can expect in return.

Last updated: 18 August 2026.

Systems in scope

This policy covers only systems owned by JAYMON SECURITY S.L.:

  • jaymonsecurity.es and its subdomains
  • jaymonsecurity.com and its subdomains
  • Our corporate profiles and the mail infrastructure attached to those domains
Our clients’ systems are expressly out of scope. The fact that we audit an organisation’s infrastructure does not authorise you to test it. If you have found something on a client system, contact that system’s owner, not us.
What we ask of you

  • Stick to non-destructive testing and the minimum interaction needed to demonstrate the flaw.
  • If you accidentally access personal or confidential data, stop, do not download it and tell us immediately.
  • Do not disclose the finding publicly until we have fixed it or 90 days have passed since your report.
  • Give us a reasonable window to remediate before considering the matter closed.
What is not permitted

  • Denial of service in any form, including load or stress testing.
  • Social engineering, phishing or any technique aimed at our staff, clients or suppliers.
  • Physical attacks against our premises or those of third parties.
  • Mass brute forcing, spam, or any activity that degrades the service.
  • Accessing, modifying, exfiltrating or destroying data that is not yours.
  • Installing backdoors or persisting on the system beyond the proof of concept.
How to report

Write to info@jaymonsecurity.com with the subject “Responsible disclosure”. It helps us a great deal if you include:

  • The affected system or URL.
  • The vulnerability class and its potential impact.
  • The steps needed to reproduce it, with screenshots or logs if you have them.
  • How you would like to be credited, if you want public recognition.
Our commitment

  • Acknowledgement within 2 hours during business hours (Monday to Friday, 9:00 to 18:00 CET, Madrid public holiday calendar).
  • An initial technical assessment within 5 business days, telling you whether we confirm the flaw and how we have rated its severity.
  • We will keep you updated on progress until the case is closed.
  • We will credit you publicly if you wish, and respect your anonymity if you prefer.
Good faith research

If you research in good faith and comply with this policy, we will not initiate or support legal action against you in relation to your research, and we will consider your activity authorised.

This protection does not extend to conduct beyond what is described here, nor can it waive third-party rights. Should a third party take action against you over research conducted under this policy, we will confirm that you were acting with our authorisation.

No bug bounty

We do not run a bug bounty programme and we do not offer financial compensation. What we do offer is a fast response, a technical conversation between equals, and public credit if you want it.

Machine-readable contact details at /.well-known/security.txt, per RFC 9116.
ENES