We audit other people’s systems every day, so we know what it takes to find a flaw and how awkward it is to report one without knowing whether anyone will listen. If you have found a vulnerability in our systems, this page tells you exactly how to reach us and what you can expect in return.
Last updated: 18 August 2026.
This policy covers only systems owned by JAYMON SECURITY S.L.:
jaymonsecurity.esand its subdomainsjaymonsecurity.comand its subdomains- Our corporate profiles and the mail infrastructure attached to those domains
- Stick to non-destructive testing and the minimum interaction needed to demonstrate the flaw.
- If you accidentally access personal or confidential data, stop, do not download it and tell us immediately.
- Do not disclose the finding publicly until we have fixed it or 90 days have passed since your report.
- Give us a reasonable window to remediate before considering the matter closed.
- Denial of service in any form, including load or stress testing.
- Social engineering, phishing or any technique aimed at our staff, clients or suppliers.
- Physical attacks against our premises or those of third parties.
- Mass brute forcing, spam, or any activity that degrades the service.
- Accessing, modifying, exfiltrating or destroying data that is not yours.
- Installing backdoors or persisting on the system beyond the proof of concept.
Write to info@jaymonsecurity.com with the subject “Responsible disclosure”. It helps us a great deal if you include:
- The affected system or URL.
- The vulnerability class and its potential impact.
- The steps needed to reproduce it, with screenshots or logs if you have them.
- How you would like to be credited, if you want public recognition.
- Acknowledgement within 2 hours during business hours (Monday to Friday, 9:00 to 18:00 CET, Madrid public holiday calendar).
- An initial technical assessment within 5 business days, telling you whether we confirm the flaw and how we have rated its severity.
- We will keep you updated on progress until the case is closed.
- We will credit you publicly if you wish, and respect your anonymity if you prefer.
If you research in good faith and comply with this policy, we will not initiate or support legal action against you in relation to your research, and we will consider your activity authorised.
This protection does not extend to conduct beyond what is described here, nor can it waive third-party rights. Should a third party take action against you over research conducted under this policy, we will confirm that you were acting with our authorisation.
We do not run a bug bounty programme and we do not offer financial compensation. What we do offer is a fast response, a technical conversation between equals, and public credit if you want it.

