Vulnerability Disclosure Policy
How to report a security vulnerability to Jooni, what is in scope, and what you can expect from us in return.
Last updated:
Related: Security, Acceptable Use Policy, and Terms of Use.
1. Purpose and what to expect
Jooni values the work of security researchers and welcomes reports of vulnerabilities in our products and services. This policy describes what you may test, how to tell us what you found, and what we commit to in return. It applies to anyone who reports a vulnerability to us, whether a researcher, a customer, a partner, or a member of the public.
If you follow this policy, we will work with you in good faith: we will acknowledge your report, keep you informed as we investigate and fix the issue, and credit you if you wish.
2. In scope
- jooni.com and the subdomains that Jooni operates.
- jooni.io and the production subdomains that Jooni operates.
- Our status page (status.jooni.com) — the content and configuration Jooni controls. The status page is hosted by a third party; the host's own platform and infrastructure are out of scope and should be reported to them.
- Jooni Module hardware and firmware.
If you are not sure whether something is in scope, ask us first at security@jooni.com before you test.
3. Out of scope
- Development, staging, and other non-production environments on any Jooni domain.
- Denial-of-service, volumetric, load, or stress testing of any kind.
- Social engineering or phishing of Jooni employees, contractors, customers, or partners.
- Physical attacks on Jooni facilities, personnel, or equipment you do not own.
- Third-party services, platforms, and infrastructure that Jooni does not operate — report those to the provider.
- Customer deployments and networks. Testing a customer's installation requires that customer's own authorization.
- Reports of missing best practices or automated scanner output without a demonstrated security impact.
4. Testing rules
- Test only systems that are in scope, and only accounts, devices, and data that you own or are authorized to test.
- Do the minimum needed to demonstrate the issue. Stop as soon as you have sufficient proof.
- Do not access, copy, modify, delete, or retain data that is not your own, including other customers' data. If you encounter another party's data, stop and tell us.
- Do not install persistent access, pivot to other systems, or degrade the availability of any service, including through automated scanning.
- Do not disclose the issue publicly, or to third parties, before we have coordinated disclosure with you (see section 8).
5. Good-faith safe harbor
If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, Jooni will consider your research authorized with respect to Jooni's own in-scope systems, products, and services, and will not pursue or support legal action against you for it. We will work with you to understand and resolve the issue, and we will not refer your activity to law enforcement unless we reasonably believe you acted in bad faith or outside this policy.
This commitment is made by Jooni only. It cannot authorize activity against third parties, and it does not bind our service providers, hosting partners, or customers, whose systems and terms remain their own. If a third party takes action against you for research you conducted in good faith under this policy, we will, on request, confirm to them that your activity was carried out in accordance with it. This policy is not a licence to break any law; you remain responsible for complying with the laws that apply to you.
6. How to report
Email security@jooni.com. Please include, as far as you can:
- The product or service affected — for hardware, the device model and firmware version; for web services, the URL.
- The type of issue and its potential impact.
- Steps to reproduce, including any proof-of-concept code, requests, or screenshots.
- Your contact details, and whether you would like to be credited (and under what name or handle).
Do not include anyone else's personal or customer data in your report. If your report contains sensitive material, say so in your first email and we will agree with you how to share it.
7. What happens next
- Acknowledgment: we will acknowledge your report within 3 business days.
- Triage: we will validate the issue, assess its severity, and tell you our initial assessment.
- Status updates: while the report is open we will keep you informed of progress at least every 30 days, and whenever something material changes.
- Remediation: we prioritize fixes by severity and exposure. Fixes for fielded hardware and firmware can take longer than fixes for web services because they depend on release cycles and customer roll-outs.
- Closure: we will tell you when the issue is fixed and agree the disclosure with you (see section 8).
8. Coordinated disclosure
We ask that you give us 90 days from the date of your report before disclosing the issue publicly. This is a coordination window, not a guaranteed fix deadline: some issues, particularly in fielded hardware and firmware, take longer to fix and roll out. If we need more time we will tell you why and agree an extension with you. Where an issue is being actively exploited or poses an urgent risk to the public, we may agree with you to disclose sooner.
When we publish details of a fixed issue, we will credit you if you wish. We will not publish your name or handle without your consent.
9. Acknowledgments
We thank everyone who reports vulnerabilities to us in good faith. With your consent, we will list your name or handle here once the issue has been resolved. No acknowledgments have been published yet.