Security
How to report a security vulnerability in Jonzy Relocation, safe harbour terms, scope, and what to expect after you disclose.
How to report
Email us with the subject line “Security report, Jonzy”. Include the affected URL or feature, steps to reproduce, and the impact you believe it has. Please do not open a public GitHub issue for security reports — we aim to acknowledge valid reports within five business days.
Safe harbour
We welcome good-faith research. Do not access other users' data beyond what is needed to demonstrate an issue, do not degrade the service, and give us reasonable time to fix before public disclosure. Jonzy does not currently run a paid bug bounty program, but we credit researchers when they ask and a fix ships.
Out of scope
- Prototype billing mode that unlocks Pro without payment in non-production builds
- Information intentionally public (city guides, community posts, compare-share snapshots)
- Third-party infrastructure except where our integration is clearly at fault