A division of Jiranisoko Market Ltd
JIRANISOKO Tech
Solutions

Security

Responsible disclosure policy

If you have found a vulnerability in a system we operate, we want to hear about it, and we will not take action against you for telling us in good faith.

How to report

Send your report to Gate G-07 — security address not configured with enough detail to reproduce the issue: the affected system, the steps taken, and the impact you believe it has. Proof-of-concept code is welcome. Please do not include third party personal data in the report.

What we commit to

Acknowledgement
Within two business days of receipt.
Triage
An initial severity assessment and our intended course of action within ten business days.
Progress
Updates at least every fifteen business days until the issue is resolved or we explain why it will not be.
Credit
Public acknowledgement on request, once the issue is remediated.
Good faith
We will not pursue legal action against a researcher who follows this policy, and we will say so in writing if you ask.

Scope and boundaries

This policy covers systems operated by Jiranisoko Tech Solutions. It does not extend to systems belonging to our clients: if you believe you have found an issue in a system we built but do not operate, report it to us and we will route it to the operator rather than act on it ourselves.

Please do not

  • Access, modify or delete data belonging to anyone other than yourself
  • Degrade service availability, including through automated load or denial of service testing
  • Use social engineering, phishing or physical intrusion against our staff or premises
  • Disclose the issue publicly before we have had a reasonable opportunity to remediate it
On timelines

We do not operate a bug bounty and make no offer of payment. The commitments above are about responsiveness, which in our experience is what researchers actually want from a disclosure process.