Vulnerability Disclosure Policy

JLS Technology USA, LLC · Effective October 8, 2026 · Version 1.0

JLS Technology USA welcomes reports from security researchers about vulnerabilities in the systems and software we operate or publish. This policy explains what is in scope, how to report, what you can expect from us, and the commitments we make in return. It also states how we handle vulnerabilities we discover in other people’s software.

Scope

In scope:

Out of scope:

How to report

Email security@jlstech.com. Include the affected URL or artifact, steps to reproduce, the impact as you understand it, and any proof-of-concept material. Please do not include client data, personal data, or more detail than needed to demonstrate the issue. We accept reports in English, Spanish, and Portuguese.

Machine-readable contact details are published at https://jlstech.com/.well-known/security.txt.

What you can expect from us

We do not currently operate a bug bounty program and do not pay for reports.

Our commitments to good-faith researchers

If you make a good-faith effort to comply with this policy while researching in-scope systems, we will consider your research authorized. We will not pursue or support legal action against you for that research, and we will work with you to understand and resolve the issue. If legal action is initiated by a third party against you for activity conducted in compliance with this policy, we will make it known that your actions were conducted in compliance with it.

Good faith means, at minimum:

How we disclose vulnerabilities we find in others’ software

JLS Technology USA performs security research, including on open-source software that organizations depend on. When we find a vulnerability in software we do not control:

Changes to this policy

We may update this policy. The version and effective date at the top identify the current text.


Contact: security@jlstech.com · JLS Technology USA, LLC · jlstech.com