Vulnerability Disclosure Policy
JLS Technology USA, LLC · Effective October 8, 2026 · Version 1.0
JLS Technology USA welcomes reports from security researchers about vulnerabilities in the systems and software we operate or publish. This policy explains what is in scope, how to report, what you can expect from us, and the commitments we make in return. It also states how we handle vulnerabilities we discover in other people’s software.
Scope
In scope:
- jlstech.com and any subdomain of jlstech.com
- Software, tools, datasets, and research artifacts published by JLS Technology USA under our own name (for example, on our GitHub organization)
Out of scope:
- Systems belonging to our clients. We do not own those systems and cannot authorize testing against them. If you have found an issue in a client environment, report it to that organization directly.
- Third-party services we use but do not operate (hosting, email, SaaS platforms). Report those to the provider.
- Denial-of-service testing, volumetric testing, or anything that degrades availability
- Social engineering of JLS staff, contractors, or clients
- Physical attacks, and attacks requiring physical access
- Findings that only demonstrate a missing best-practice header, version banner, or configuration opinion without a demonstrated security impact
How to report
Email security@jlstech.com. Include the affected URL or artifact, steps to reproduce, the impact as you understand it, and any proof-of-concept material. Please do not include client data, personal data, or more detail than needed to demonstrate the issue. We accept reports in English, Spanish, and Portuguese.
Machine-readable contact details are published at https://jlstech.com/.well-known/security.txt.
What you can expect from us
- Acknowledgment of your report within 3 business days
- An initial assessment and severity classification within 10 business days
- Status updates at least every 30 days until resolution
- Credit in our public acknowledgments if you want it, once the issue is resolved
We do not currently operate a bug bounty program and do not pay for reports.
Our commitments to good-faith researchers
If you make a good-faith effort to comply with this policy while researching in-scope systems, we will consider your research authorized. We will not pursue or support legal action against you for that research, and we will work with you to understand and resolve the issue. If legal action is initiated by a third party against you for activity conducted in compliance with this policy, we will make it known that your actions were conducted in compliance with it.
Good faith means, at minimum:
- Stop and report as soon as you confirm a vulnerability. Do not use it to access, modify, or exfiltrate data beyond what is needed to demonstrate it.
- Do not access, retain, or share client data or personal data. If you encounter any, stop, report it, and delete what you have.
- Do not degrade availability, and do not pivot into other systems.
- Give us a reasonable time to remediate before public disclosure. Our default coordinated-disclosure window is 90 days from your report, which we will extend or shorten by mutual agreement.
How we disclose vulnerabilities we find in others’ software
JLS Technology USA performs security research, including on open-source software that organizations depend on. When we find a vulnerability in software we do not control:
- We report it privately to the maintainer or vendor first, through their published security contact or platform vulnerability-reporting feature.
- We follow a 90-day coordinated-disclosure window from the date of our report, extended when the maintainer is engaged and needs more time, and shortened if the issue is already being exploited or is publicly known.
- We publish only after a fix is available or the window has lapsed, and we withhold exploit detail that serves no defensive purpose.
- We do not test against systems we do not own or are not contractually authorized to test.
Changes to this policy
We may update this policy. The version and effective date at the top identify the current text.
Contact: security@jlstech.com · JLS Technology USA, LLC · jlstech.com