Security Contact & Responsible Disclosure
Reporting a Vulnerability
If you have discovered a potential security vulnerability in JIFFYAI's platform or infrastructure, we want to hear from you.
- Contact: ciso@jiffy.ai
- PGP key: Available on request — email ciso@jiffy.ai with subject “PGP Key Request” and we will respond within 24 hours.
- Response time: We aim to acknowledge all reports within 24 hours and provide a resolution timeline within 5 business days.
Scope
The following systems and services are in scope for this programme:
In scope:
- trust.jiffy.ai (Trust Center)
- api.jiffy.ai (Platform API)
- vigil.jiffy.ai (Security Programme OS)
- *.jiffy.ai subdomains hosting customer-facing services
Out of scope:
- Third-party services (AWS infrastructure, MongoDB Atlas, etc.)
- Social engineering of JIFFYAI employees
- Physical security testing
- Denial of service attacks
Responsible Disclosure Policy
We ask that you:
- Give us reasonable time to investigate and remediate before public disclosure.
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Do not perform denial-of-service attacks or social engineering.
We commit to:
- Acknowledge your report promptly.
- Keep you informed of our progress.
- Not pursue legal action against researchers acting in good faith.
General Security Enquiries
For general security questions, vendor security assessments, or compliance documentation requests, contact: ciso@jiffy.ai
For enterprise customers requiring a dedicated security review, please use the Request Access flow.