Security Contact & Responsible Disclosure

Reporting a Vulnerability

If you have discovered a potential security vulnerability in JIFFYAI's platform or infrastructure, we want to hear from you.

  • Contact: ciso@jiffy.ai
  • PGP key: Available on request — email ciso@jiffy.ai with subject “PGP Key Request” and we will respond within 24 hours.
  • Response time: We aim to acknowledge all reports within 24 hours and provide a resolution timeline within 5 business days.

Scope

The following systems and services are in scope for this programme:

In scope:

  • trust.jiffy.ai (Trust Center)
  • api.jiffy.ai (Platform API)
  • vigil.jiffy.ai (Security Programme OS)
  • *.jiffy.ai subdomains hosting customer-facing services

Out of scope:

  • Third-party services (AWS infrastructure, MongoDB Atlas, etc.)
  • Social engineering of JIFFYAI employees
  • Physical security testing
  • Denial of service attacks

Responsible Disclosure Policy

We ask that you:

  • Give us reasonable time to investigate and remediate before public disclosure.
  • Avoid accessing, modifying, or deleting data that does not belong to you.
  • Do not perform denial-of-service attacks or social engineering.

We commit to:

  • Acknowledge your report promptly.
  • Keep you informed of our progress.
  • Not pursue legal action against researchers acting in good faith.

General Security Enquiries

For general security questions, vendor security assessments, or compliance documentation requests, contact: ciso@jiffy.ai

For enterprise customers requiring a dedicated security review, please use the Request Access flow.