If you think you've found a security vulnerability in JSONPad, please tell us privately so we can fix it before anyone else finds it. We're grateful for every report made in good faith.
Email contact@jsonpad.io with "Security report" in the subject. Please don't report vulnerabilities in public GitHub issues, social media or anywhere else public.
It helps if your report includes:
JSONPad is run by a very small team, so please bear with us. We aim to:
Fixed security issues are listed in the changelog, under "Security", once the fix is live.
We don't currently run a paid bug bounty programme, so we can't offer rewards for reports.
We won't pursue or support legal action against anyone who finds and reports a vulnerability in good faith and follows these guidelines:
In scope: jsonpad.io and its subdomains (including the API, realtime and MCP servers), and the official JSONPad SDKs and npm packages.
Usually not in scope, unless you can show a concrete way to exploit it: output from automated scanners, missing best-practice headers, software version disclosure, rate limits, and issues that need an already-compromised device or browser.
For anything that isn't a security issue, such as a bug or a problem with your account, email us at contact@jsonpad.io or open an issue.
This policy is also published as a security.txt file.