Reporting security issues

If you think you've found a security vulnerability in JSONPad, please tell us privately so we can fix it before anyone else finds it. We're grateful for every report made in good faith.

How to report

Email contact@jsonpad.io with "Security report" in the subject. Please don't report vulnerabilities in public GitHub issues, social media or anywhere else public.

It helps if your report includes:

  • what you found, and which part of JSONPad it affects
  • steps to reproduce it, or a proof of concept
  • what you think an attacker could do with it, and anything that limits that (for example, whether it needs a victim to click something)
  • how you'd like to be credited, if at all

What to expect from us

JSONPad is run by a very small team, so please bear with us. We aim to:

  • acknowledge your report within a few working days
  • let you know whether we can reproduce it, and what we plan to do
  • keep you updated until it's fixed, and tell you when it is
  • credit you on this page, if you'd like us to

Fixed security issues are listed in the changelog, under "Security", once the fix is live.

We don't currently run a paid bug bounty programme, so we can't offer rewards for reports.

Testing guidelines

We won't pursue or support legal action against anyone who finds and reports a vulnerability in good faith and follows these guidelines:

  • Only use accounts, lists and tokens that you own, or that you have permission from their owner to use.
  • Don't access, change or delete other people's data. If you come across any by accident, stop, don't keep a copy, and tell us.
  • Don't degrade the service for others: no denial of service, load testing or high-volume automated scanning.
  • No social engineering, phishing or physical attacks.
  • Give us a reasonable amount of time to fix the issue before you disclose it publicly, and agree the timing with us.

Scope

In scope: jsonpad.io and its subdomains (including the API, realtime and MCP servers), and the official JSONPad SDKs and npm packages.

Usually not in scope, unless you can show a concrete way to exploit it: output from automated scanners, missing best-practice headers, software version disclosure, rate limits, and issues that need an already-compromised device or browser.

For anything that isn't a security issue, such as a bug or a problem with your account, email us at contact@jsonpad.io or open an issue.

This policy is also published as a security.txt file.