Report a security vulnerability
Found a possible weakness affecting JusFund? Report it privately, with enough detail to help us investigate.
Start with a short report.
Email us with “Security vulnerability” in the subject. Describe the issue without sending confidential case material.
info@jusfund.techHelp us understand the issue.
- The affected page, feature or URL.
- What happened, what you expected, and the potential impact.
- Steps to reproduce using your own account and harmless test data.
- When it happened and any relevant browser or device details.
- A way to contact you for clarification, if you are comfortable providing one.
Keep the report to what is needed.
Remove names, document contents, passwords, session tokens and private links from screenshots or logs. If evidence cannot be shared safely by email, describe what you have and ask how to provide it securely.
If you encounter another person’s information, stop. Do not browse further, download it or share it. Report the location and the circumstances without including the information itself.
Avoid putting users or services at risk.
This guidance concerns JusFund’s website and application. It does not authorise access to other people’s accounts or testing of our providers’ infrastructure.
- Use only accounts and data you own or have explicit permission to use.
- Do not disrupt availability, alter or delete other users’ data, guess credentials, or use social engineering.
- Do not continue testing once you have enough information to explain the suspected weakness.
Give us the chance to investigate.
We use reports to investigate suspected weaknesses and may ask for clarification. Please coordinate any public disclosure with us so that affected information can be protected while the issue is assessed.
A report does not need to contain a working exploit or confidential data. A clear description is a useful starting point.
Need help with something else?
For account support or questions about your information, use the relevant contact route.