Skip to main content
Security disclosure

Report vulnerabilities safely.

We welcome good-faith reports that help protect testers, buyers, payouts, and customer research data. We do not run a paid bounty yet, but we acknowledge valid reports and credit researchers with consent.

Safe scope

  • www.9jatesters.com public application routes and unauthenticated API behavior.
  • Public authentication, order, signup, and API behavior without attempting credential theft or data exfiltration.
  • Authorization flaws that expose your own account data or demonstrably cross tenant boundaries in a safe proof.
  • Payment, webhook, cron, upload, and media-access issues that can be shown without harming real users.

Out of scope

  • Social engineering, phishing, spam, denial-of-service, or physical attacks.
  • Accessing, modifying, deleting, or publishing another person's data.
  • Automated high-volume scanning that degrades service availability.
  • Reports that only state missing certifications, missing bug bounty, or theoretical clickjacking where headers already deny framing.

Response targets

Email [email protected] with the subject "Security disclosure". Include the affected URL, impact, reproduction steps, and whether any data was accessed. We target acknowledgement within 24 hours, triage within 3 business days, and remediation for critical issues within 30 days where a safe temporary mitigation is not enough.

Please stop testing and notify us immediately if you encounter real user data, payment data, payment-verification data, private recordings, or admin-only information.