This policy applies to Jivaro-operated services that link to it. A product, store, service, or venture policy controls when it addresses the same subject more specifically.
Systems in scope
Public websites, Pages Functions, forms, redirect handlers, downloadable files, and browser apps operated by Jivaro are in scope unless a page states otherwise. Third-party payment systems, cloud providers, venture domains operated by another legal entity, advertising networks, social accounts, and unrelated infrastructure are not authorized targets under this policy.
Good-faith testing rules
This policy does not authorize violations of law, contracts, privacy rights, or the terms of third-party systems.
- Use the minimum testing necessary to demonstrate the issue.
- Use accounts and data you own or have explicit permission to test.
- Stop immediately if personal, confidential, payment, authentication, or other non-public data becomes accessible.
- Do not perform denial-of-service testing, destructive actions, persistence, malware deployment, credential attacks, social engineering, spam, physical intrusion, or broad automated scanning that degrades service.
- Do not download, copy, alter, retain, or disclose data beyond what is necessary to document the finding.
What to include
Submit the affected URL or asset, prerequisites, safe reproduction steps, observed and expected behavior, potential impact, and any minimal proof needed to understand the issue. Remove secrets and personal data from screenshots or samples.
Jivaro may ask follow-up questions, confirm receipt, reproduce the issue, prioritize a repair, and coordinate a reasonable disclosure timeline. Submission does not create an employment, contractor, or confidential relationship.
Safe-harbor intent and rewards
When research is conducted in good faith and stays within this policy, Jivaro's intent is to treat it as authorized security research and not pursue action merely for bypassing a technical control to demonstrate the reported issue. Jivaro cannot bind third parties or law-enforcement authorities and may act where conduct is harmful, deceptive, unlawful, or outside the policy.
There is no standing bug bounty, payment promise, public credit guarantee, or reward unless Jivaro agrees to it in writing before the work. Do not publicly disclose an unresolved vulnerability before Jivaro has had a reasonable opportunity to investigate and reduce risk.
Contact and updates
Questions about this policy can be sent through the official contact form. Security reports and corrections should use their dedicated categories. Jivaro may update this policy prospectively when operations, law, or services change; the effective and review dates identify the published version.

