JobsAI Security

Security and responsible vulnerability disclosure

We thank security researchers for responsible testing and vulnerability reporting. These rules follow the compliance baseline in the project documentation and the public RFC 9116 security.txt.

How to report a vulnerability

Send a description to [email protected]. Include the affected URL or endpoint, reproduction steps, impact, and an optional proof of concept.

An optional PGP key will be published at /.well-known/pgp-key.txt. Until then, do not send sensitive data - request a secure transfer channel instead.

SLA and fix priorities

We will perform initial triage within 5 business days. Fixes are planned according to severity:

SeverityFix target
Criticalfix or mitigation within 7 days
Highfix within 30 days
Mediumfix within 90 days
Lowbest-effort based on impact

Safe harbor

If you test in good faith, stay within scope, and report findings without unnecessary delay, we will not take legal action against you for the security testing itself.

  • Do not access or download user data; demonstrate only minimal impact.
  • Do not run DoS, volumetric tests, or tests that disrupt service availability.
  • Do not use automated scanners without prior contact and consent.
  • Do not perform social engineering against employees, contractors, or users.

In scope

  • *.jobsai.cz
  • Public and agent endpoints of JobsAI
  • MCP, A2A and ACP mirrors and integration interfaces

Out of scope

  • Third-party services: Stripe, GoPay, Mapy.cz, Datová schránka and Azure infrastructure
  • DoS, DDoS and volumetric attacks
  • Social engineering against the team or partners

Acknowledgements

Signed and verified reports may be published in the hall of fame by agreement: /bezpecnost/sin-slavy.