JobsAI Security
Security and responsible vulnerability disclosure
We thank security researchers for responsible testing and vulnerability reporting. These rules follow the compliance baseline in the project documentation and the public RFC 9116 security.txt.
How to report a vulnerability
Send a description to [email protected]. Include the affected URL or endpoint, reproduction steps, impact, and an optional proof of concept.
An optional PGP key will be published at /.well-known/pgp-key.txt. Until then, do not send sensitive data - request a secure transfer channel instead.
SLA and fix priorities
We will perform initial triage within 5 business days. Fixes are planned according to severity:
| Severity | Fix target |
|---|---|
| Critical | fix or mitigation within 7 days |
| High | fix within 30 days |
| Medium | fix within 90 days |
| Low | best-effort based on impact |
Safe harbor
If you test in good faith, stay within scope, and report findings without unnecessary delay, we will not take legal action against you for the security testing itself.
- Do not access or download user data; demonstrate only minimal impact.
- Do not run DoS, volumetric tests, or tests that disrupt service availability.
- Do not use automated scanners without prior contact and consent.
- Do not perform social engineering against employees, contractors, or users.
In scope
*.jobsai.cz- Public and agent endpoints of JobsAI
- MCP, A2A and ACP mirrors and integration interfaces
Out of scope
- Third-party services: Stripe, GoPay, Mapy.cz, Datová schránka and Azure infrastructure
- DoS, DDoS and volumetric attacks
- Social engineering against the team or partners
Acknowledgements
Signed and verified reports may be published in the hall of fame by agreement: /bezpecnost/sin-slavy.