Report a Security Vulnerability
We take security seriously and appreciate reports that help keep JobGPT safe for students and teams.
Responsible Disclosure
If you discover a security vulnerability in JobGPT, please report it to us responsibly. We're committed to working with security researchers to verify and address any potential vulnerabilities.
Please give us a reasonable opportunity to investigate before publicly disclosing a report. We ask researchers to avoid accessing, modifying, deleting, or sharing another user's data while validating an issue.
How to Report
Email us at security@jobmagical.com with:
- A detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Your contact information
Our Commitment
We will acknowledge your report within 48 hours and provide regular updates on our progress. We will not take legal action against security researchers who report vulnerabilities responsibly.
What to Include
Clear Reproduction
Include the affected URL, account state, browser details, and the smallest set of steps needed to reproduce the issue.
Evidence
Screenshots, request logs, proof-of-concept notes, and impact details help us triage faster.
Scope
Focus on JobGPT-owned web properties, authentication flows, data handling, and account security.
Safe Testing
Do not run destructive tests, degrade service, or attempt to access information that is not yours.
Bug Bounty Program
We offer rewards for valid security vulnerabilities. Rewards range from $100 to $5,000 depending on severity and impact.
Reward decisions consider exploitability, data exposure risk, report quality, and whether the issue has already been reported or is already known to the team.