Report a Security Vulnerability

We take security seriously and appreciate reports that help keep JobGPT safe for students and teams.

Responsible Disclosure

If you discover a security vulnerability in JobGPT, please report it to us responsibly. We're committed to working with security researchers to verify and address any potential vulnerabilities.

Please give us a reasonable opportunity to investigate before publicly disclosing a report. We ask researchers to avoid accessing, modifying, deleting, or sharing another user's data while validating an issue.

How to Report

Email us at security@jobmagical.com with:

  • A detailed description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Your contact information

Our Commitment

We will acknowledge your report within 48 hours and provide regular updates on our progress. We will not take legal action against security researchers who report vulnerabilities responsibly.

What to Include

Clear Reproduction

Include the affected URL, account state, browser details, and the smallest set of steps needed to reproduce the issue.

Evidence

Screenshots, request logs, proof-of-concept notes, and impact details help us triage faster.

Scope

Focus on JobGPT-owned web properties, authentication flows, data handling, and account security.

Safe Testing

Do not run destructive tests, degrade service, or attempt to access information that is not yours.

Bug Bounty Program

We offer rewards for valid security vulnerabilities. Rewards range from $100 to $5,000 depending on severity and impact.

Reward decisions consider exploitability, data exposure risk, report quality, and whether the issue has already been reported or is already known to the team.