Home › Shopping Policies

Report Security Issues

Last Updated: May 28, 2026
If you have discovered a security vulnerability on jepordy.com, we encourage you to report it to us immediately. Jepordy LLC takes the security of our platform and our customers' data very seriously. We review all legitimate reports and aim to resolve confirmed issues as quickly as possible. Please read this page carefully before submitting a report.

Submit a Vulnerability Report

Use the subject line: "Security Vulnerability Report – jepordy.com" and include reproducible steps.

Report a Vulnerability

1Fundamentals (Safe-Harbor Rules)

If you follow the principles below when reporting a security issue to jepordy.com, Jepordy LLC will not initiate legal action or enforcement investigations against you in response to your report. This represents our good-faith safe-harbor commitment to security researchers.

We ask that you:

  1. Give us reasonable time to review and fix the issue before disclosing it publicly or sharing it with others — generally a minimum of 90 days from acknowledgment.
  2. Do not interact with or access private accounts without the account owner's explicit consent.
  3. Make a good-faith effort to avoid privacy violations, service disruptions, destruction of data, or interruption of generator orders in progress.
  4. Do not exploit the vulnerability for any reason, including to demonstrate further risks or access sensitive data beyond what is strictly necessary to confirm the issue.
  5. Comply with all applicable local, state, and federal laws and regulations — including the U.S. Computer Fraud and Abuse Act (CFAA).
  6. Use only your own test accounts or accounts for which you have written authorization.

2Bounty Program

Jepordy LLC recognizes and rewards security researchers who help protect our platform by responsibly reporting vulnerabilities. Bounties are awarded at Jepordy LLC's sole discretion, based on risk level, impact, and report quality.

To potentially qualify for a bounty, you must:

  1. Follow all fundamentals listed above.
  2. Report a valid security vulnerability that poses a genuine risk to user privacy or platform security.
  3. Submit your report directly to Contact@jepordy.com — please do not contact employees directly or post on social media.
  4. Disclose any accidental privacy violations or service disruptions that occurred during your research.
  5. Understand that while we investigate all valid reports, response priority is based on risk severity and may take time.
  6. Agree that Jepordy LLC reserves the right to publish submitted reports at our discretion, with the reporter's credit (or anonymously, at the reporter's request).

3Severity Tiers & Rewards

Rewards are based on the impact and severity of the reported vulnerability. Please provide detailed and reproducible steps in your report — issues that cannot be reproduced are not eligible for a bounty.

  • The first valid report of a given issue receives the bounty.
  • Multiple bugs caused by a single underlying issue are treated as one report.
  • We assess rewards based on impact, exploitability, and overall report quality.

Critical Severity

$200
  • Remote Code Execution (RCE)
  • Remote Shell or Command Execution
  • Vertical Authentication Bypass
  • SQL Injection leaking targeted data
  • Full account takeover

High Severity

$100
  • Lateral authentication bypass
  • Disclosure of sensitive internal data
  • Stored XSS affecting other users
  • Local file inclusion (LFI)
  • Insecure handling of authentication cookies

Medium Severity

$50
  • Logic or business process flaws
  • Insecure direct object references (IDOR)
  • CSRF on sensitive actions
  • Unvalidated redirects to external sites

Low Severity

Recognition Only
  • Open redirects
  • Reflected XSS
  • Low-sensitivity information leaks
  • Missing security headers

4Non-Reportable Issues

The following are generally out of scope and not eligible for a bounty:

  • Denial of Service (DoS / DDoS) attacks or testing
  • Spam or social engineering attacks against Jepordy LLC staff
  • Physical security issues (warehouse, office, freight)
  • Vulnerabilities in third-party services or plugins not directly controlled by Jepordy LLC (e.g., WooCommerce core, WordPress core, Cloudflare, Stripe, PayPal)
  • Reports generated solely by automated scanning tools without manual validation
  • Issues already known to our team or previously reported
  • Best-practice recommendations without a demonstrated security impact
  • Self-XSS that requires the victim to paste code into their own browser console
  • SPF, DKIM, or DMARC misconfigurations without a demonstrated phishing impact
  • Outdated software versions without a proven exploitable vulnerability

5How to Submit a Report

To report a security vulnerability, please send an email to Contact@jepordy.com with the subject line:

Security Vulnerability Report – jepordy.com

Your report should include:

  • A clear, technical description of the vulnerability
  • Step-by-step instructions to reproduce the issue
  • The potential impact and worst-case scenario
  • Any screenshots, videos, or proof-of-concept code (if applicable)
  • The URL, endpoint, or specific page affected
  • Your preferred attribution (your name, handle, or anonymous)
Our commitment to you: We will acknowledge your report within 3 business days and keep you informed of our progress throughout the resolution process. Critical and High severity issues are typically triaged within 24 hours.

Security Contact

Questions about our security disclosure program, scope, or an in-progress report? Get in touch — we typically respond within one business day.

Business Hours: Monday – Friday 9:00 AM – 6:00 PM CST  ·  Saturday & Sunday Closed