
Legal
Security and responsible disclosure — jerne.com
If you find a security problem, tell us first. Write to security@jerne.com. We will acknowledge within one business day, keep you informed, and tell you when it is fixed. We will not take legal action against research that follows this policy, and we ask that you do not access, change or keep any data that is not your own, do not disrupt the service, and give us a reasonable time to fix a problem before you talk about it publicly.
In scope: jerne.com and its subdomains, the brand portal, the public API and the MCP endpoint, and the emails we send. Out of scope: denial of service, social engineering of our staff or curators, physical attacks, findings in third-party services we use (report those to the provider), and reports from automated scanners with no demonstrated impact.
What we do ourselves. Dependencies are scanned on every build and security patches are applied within seven days for anything reachable from the internet; container images are scanned before they deploy; a web application firewall sits in front of every public surface; access to production is by named individual accounts with a second factor; recordings and transcripts of support contacts are deleted twelve months after the contact. We have not yet commissioned an external penetration test and will say so to anyone who asks until we have.
We do not pay bounties. We will credit you here, with your permission, when a report leads to a fix.
Last reviewed: 15 September 2026.
© 2026 Jerne Group Inc. · Suite 5600, 100 King Street West, Toronto, Ontario, M5X 1C9, Canada