Security

Responsible Disclosure

We take security seriously. If you've found a vulnerability in Just Domain, here's how to tell us — and what to expect after you do.

Version1.0
Effective DateJune 8, 2026
Last UpdatedJune 8, 2026
Applies tojustdomain.ai, mcp.justdomain.ai, and all Just Domain services

The short version

Email security@just-done.ai with the details. We’ll acknowledge within 2 business days and aim to triage within 5. Don’t publish or exploit the issue until we’ve had a chance to fix it. We won’t pursue legal action against good-faith researchers who follow this policy.

This policy is also machine-readable at /.well-known/security.txt per RFC 9116.

1.Reporting a Vulnerability

If you believe you’ve found a security vulnerability in any Just Domain service — the marketing site at justdomain.ai, the checkout flow, the MCP server at mcp.justdomain.ai (used by ChatGPT, Claude, and other AI assistants), or the webhook handler — please email security@just-done.ai with:

  • A clear description of the issue and where it lives.
  • Step-by-step reproduction instructions, ideally with a minimal proof of concept.
  • The impact you can see (what an attacker could do, who is affected).
  • Your name or handle if you’d like to be credited in the Hall of Thanks below.

Encrypted reports are welcome — drop us a line at the address above and we’ll exchange keys.

2.Scope

The following hosts are in scope:

  • justdomain.ai and any sub-route (marketing, checkout, account, dashboard).
  • sandbox.justdomain.ai — the staging mirror.
  • mcp.justdomain.ai and sandbox-mcp.justdomain.ai — the MCP server consumed by AI assistants.
  • webhooks.justdomain.ai and sandbox-webhooks.justdomain.ai — the Stripe webhook surface.

3.Out of Scope

We appreciate the effort, but the following classes of report are unlikely to result in a fix:

  • Missing security headers without a demonstrable impact (e.g. X-Content-Type-Options, Referrer-Policy without an exploit path).
  • Reports generated solely by automated scanners with no manual verification.
  • Self-XSS, clickjacking on pages with no sensitive state changes, or rate-limit bypasses on non-authentication endpoints.
  • Vulnerabilities in third-party services we depend on (Stripe, Openprovider, Vercel, Railway, WorkOS) — please report those directly to the vendor.
  • Outdated software versions without a working exploit specific to our deployment.
  • Social engineering of our team or contractors, physical attacks, and any testing that involves a real third party.

4.Our Response

We commit to the following timeline once we receive a valid report:

  • Within 2 business days — acknowledge receipt and assign a tracking handle.
  • Within 5 business days — an initial triage assessment with a severity rating and our planned next steps.
  • Continuous — updates as we make progress on the fix, until resolution.
  • After deploy — a final note confirming the fix and any follow-up monitoring.

5.Coordinated Disclosure

We ask that you give us a reasonable opportunity to fix a reported issue before you publish it. Our default disclosure window is 90 days from initial report; if we need more time we will say so and explain why. We will not gag you indefinitely.

If you believe an issue is being actively exploited or affects a meaningful number of users in real time, contact us immediately at the address above and we will treat it as a P0.

6.Safe Harbor

We will not pursue civil action or report you to law enforcement for security research conducted in good faith and in compliance with this policy.

“Good faith” means: you make a sincere effort to avoid privacy violations, data destruction, service degradation, or harm to our users; you only interact with accounts you own or have explicit permission to test; you stop and report as soon as you understand a vulnerability; and you do not exfiltrate more data than is needed to demonstrate the issue.

This safe harbor applies to our services only. It does not authorize you to act in a way that violates the policies of our vendors or any third-party services.

7.Recognition

Just Domain is an indie operation — we don’t (yet) run a paid bug bounty. We do, however, maintain a Hall of Thanks for researchers who help us stay safe. If you would like to be credited publicly, say so in your report and include the name or handle you would like us to use.

8.Contact

Primary: security@just-done.ai

General privacy questions: privacy@just-done.ai

Machine-readable policy: /.well-known/security.txt