Overview
Security is a top priority at Juni. We manage financial data that is strictly confidential to our customers, and we take that responsibility very seriously.
If you’ve discovered a vulnerability that may in some way compromise the confidentiality, integrity, or availability of our systems, please report it to us as soon as possible so we can take appropriate action.
How to report a vulnerability
Reporting Channel
Please send your report via email to: security@juni.co.
What the report should include
For us to quickly analyze, confirm, and resolve your finding, we ask you to include the following details in your report:
Reproduction steps: Concrete, clear, and detailed steps that we can follow to reproduce the vulnerability
Affected resources: Information about which platforms, services, or exposed resources are affected (e.g., IP addresses, domain names, URLs, version numbers)
Supporting evidence: Any additional information that supports your claim (e.g., logs, screenshots, or traces)
What you should do
Let us know as soon as possible upon discovery of a potential security issue
Provide us with a reasonable amount of time to resolve the issue before any disclosure to the public or a third party
Make a good faith effort to avoid privacy violations and interruption or service degradation of our service
Respect the privacy of our customers. Only test using accounts you own or where you have explicit permission from the account holder
What you should avoid
Break the law
Test third-party services not owned by Juni (e.g., anything registered as
juni.{thirdpartydomain}.com)Modify, copy, or remove any Juni data
Perform any of the following attack types:
Denial of Service (DoS/DDoS)
Spamming
Social Engineering (including Phishing) of Juni staff, contractors, or customers
Access or make changes to customer accounts
Do any lateral movement and post-exploitation within Juni infrastructure
Bug bounty and public disclosure
Bug bounty
We are not currently offering a bug bounty program.
Public disclosure
Public disclosures of any vulnerabilities (e.g., through social media or the press) can put our community at risk. Therefore, confidentiality is crucial. All disclosures should be made in accordance with our Responsible Disclosure Policy so that we can focus on resolving any issues as soon as possible. We reserve the right to take legal action if this policy is not followed.
