Last updated: March 2026 — Vulnerability Disclosure & Security Practices
Found a security issue?
Please report it responsibly to security@joove.app — do not disclose it publicly until we have had a chance to address it.
JOOVE takes the security of our platform and the privacy of our users seriously. We implement industry-standard security measures including:
We welcome responsible disclosure from security researchers. If you discover a vulnerability in JOOVE, please follow these guidelines:
We confirm receipt of your report and provide a reference number.
We assess severity (Critical / High / Medium / Low) and begin investigation.
We aim to patch critical issues within 30 days. Medium/Low issues within 90 days.
We will notify you when the fix is live and coordinate any public disclosure.
JOOVE will not pursue legal action against security researchers who discover and responsibly disclose vulnerabilities in accordance with this policy. We consider responsible disclosure a valuable contribution to our security posture. This safe harbour applies provided the researcher: (a) acts in good faith, (b) does not access or harm user data beyond what is necessary to demonstrate the issue, and (c) reports to us before any public disclosure.
This policy applies to the following JOOVE systems:
Out of scope: third-party services (Supabase, Stripe, Vercel, PostHog) — please report vulnerabilities in those services directly to their security teams.
In the event of a data breach involving personal information, JOOVE will notify affected users and, where required, the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. We aim to notify within 30 days of becoming aware of a qualifying breach.
Security reports: security@joove.app
General privacy: privacy@joove.app