Security

Reporting a security vulnerability

If you believe you have found a security vulnerability in the Jepify app, its services or this website, please tell us privately at security@dynamikus.com. We read every report.

How to report

What to include

The app version or page, your device and operating system, the steps to reproduce, and what an attacker could achieve. Screenshots or a short video help.

Please do not include

Real children's or families' personal data. Use your own test account. If you came across someone else's data, stop, do not keep a copy, and tell us what you saw.

What happens next

We confirm that we received your report, assess it, and keep you informed until it is resolved. Tell us if you would like to be credited when we publish a fix.

Our disclosure policy

What is in scope?

The Jepify mobile app for Android and iOS, the Jepify backend services it uses, and jepa.dynamikus.com. Third-party services we use, such as app stores and cloud providers, have their own reporting channels.

What we ask of you

Give us reasonable time to fix the issue before telling anyone else. Only test against your own accounts, do not access or change other people's data, and do not run tests that could disrupt the service for families, such as denial of service, spam or social engineering.

What we commit to

We handle every report in good faith and welcome research that follows this policy. We fix confirmed vulnerabilities and provide security updates free of charge through the App Store and Google Play.

Do you pay bug bounties?

No. Jepify does not run a paid bug bounty programme.

Where are fixed vulnerabilities published?

After a fix is available, we publish a short security advisory on this page with the affected versions, the impact and what users should do.

Is there a machine-readable contact?

Yes: /.well-known/security.txt (RFC 9116).

Keeping Jepify secure

Install updates when your device offers them: security fixes reach you through the App Store and Google Play. Keep your phone locked with a passcode, and keep the parent account’s sign-in details to yourself.

Security advisories

No security advisories have been published.