1. Overview
JAMMY GROUP INC. welcomes good-faith reports of suspected security vulnerabilities affecting our websites, applications, APIs, and other publicly accessible systems. Reports may be sent to webdev@jammygroup.ca.
This policy explains which systems and research activities are covered, how to minimize harm, what information helps us investigate, and how we approach compliant good-faith research. It is not a bug-bounty program and does not authorize conduct prohibited by law.
2. Systems in scope
This policy applies only to publicly accessible websites, applications, APIs, and related systems that JAMMY GROUP INC. owns and operates. If ownership is unclear, contact us before testing.
Third-party products, platforms, infrastructure, payment systems, ticketing systems, identity providers, stores, venues, partner services, and vendor systems are outside scope unless JAMMY expressly identifies a specific asset as included. Report a vulnerability in a third-party service to that provider under its policy.
Private, internal, development, administrative, employee, event-operations, booth, device, network, or physical systems are outside scope unless they are publicly accessible to you through an ordinary authorized account and the testing otherwise follows this policy.
3. What to include in a report
Include, where reasonably possible:
- the affected service, page, URL, application, API, or feature;
- a clear description of the suspected vulnerability and its potential impact;
- the minimum steps needed for us to reproduce the issue;
- relevant device, browser, application-version, or operating-system information;
- the date and approximate time of testing; and
- screenshots, logs, request details, or other supporting evidence with credentials and personal information removed or obscured.
Send one clear report for related findings when practical. Do not submit an exploit package, executable code, or sensitive data when a minimized description or redacted evidence is sufficient.
4. Research requirements
Security research must avoid harm to JAMMY, our users, event participants, partners, service providers, and the public. You must:
- test only in-scope systems that are publicly accessible to you;
- use only accounts, devices, tickets, content, and data that belong to you or that you are expressly authorized to use;
- make only the minimum access or interaction necessary to demonstrate the suspected issue;
- stop testing and notify us promptly if you encounter non-public personal information, payment information, credentials, private communications, or other sensitive data;
- avoid altering, deleting, downloading, retaining, or publicly disclosing data that is not your own;
- avoid disrupting services, degrading performance, creating excessive traffic, or interfering with another user; and
- give us a reasonable opportunity to investigate and address the issue before publicly disclosing technical details.
Do not establish persistence, escalate privileges beyond the minimum proof, pivot or move laterally to another system, access communications content, or continue after confirming that a vulnerability exists.
5. Prohibited testing
Do not use or attempt:
- social engineering, phishing, pretexting, impersonation, or bribery;
- credential stuffing, password spraying, password guessing, or testing leaked credentials;
- malware, ransomware, destructive payloads, persistence, or command-and-control tools;
- denial-of-service, load, stress, volumetric, resource-exhaustion, or excessive automated testing;
- physical-security, device-tampering, venue, office, booth, employee, or volunteer testing;
- testing directed at attendees, performers, vendors, partners, service providers, or other third parties;
- payment fraud, purchases using unauthorized funds, chargeback testing, or financial-system manipulation; or
- extortion, threats, demands for payment, or disclosure intended to pressure JAMMY or another person.
6. Sensitive data and evidence
Minimize and redact evidence. Do not include passwords, passkeys, authentication tokens, session cookies, recovery codes, ticket QR codes, full payment-card details, government identification, unnecessary personal information, private communications, or data obtained through unauthorized or excessive access.
If sensitive information appears unexpectedly, stop, do not save or share it, and tell us only what is necessary to identify the affected system and exposure. Do not email the sensitive value itself. We may provide a more appropriate evidence-transfer method if the information is genuinely necessary to investigate.
7. What to expect from JAMMY
We may acknowledge a report, request additional information, attempt to reproduce the issue, assess severity and scope, and provide updates when appropriate. Response and remediation time depend on the report’s completeness, complexity, impact, affected systems, third-party coordination, and operational priorities.
Submission does not create an employment, agency, partnership, fiduciary, confidentiality, or other contractual relationship. It does not guarantee payment, a bounty, public recognition, credit, a particular response, or a particular remediation timeline. Do not submit information that requires JAMMY to accept additional terms as a condition of reviewing it.
8. Good-faith safe harbour
Where a researcher acts in good faith and substantially follows this policy, JAMMY will not initiate legal action solely because of the compliant security research or report. If we conclude that activity substantially followed this policy, we will treat it as an authorized good-faith effort for purposes within JAMMY’s control.
This statement does not bind law enforcement, regulators, prosecutors, courts, third parties, or service providers. It does not apply to unlawful conduct, extortion, threats, privacy violations, service disruption, data misuse, intellectual-property infringement, physical intrusion, breach of another organization’s systems, or activity outside the scope described above.
If you are uncertain whether an activity is permitted, stop and ask first at webdev@jammygroup.ca.