Security

How we protect JupiteX, and how you can help. Last updated December 2025.

This page sets out the controls we run, how to report a vulnerability, what happens after you report one, what is in and out of scope, and how to appeal a decision. Reports go to security@jupitex.ai and are acknowledged within 72 hours. Appeals go to appeals@jupitex.ai and are reviewed within 7 days.

Our commitment

We take security seriously:

  • Encryption in transit (TLS) and at rest
  • Access controls and authentication
  • Regular security reviews
  • AWS security infrastructure
  • Minimal data collection by design

Only a few trained staff can access production systems, and only when needed.

Responsible disclosure

Found a vulnerability? We appreciate your help.

How to report

Email security@jupitex.ai with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your contact information

What we will do

  • Acknowledge within 72 hours
  • Investigate and keep you updated
  • Fix confirmed issues promptly
  • Credit you if you want — we name researchers in our security acknowledgments

What we ask

  • Give us reasonable time to fix before public disclosure
  • Do not access or modify other users' data
  • Do not disrupt the service

Scope

In scope:

  • jupitex.ai and its subdomains
  • JupiteX mobile apps (when launched)

Not in scope:

  • Email spoofing and social engineering
  • Physical security
  • Third-party apps we do not control

Appeals

If you disagree with how we handled your report, email appeals@jupitex.ai. We review within 7 days.

Contact

security@jupitex.ai for vulnerability reports. appeals@jupitex.ai if you want a decision reviewed.

Explore more