Trust & Safety

Security

We take the security of our website and the data you share with us seriously. This page describes our security practices and how to report a vulnerability responsibly.

Last updated:

Our Security Practices

HTTPS Encryption

All traffic to and from jdkcapitalsai.com is encrypted using TLS (HTTPS). We do not serve content over unencrypted HTTP.

Input Validation

All form submissions are validated and sanitized on the server side to prevent injection attacks and malicious input.

Access Controls

Administrative access to our systems is restricted to authorized personnel using strong authentication practices.

Dependency Management

We regularly audit and update software dependencies to address known vulnerabilities, using automated scanning tools.

Data Minimization

We collect only the information necessary to provide our services. We do not store sensitive financial or government ID data on our web servers.

Security Headers

Our web server is configured with security headers including Content Security Policy, X-Frame-Options, and other protective measures.

Data Protection

Information submitted through our contact forms, intake forms, and other website interactions is:

  • Transmitted over encrypted HTTPS connections
  • Stored in access-controlled systems with limited personnel access
  • Used only for the purposes described in our Privacy Policy
  • Not sold or shared with third-party advertisers
  • Retained only as long as necessary to fulfill the purpose for which it was collected

For full details on how we handle personal information, see our Privacy Policy.

Responsible Disclosure Policy

If you discover a security vulnerability on our website or in our services, we ask that you report it to us responsibly before disclosing it publicly. We appreciate the security community's efforts to help keep our users safe.

How to Report

Please email a description of the vulnerability to:

What to Include

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any relevant screenshots, URLs, or proof-of-concept code
  • Your contact information (optional, but helpful for follow-up)

Our Commitments

  • We will acknowledge receipt of your report within 5 business days
  • We will investigate and work to remediate confirmed vulnerabilities promptly
  • We will not pursue legal action against researchers who report in good faith
  • We will keep you informed of our progress if you provide contact information

Out of Scope

The following are outside the scope of our responsible disclosure program:

  • Denial of service (DoS/DDoS) attacks
  • Social engineering or phishing attacks targeting our staff
  • Physical security issues
  • Vulnerabilities in third-party services or platforms we use
  • Issues that require physical access to a user's device

Security Questions?

For general security questions or to report a vulnerability, contact us directly.

[email protected]