We welcome security research. If you've found a vulnerability in JP Sheet, here's exactly how to report it โ and what we promise in return.
Email us with full technical details. We read every report and respond within 48 hours.
Email [email protected]This policy is mostly about reporting problems to us. Here is what we do to avoid them.
Everything is encrypted in transit. The whole site runs over HTTPS, with Cloudflare in front handling TLS and filtering attack traffic before it reaches us.
We never see your card. Card details go straight to Stripe and never touch our servers. PayPal and crypto payments are the same — we receive a confirmation, not a payment instrument.
The database is not reachable from the internet. It listens on the local machine only. Even someone who found our server address could not connect to it.
Admin access is locked down. Five failed sign-ins lock the account for fifteen minutes, which makes guessing passwords pointless.
Our APIs are rate limited. A real customer never notices; a script hits the ceiling quickly.
Errors are watched. Every crash is recorded and reviewed — a failure nobody sees is a failure that repeats.
Less than you might expect. Your email address, your orders, and the reports you bought. That is the bulk of it.
No card numbers. No passwords in readable form. And no vehicle owner details — our VIN reports return records about a car, never about a person, so there is no owner database here to breach.
JP Sheet is operated by List Networks Ltd, registered in England and Wales. Our servers are in Manchester, so your data sits under UK data protection law. More detail is in our data transfers page.
Send an email to [email protected] with the technical details. We monitor this address daily, including weekends.
For machine-readable security contact details, see our security.txt file (RFC 9116 standard).
The more detail you can give us, the faster we can verify and fix the issue. A useful report includes:
Please do not include real customer data in your report. If you accessed any customer data while investigating, tell us โ we will help you delete it safely.
Our commitments after receiving a valid report:
If a fix requires more than 30 days, we will explain why and give you a realistic timeline.
Yes. If you act in good faith โ research a vulnerability, report it privately, do not access or alter customer data, and do not disrupt our service โ we will not pursue legal action against you under computer-misuse or contract law.
This safe-harbor commitment applies as long as you:
We follow the principles of coordinated vulnerability disclosure: you report privately, we fix, you can publish after the fix is deployed.
The following assets are explicitly in scope for security testing under this policy:
jpsheet.com and all its public subdomains/api/ endpoints (rate-limited; please do not flood)/admin/login.php (please do not brute-force; we have detection)/api/chatbot.phpThe following are not covered by this policy. Reports about these will be politely declined:
We do not currently run a paid bug bounty program. We do offer:
If you depend on bug-bounty income, this isn't the right program for you โ and that's fine. We'd rather be honest about what we can offer.
Researchers who have helped us improve JP Sheet's security. Listed with their permission, in chronological order. Want to be added here? Report a valid vulnerability.
Please use our regular support channels โ they are faster for non-security problems:
Reserve [email protected] for actual security vulnerabilities โ it keeps our queue clear so real issues get fast attention.
Send the details โ we read every report and respond within 48 hours.
Email [email protected]Last updated: 19 September 2026 ยท This policy applies to JP Sheet and its subdomains. Operated worldwide since 2023.