Security
How Jotmor protects private notes and media, and how to report a vulnerability responsibly.
Current safeguards
- Encryption in transit and AWS KMS-backed encryption at rest for user data.
- Private S3 and RDS resources, least-privilege service roles, and short-lived signed media links.
- Amazon Cognito authentication with TOTP multi-factor authentication support.
- AWS WAF, rate limits, security logging, monitoring, backups, and retained recovery resources.
- Managed malware screening before uploaded files become available for processing or playback.
- Separated API, messaging, media-processing, and purge task permissions.
No system is perfectly secure. These measures reduce risk but are not a guarantee against every incident.
Report a vulnerability
Email security@jotmor.com with a clear description, affected URL, reproduction steps, and impact. Do not include real user content, credentials, or unnecessary personal data.
Do not access another person’s data, use automated high-volume scanning, disrupt availability, perform denial-of-service testing, send malware, or use social engineering. Stop testing and report immediately if you encounter user information.
We aim to acknowledge a good-faith report within 7 days. Jotmor does not currently operate a paid bug-bounty program, and this page does not authorize unlawful activity or promise compensation.
Account security
Use a unique password, enable TOTP, protect recovery access, sign out on shared devices, and contact us promptly if you suspect unauthorized access.