Security
If you find a security vulnerability in Ojin, please tell us. We want to fix it before anyone can misuse it, and we will work with you to do that.
Report a vulnerability
Email security@ojin.ai in English or German. Please include:
- where you found it (URL, API endpoint or component)
- the steps we need to reproduce it
- what an attacker could do with it
What happens next
We confirm that we received your report, investigate it, and keep you updated until we have fixed it. Once the fix is live, we are happy to credit you by name if you want us to.
Scope
This policy covers:
- the ojin.ai website and the Ojin dashboard
- the Ojin API at api.ojin.ai
- the model endpoints at models.ojin.ai
- the Ojin widget you embed on your own site
Please report issues in third-party services we use to the vendor that runs them.
Testing rules
- Test only with your own account and your own data.
- If you reach data that belongs to someone else, stop, do not keep or share it, and tell us.
- Do not run denial-of-service tests, send spam or target our staff with social engineering.
- Give us reasonable time to fix the issue before you publish anything about it.
Good faith
If you follow this policy, we consider your research authorised and will not take legal action against you for it.
