Security

Effective: 2026-06-03

Vulnerability disclosure

Found something? Email security@parallelcohesion.com with a description, reproduction steps and your contact info. We acknowledge every good-faith report within 72 hours, work to fix within 90 days, and do not pursue researchers who act in good faith within the safe-harbour rules below.

Safe harbour

Researchers who act in good faith are not legally pursued provided they:

Scope

In scope: jive.parallelcohesion.com, our Supabase project, the Jive mobile apps on the App Store and Google Play.

Out of scope: third-party services (Stripe, Apple, Google, Resend) — report to them directly. Physical security of venues. Social engineering of staff.

What we do

TLS 1.3, HSTS preload, Content Security Policy, hardware-backed token storage on device (iOS Keychain / Android Keystore), biometric gate on QR display, Postgres Row Level Security, code-signed OTA updates, daily ledger anchor hash, audit log. Full posture: see the SECURITY.md reference document available on request.

Bug bounty

We do not currently operate a paid bug bounty. We may credit researchers on a Hall of Fame page at their request.

security.txt

Our RFC 9116 disclosure file is at jive.parallelcohesion.com/.well-known/security.txt.

Security — Jive · Jive