Security
Effective: 2026-06-03
Vulnerability disclosure
Found something? Email security@parallelcohesion.com with a description, reproduction steps and your contact info. We acknowledge every good-faith report within 72 hours, work to fix within 90 days, and do not pursue researchers who act in good faith within the safe-harbour rules below.
Safe harbour
Researchers who act in good faith are not legally pursued provided they:
- Do not access, modify, exfiltrate or destroy other users' data.
- Do not degrade service for other users (no DoS, mass scanning at production).
- Do not retain user data found incidentally; report and delete.
- Do not publicly disclose before we have fixed, or before 90 days have passed.
- Comply with applicable law.
Scope
In scope: jive.parallelcohesion.com, our Supabase project, the Jive mobile apps on the App Store and Google Play.
Out of scope: third-party services (Stripe, Apple, Google, Resend) — report to them directly. Physical security of venues. Social engineering of staff.
What we do
TLS 1.3, HSTS preload, Content Security Policy, hardware-backed token storage on device (iOS Keychain / Android Keystore), biometric gate on QR display, Postgres Row Level Security, code-signed OTA updates, daily ledger anchor hash, audit log. Full posture: see the SECURITY.md reference document available on request.
Bug bounty
We do not currently operate a paid bug bounty. We may credit researchers on a Hall of Fame page at their request.
security.txt
Our RFC 9116 disclosure file is at jive.parallelcohesion.com/.well-known/security.txt.