Junix ID — PT Jalur Utama Nusantara
Junix
Coordinated Disclosure

Junix Bug Bounty.

We welcome security research. This page is the single canonical channel for coordinated disclosure. Report a valid finding here and Junix Security acknowledges within one business day.

Critical
Remote code exec, auth bypass, PII dump
Response SLA
1 business hour
High
IDOR, privilege escalation, SSRF
Response SLA
1 business day
Medium
CSRF on state-changing route, stored XSS
Response SLA
3 business days
Low
Info disclosure, minor CSP gaps
Response SLA
5 business days

In scope

  • junix.id and all subdomains (*.junix.id)
  • Customer Portal at /portal and all authenticated APIs (/api/*)
  • Public marketing site including /solutions/*, /company/*, /tools/*
  • AI-assisted endpoints (chat, deal-room, briefing) and their persisted artefacts

Out of scope

  • Third-party services we consume (Resend, PostgreSQL host, LLM providers) — report to them directly
  • Denial-of-service, volumetric or resource exhaustion testing
  • Social engineering of Junix employees, customers or vendors
  • Physical attacks against Junix offices or infrastructure
  • Findings solely relying on user-installed browser extensions or malware
  • Missing security headers on marketing pages without a concrete impact chain

Safe-harbor policy

Junix will not initiate legal action or law-enforcement contact against researchers who act in good faith, provided they:

  • Only test accounts and data belonging to themselves or accounts they are explicitly authorised to test.
  • Do not access, modify, exfiltrate or destroy any customer data beyond the minimum required to prove impact.
  • Do not run automated scanners against production without a rate cap of ≤ 5 requests/second.
  • Report findings promptly and give Junix a reasonable window (min. 90 days) before public disclosure.
  • Comply with all applicable laws.

This safe-harbor language is offered in the spirit of the disclose.io core template. Non-compliant activity is not protected.

Submit a finding

Report a vulnerability

Please include reproduction steps, impact and any proof-of-concept payloads. We deduplicate by root cause.

Severity you’re requesting
Prefer email? Send to security@junix.id with the same information. Encrypt with our PGP key if the finding is sensitive.