JuriSign · Vulnerability Disclosure

Jurisign Vulnerability Disclosure

Vulnerability disclosure

JuriSign runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Electronic SignatureE-SignatureeIDASDocument SigningPDFWebhookOTPGDPRFranceLegal TechIdentity VerificationAudit Traildata-residency-eu
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:contact@jurisign.fr

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-31'
method: searched
probe: true
source: https://www.jurisign.fr/.well-known/security.txt
sources:
- https://www.jurisign.fr/.well-known/security.txt
- https://www.jurisign.fr/confidentialite
- https://www.jurisign.fr/sous-traitance
program_published: true
rfc9116: true
security_txt:
  url: https://www.jurisign.fr/.well-known/security.txt
  http_status: 200
  content_type: text/plain
  file: well-known/jurisign-security.txt
  fields_present: [Contact, Expires, Preferred-Languages, Canonical, Policy]
  expires: '2027-05-09T00:00:00.000Z'
  preferred_languages: [fr, en]
  canonical: https://www.jurisign.fr/.well-known/security.txt
policy:
- https://www.jurisign.fr/confidentialite
contact:
- mailto:contact@jurisign.fr
disclosure_terms:
  response_target: 5 business days
  response_commitment: >-
    "Nous nous engageons a repondre dans les 5 jours ouvres et a vous tenir informe de l'avancement de la
    correction." - the provider commits to acknowledge within five working days and to keep the reporter updated
    on remediation progress.
  embargo: 90 days
  embargo_statement: >-
    "Periode de divulgation : merci de patienter au moins 90 jours apres notre reponse initiale avant toute
    publication, sauf accord prealable." - a 90-day wait after the initial response is requested before
    publication, unless agreed otherwise.
  submission_expectation: A detailed description of the vulnerability, sent to the contact address.
bug_bounty:
  program: none
  paid: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti, YesWeHack]
  note: >-
    No bug bounty or paid vulnerability reward programme is published, and the security.txt carries no
    Acknowledgments, Hiring or Encryption field. Disclosure is direct-to-email under the terms above.
breach_notification:
  customer_notification_window: 48 hours
  statement: >-
    The GDPR Article 28 annex commits to notifying the customer of any personal-data breach as soon as possible
    and at most within forty-eight (48) hours, so the customer can meet its own CNIL notification deadline. The
    notification must state the nature of the breach, the categories and approximate volume of data and people
    affected, the likely consequences, and the measures taken or planned.
  source: https://www.jurisign.fr/sous-traitance
  regulator: CNIL (France)
security_measures_published:
  source: https://www.jurisign.fr/sous-traitance
  measures:
  - Encryption of communications
  - Irreversible hashing of secrets
  - SHA-256 fingerprinting of documents
  - Cryptographic chaining of audit logs with integrity verification
  - Logical isolation between customer organizations
  - One-time-code authentication of signers
evidence:
- source: https://www.jurisign.fr/.well-known/security.txt
  kind: RFC 9116 security.txt
  http_status: 200
  fetched: '2026-08-31'
- source: https://www.jurisign.fr/sous-traitance
  kind: GDPR Article 28 processing annex (breach notification + security measures)
  http_status: 200
  fetched: '2026-08-31'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/jurisign-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.