> ## Documentation Index
> Fetch the complete documentation index at: https://dev.jup.ag/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Report security vulnerabilities to Jupiter by email

Jupiter welcomes reports from security researchers. If you find a vulnerability in Jupiter's onchain programs, APIs, or web infrastructure, report it to [security@jup.ag](mailto:security@jup.ag) rather than disclosing it publicly.

## Scope

Reports fall into two scopes:

* **Web3**: Jupiter's onchain programs and protocol infrastructure
* **Web2**: web applications, APIs, and supporting infrastructure

Focus on vulnerabilities that materially threaten user funds, protocol solvency, governance integrity, or user data. Theoretical issues and deviations from best practice are out of scope.

Good-faith research conducted in line with these guidelines is not subject to legal action.

## Reporting a vulnerability

1. Email [security@jup.ag](mailto:security@jup.ag) with reproduction steps and an impact assessment.
2. Do not disclose the vulnerability publicly until the report is resolved.

## Related

* [Audits](/docs/resources/audits): formal audit reports for Jupiter programs
* [Support](/docs/resources/support): developer support channels for non-security issues
