Security
Reporting a security problem
If you have found a weakness in RecipeJam, we want to hear about it before anyone else does. This page says where to send it, what happens next, and what you can expect from us in return.
The machine-readable version is at /.well-known/security.txt.
Where to send it
Email security@recipejam.com. Tell us what you found, where, and how to see it for ourselves — a URL, a request, a screenshot. If you would rather not use that address, privacy@recipejam.com reaches the same people.
What is in scope
Anything RecipeJam Limited runs: this website, the API, the connector AI apps use at
/mcp, the share links, and the sign-in and payment
flows as far as they are ours. Not in scope: the services we build on — Stripe,
Amazon Web Services, Google — which have their own programmes; flooding the site
with traffic; and anything that involves deceiving a person rather than a system.
Please test against your own account or the demo, never against another person's recipes. If you find you can reach somebody else's data, stop there and tell us — that is the report we most want, and the one that least needs demonstrating twice.
What we will do
We will acknowledge your report within three working days, tell you what we make of it, and fix what needs fixing with an urgency that matches what it makes possible. We will let you know when it is done. If you would like to be named when we describe the fix, say so; if you would rather not, we will not.
We do not pay bounties. RecipeJam is a small company and this is an honest page, not a programme.
What we will not do
We will not threaten or take action against anyone who reports in good faith, stays within the scope above, avoids other people's data, and gives us a reasonable chance to fix the problem before talking about it publicly. Research done that way is a favour to us and to the people whose recipes we keep, and we will treat it as one.