generated: '2026-08-06' method: searched probe: true source: https://gojitsu.com/security description: >- Jitsu (formerly AxleHire) publishes a responsible-disclosure invitation on its security page. There is no RFC 9116 /.well-known/security.txt on any Jitsu host (all probed 404 or answered with an SPA shell), and no bug-bounty program on HackerOne, Bugcrowd or Intigriti was found. Reports are taken by email and through a hosted intake form. program: type: responsible-disclosure bug_bounty: false safe_harbor_stated: false policy_url: https://gojitsu.com/security contact_email: support@gojitsu.com report_forms: - https://j-it.su/rd - https://docs.google.com/forms/d/e/1FAIpQLSeDO_UZC0rOSWOCwka3XLMdeucpS3u8kyTpmUKYE7u7BuU63g/viewform guidance: >- "If you discover a potential security vulnerability in our systems, we encourage you to report it to us promptly and responsibly" — reporters are asked to avoid accessing, modifying or deleting data and to allow a reasonable remediation window. trust_center: https://trust.gojitsu.com/ security_txt: published: false probed: - url: https://gojitsu.com/.well-known/security.txt status: 404 - url: https://api.gojitsu.com/.well-known/security.txt status: 404 - url: https://docs.gojitsu.com/.well-known/security.txt status: 200 note: >- Firebase SPA catch-all — returns the docs index.html (text/html) for every /.well-known/* path. Not a real security.txt. x-evidence: fetched: '2026-08-06' url: https://gojitsu.com/security http_status: 200 control_path_status: 404 control_note: >- https://gojitsu.com/this-page-does-not-exist-control returns 404 with a 22076-byte HubSpot 404 body, so the 25876-byte 200 at /security is a real page and not a soft-404.