Security

Public surface. Private systems.

Jmorex keeps the public consulting website intentionally narrow. Public pages explain the business and route visitors to contact or hosted checkout; private Jova, Kimi, customer, financial, device, and operator systems are not exposed as public website functionality.

Last reviewed: September 18, 2026.

Public-site controls

The public site is a static first-party surface with restrictive browser security headers. Current controls include HTTPS/HSTS, frame denial, MIME sniffing protection, a restrictive Content Security Policy, restricted browser permissions, and no embedded third-party analytics or advertising runtime on the public consulting surface.

Payments

Jmorex does not collect card credentials directly on jmorex.com. The current Digital Review purchase flow hands payment entry to Stripe-hosted checkout. A hosted payment handoff does not expand Jmorex's authority over the payer's financial accounts.

Public/private boundary

Private operating systems, authenticated business workspaces, internal model endpoints, home/device controls, financial credentials, and client records are not public website features. A public description or link does not imply that a private system is generally accessible.

Responsible disclosure

If you believe you found a security issue affecting jmorex.com or a Jmorex-controlled public surface, email jerome.c@jmorex.com. Include the affected URL or component, a clear description, reproduction steps when safe, and the potential impact.

Please avoid destructive testing, privacy-invasive data access, denial-of-service activity, social engineering, credential attacks, or accessing more data than necessary to demonstrate the issue. Do not publicly disclose sensitive details before Jmorex has had a reasonable opportunity to investigate and respond.

No certification claim

This page describes the current public-site posture and operating boundaries. It does not claim SOC 2, ISO 27001, PCI certification by Jmorex, a paid bug-bounty program, or independent penetration-test assurance unless a future public record explicitly establishes that evidence.

Machine-readable contact

The canonical vulnerability-reporting contact is also published at /.well-known/security.txt.