JCS-controlled website pages
The production pages and static resources served from jesuschristsavestoken.com, including index.html, verify.html, about-jcs.html, terms.html, privacy.html, security.html, AI manifests, and security contact files.
Jesus Christ Saves Token treats security as an act of stewardship. The JCS ministry serves people who may face financial harm, identity exposure, or even religious persecution. A vulnerability affecting a wallet request, testimony, prayer NFT, public identity choice, or website control can therefore create consequences beyond ordinary technical inconvenience. This page explains how to report a suspected vulnerability safely and responsibly.
Send vulnerability reports to:
Use the subject line JCS Security Report. Email is the primary reporting channel. The public X account may be used to say that an urgent report was sent, but do not publish technical details, exploit code, private information, or an unpatched weakness on social media.
The production pages and static resources served from jesuschristsavestoken.com, including index.html, verify.html, about-jcs.html, terms.html, privacy.html, security.html, AI manifests, and security contact files.
Code that prepares Xaman authorization, trustlines, payments, offers, cancellations, NFT mints, memos, prayer identifiers, replies, Amen reactions, and other user-requested XRPL transactions.
The browser logic that reads public XRPL history, renders testimonies, stores unfinished drafts, builds prayer NFTs, applies visibility settings, and creates sharing links.
Issuer and currency configuration, Content Security Policy, canonical URLs, project-owned repositories or deployment configuration when specifically identified as controlled by JCS.
The following are generally outside scope unless the report demonstrates that JCS code or configuration directly causes the vulnerability:
A useful report should contain enough information to reproduce and understand the issue while avoiding unnecessary personal or sensitive data.
Use a test wallet and the smallest possible proof. Redact wallet secrets, access tokens, session identifiers, personal testimony, names, locations, and any information that could expose a believer to persecution or retaliation.
The following activities are expressly outside this policy and are not authorized:
When a researcher acts in good faith, stays within this policy, avoids harm, reports promptly, and gives JCS a reasonable opportunity to correct the issue, JCS will not initiate legal action against that researcher solely for the policy-compliant security research.
This limited statement applies only to JCS-controlled systems and only to conduct JCS has legal authority to authorize. It does not bind governments, prosecutors, law-enforcement agencies, Xaman, XRPL Labs, validators, hosting providers, social platforms, service providers, wallet owners, or other third parties. It does not excuse unlawful conduct, privacy violations, financial harm, extortion, reckless testing, or activity outside the stated scope.
If uncertainty exists about whether a proposed test is allowed, ask for written permission before performing it.
These are good-faith targets, not guarantees. Response time may depend on report quality, volunteer availability, access to affected systems, third-party coordination, legal requirements, and the seriousness of the issue.
JCS may ask for clarification, additional evidence, safer reproduction steps, or confirmation that sensitive data was deleted. A report may be closed when it is not reproducible, outside scope, already known, a duplicate, informational only, or not a security vulnerability.
Severity is determined by actual exploitability, user interaction, scope, confidentiality, integrity, availability, wallet or financial impact, public-ledger permanence, and risk to people whose Christian identity could be exposed.
Do not publish an uncorrected vulnerability or identifying details before coordination. JCS asks reporters to allow at least ninety days from confirmation for correction before public disclosure, unless the parties agree to a different timeline or immediate disclosure is legally required to prevent imminent harm.
A disclosure should protect users by omitting wallet secrets, access tokens, personal testimony, names, locations, unpublished code, live exploit paths, and information that could identify or endanger believers. JCS may request additional time when a correction depends on a third party, major redesign, application review, hosting provider, or wallet integration.
JCS may publish a security notice, correction summary, release number, affected version, mitigation, or acknowledgment when appropriate. Reporter acknowledgment requires the reporter’s permission.
JCS does not currently operate a paid bug-bounty program and does not promise money, JCS tokens, XRP, NFTs, donations, employment, public recognition, or any other reward for a report. Do not incur costs or perform risky testing in expectation of payment.
JCS may voluntarily thank a researcher or provide acknowledgment, but any recognition is discretionary and does not create a contract, employment relationship, partnership, ownership interest, or entitlement to future compensation.
JCS will use report information to investigate, reproduce, correct, document, coordinate, and defend against the reported issue. Information may be shared with developers, hosting providers, Xaman or another affected third party, legal advisers, security professionals, or authorities when reasonably necessary.
JCS cannot promise absolute confidentiality, attorney-client privilege, clergy-penitent privilege, or anonymous communication through ordinary email. Reporters should use an alias and avoid unnecessary identifying information when personal safety is a concern.
See the Privacy Policy for additional information. Never include a wallet seed, recovery phrase, private key, victim data, government identification, or information revealing a persecuted person’s identity unless lawfully necessary and specifically requested through a secure process.
https://jesuschristsavestoken.com/.well-known/security.txt
The machine-readable file provides the primary contact, canonical location, policy URL, preferred language, expiration date, and bug-bounty status. It should be renewed before its expiration date so researchers do not rely on stale information.
This policy is intended to encourage responsible reporting and improve security. It is not legal advice, a warranty that the site is secure, a promise that every report will be corrected, or a waiver of rights concerning conduct outside the policy.
JCS describes itself as a Christ-centered faith ministry and technology project. This security policy does not independently create or prove legal status as a church, nonprofit corporation, public charity, tax-exempt entity, or organization recognized under Section 501(c)(3).
Nothing here authorizes access to third-party systems, circumvention of law, violation of another person’s rights, or interference with public blockchain infrastructure. Mandatory law applies regardless of this policy.