Second Coffee Labs

Vulnerability disclosure policy

Last updated: 11 October 2026

We welcome reports from anyone who finds a security weakness in our website. This policy explains what is in scope, how to test responsibly, and what you can expect from us.

Scope

In scope: secondcoffeelabs.com and www.secondcoffeelabs.com.

Out of scope: our clients' systems and cloud accounts, which belong to them; the infrastructure of our providers, such as Cloudflare, which have their own disclosure programmes; and our email systems.

Testing responsibly

Please:

Good faith

If you act in good faith and follow this policy, we consider your research authorised, we will not take legal action against you over it, and we will work with you to understand and fix the issue. We cannot speak for third parties or the authorities, so if you are unsure whether something is in scope, ask us first.

How to report

Write to hello@secondcoffeelabs.com with "Security" in the subject. Please include where the issue is, what an attacker could do with it, and the steps to reproduce it. You may report anonymously.

What to expect

Recognition

We do not run a paid bug bounty. With your permission, we are glad to credit you once the issue is fixed.