Vulnerability disclosure policy
Last updated: 11 October 2026
We welcome reports from anyone who finds a security weakness in our website. This policy explains what is in scope, how to test responsibly, and what you can expect from us.
Scope
In scope: secondcoffeelabs.com and www.secondcoffeelabs.com.
Out of scope: our clients' systems and cloud accounts, which belong to them; the infrastructure of our providers, such as Cloudflare, which have their own disclosure programmes; and our email systems.
Testing responsibly
Please:
- Do no harm: no denial-of-service testing, no heavy automated scanning, and nothing that degrades the site for others.
- Do not use social engineering, phishing or physical attempts against us, our clients or our providers.
- Do not access, change or keep data that is not yours. If you come across any, stop and tell us.
- Give us a reasonable time to fix the issue before you share it with anyone else.
Good faith
If you act in good faith and follow this policy, we consider your research authorised, we will not take legal action against you over it, and we will work with you to understand and fix the issue. We cannot speak for third parties or the authorities, so if you are unsure whether something is in scope, ask us first.
How to report
Write to hello@secondcoffeelabs.com with "Security" in the subject. Please include where the issue is, what an attacker could do with it, and the steps to reproduce it. You may report anonymously.
What to expect
- We acknowledge your report within three business days.
- We keep you updated while we investigate and fix it.
- We agree a disclosure date with you, normally within 90 days of your report.
Recognition
We do not run a paid bug bounty. With your permission, we are glad to credit you once the issue is fixed.