Our commitment
We welcome reports from security researchers who identify vulnerabilities in good faith. When you report an issue responsibly, we commit to:
- Acknowledge your report within 5 business days
- Investigate and assess the reported issue
- Keep you informed of our progress
- Credit your contribution publicly upon request, once the issue is resolved
How to report
Please include:
- A clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Any supporting evidence (screenshots, proof of concept)
Scope
In scope
- mycoachoffice.com and its subdomains
- The My Coach Office web application
Out of scope
- Third-party services or integrations not under our control
- Social engineering attacks
- Denial of service attacks
- Automated scanning that impacts platform availability
What does not qualify
We receive a high volume of automated scanner output. To keep our disclosure process useful for everyone, the following are considered out of scope and are not eligible for acknowledgement, unless accompanied by a working proof of concept that demonstrates real, exploitable impact:
- Automated scanner or tool output without a demonstrated exploit
- Missing security headers (CSP, HSTS, X-Frame-Options, and similar) without a working attack
- Email configuration findings (SPF, DKIM, DMARC) reported from a scanner
- Clickjacking on pages that carry no sensitive action or state change
- Rate limiting, password strength or length policy, and account or email enumeration
- Software version disclosure and banner grabbing
- Self-XSS, and issues that require an already-compromised device or browser
- Social engineering, physical attacks, and denial of service
- Best-practice or hardening suggestions without a security impact
A valid report includes a clear description, reproduction steps, and a proof of concept showing genuine impact. Automated scanner output on its own is not a report.
Guidelines
We ask that you:
- Do not access, modify, or delete data that does not belong to you
- Do not disrupt the platform or its users
- Allow us a reasonable remediation window of 30 days before public disclosure
- Act in good faith and with the intent to improve security
What we offer
My Coach Office does not operate a paid bug bounty program. We are an independent SaaS platform run by a small team.
We do offer
- Written acknowledgement of your contribution
- Public credit on our security acknowledgements page (upon request), for reports that result in a change on our side
We do not offer
- Monetary compensation
- Acknowledgement for duplicates or out-of-scope findings
Public disclosure
We support coordinated disclosure. If you have reported a vulnerability and have not received a response within 10 business days, you may proceed with public disclosure. We ask that you notify us before publishing.