CoffeeSprout
  • Home
  • Pods
  • Managed Pods
  • Managed Servers
  • Kubernetes
  • Articles
  • About
  • Contact
  • NL EN

Responsible Disclosure

Coordinated Vulnerability Disclosure

Found a security vulnerability in our website or infrastructure? Please tell us before disclosing it to anyone else.

How to report

Email support@coffeesprout.com with "Security" in the subject. Describe what you found, where, and how we can reproduce it. A minimal proof of concept helps; a full exploit is not required.

What we promise

  • You get a confirmation from an engineer within one business day, not an autoreply.
  • We keep you informed of progress and the fix.
  • Once confirmed, we prioritise the vulnerability by severity and tell you the expected remediation timeline.
  • If you want to be credited as the reporter, we are happy to do so. If you prefer to stay anonymous, you stay anonymous.
  • If you follow this policy, we will not take legal action against you for your report or research.

What we ask

  • Do not abuse what you find and do not copy more data than needed to demonstrate the issue.
  • No availability attacks (DoS), no social engineering, no physical access.
  • Do not share the vulnerability with others until it has been resolved.
  • Systems we manage for clients are out of scope; research and disclosure there is the client's decision.

Rewards

We do not run a paid bug bounty programme. What we do offer: genuine thanks, credit if you want it, and for a great find, a proper cup of coffee.

This policy was last updated on 20 August 2026. See also our security.txt.

© 2026 CoffeeSprout · Since 2008 | Infrastructure | Consulting | Articles | Partners | Privacy Policy | Terms & Conditions

Java and OpenJDK are trademarks or registered trademarks of Oracle and/or its affiliates. Other names and logos may be trademarks of their respective owners.