Found a security vulnerability in our website or infrastructure? Please tell us before disclosing it to anyone else.
How to report
Email support@coffeesprout.com with "Security" in the subject. Describe what you found, where, and how we can reproduce it. A minimal proof of concept helps; a full exploit is not required.
What we promise
- You get a confirmation from an engineer within one business day, not an autoreply.
- We keep you informed of progress and the fix.
- Once confirmed, we prioritise the vulnerability by severity and tell you the expected remediation timeline.
- If you want to be credited as the reporter, we are happy to do so. If you prefer to stay anonymous, you stay anonymous.
- If you follow this policy, we will not take legal action against you for your report or research.
What we ask
- Do not abuse what you find and do not copy more data than needed to demonstrate the issue.
- No availability attacks (DoS), no social engineering, no physical access.
- Do not share the vulnerability with others until it has been resolved.
- Systems we manage for clients are out of scope; research and disclosure there is the client's decision.
Rewards
We do not run a paid bug bounty programme. What we do offer: genuine thanks, credit if you want it, and for a great find, a proper cup of coffee.
This policy was last updated on 20 August 2026. See also our security.txt.