New·Issue certificates without leaving your inbox: Coily for Outlook & Gmail is live.

Security

Responsible Disclosure

Last updated July 22, 2026 · v1.0

Security research makes products like ours safer, and we welcome it. This page explains how to report a vulnerability in Coily, what you can expect from us, and the ground rules that keep good-faith research safe for everyone, including our customers.

How to report

Email hello@trycoily.com with the subject line "Security report". Please include:

  • A description of the issue and where you found it (URL, endpoint, or component).
  • Steps to reproduce it. A minimal proof of concept is ideal.
  • What you believe the impact is (what data or capability an attacker would gain).
  • How we can reach you for follow-up questions.

We acknowledge reports within two business days and will keep you updated as we investigate and fix. If you prefer, you may report anonymously; we will still investigate.

Scope

In scope:

  • The marketing site and application at trycoily.com and www.trycoily.com.
  • The Coily API.
  • The Coily Outlook add-in and Gmail add-on.

Out of scope:

  • Our third-party providers' own infrastructure (Supabase, Vercel, Stripe, Anthropic, Cloudflare, Zoho). Please report issues in those platforms to their own security programs.
  • Denial of service, load testing, or resource-exhaustion attacks.
  • Social engineering, phishing, or physical attacks against Coily, our contractors, or our customers.
  • Spam, SPF/DKIM/DMARC configuration commentary without a demonstrated exploit, and reports from automated scanners with no proof of impact.
  • Clickjacking on pages with no sensitive action, missing security headers with no demonstrated impact, and best-practice suggestions without a vulnerability.

Ground rules (safe harbor)

We will not pursue or support legal action against researchers who, in good faith:

  • Test only against accounts and data you own or control. Never access, modify, or delete another tenant's data. If a flaw hands you someone else's data unexpectedly, stop, capture the minimum needed to demonstrate the issue, and report it immediately.
  • Avoid privacy violations, data destruction, and service disruption.
  • Do not exfiltrate data beyond what is minimally necessary to demonstrate the issue.
  • Give us a reasonable window to fix the issue before any public disclosure. We ask for 90 days from acknowledgment, and we will work with you if a fix needs longer.
  • Comply with applicable laws.

Research conducted under these rules is authorized under the Computer Fraud and Abuse Act and equivalent laws, and we waive claims under the DMCA for good-faith circumvention performed strictly for research within this scope.

What you can expect from us

  • Acknowledgment within two business days, and a substantive assessment within ten.
  • Honest status updates while we work on a fix.
  • Credit for your finding, with your permission, once the fix ships. If you prefer to stay anonymous, we will honor that.
  • We do not operate a paid bug bounty today. If that changes, this page will say so first.

The machine-readable version

The RFC 9116 companion to this policy lives at https://www.trycoily.com/.well-known/security.txt. If the two ever disagree, this page is authoritative.

Thank you for helping keep certificate data safe. Legal questions about this policy go to legal@trycoily.com; reports themselves go to hello@trycoily.com.