Security research makes products like ours safer, and we welcome it. This page explains how to report a vulnerability in Coily, what you can expect from us, and the ground rules that keep good-faith research safe for everyone, including our customers.
How to report
Email hello@trycoily.com with the subject line "Security report". Please include:
- A description of the issue and where you found it (URL, endpoint, or component).
- Steps to reproduce it. A minimal proof of concept is ideal.
- What you believe the impact is (what data or capability an attacker would gain).
- How we can reach you for follow-up questions.
We acknowledge reports within two business days and will keep you updated as we investigate and fix. If you prefer, you may report anonymously; we will still investigate.
Scope
In scope:
- The marketing site and application at trycoily.com and www.trycoily.com.
- The Coily API.
- The Coily Outlook add-in and Gmail add-on.
Out of scope:
- Our third-party providers' own infrastructure (Supabase, Vercel, Stripe, Anthropic, Cloudflare, Zoho). Please report issues in those platforms to their own security programs.
- Denial of service, load testing, or resource-exhaustion attacks.
- Social engineering, phishing, or physical attacks against Coily, our contractors, or our customers.
- Spam, SPF/DKIM/DMARC configuration commentary without a demonstrated exploit, and reports from automated scanners with no proof of impact.
- Clickjacking on pages with no sensitive action, missing security headers with no demonstrated impact, and best-practice suggestions without a vulnerability.
Ground rules (safe harbor)
We will not pursue or support legal action against researchers who, in good faith:
- Test only against accounts and data you own or control. Never access, modify, or delete another tenant's data. If a flaw hands you someone else's data unexpectedly, stop, capture the minimum needed to demonstrate the issue, and report it immediately.
- Avoid privacy violations, data destruction, and service disruption.
- Do not exfiltrate data beyond what is minimally necessary to demonstrate the issue.
- Give us a reasonable window to fix the issue before any public disclosure. We ask for 90 days from acknowledgment, and we will work with you if a fix needs longer.
- Comply with applicable laws.
Research conducted under these rules is authorized under the Computer Fraud and Abuse Act and equivalent laws, and we waive claims under the DMCA for good-faith circumvention performed strictly for research within this scope.
What you can expect from us
- Acknowledgment within two business days, and a substantive assessment within ten.
- Honest status updates while we work on a fix.
- Credit for your finding, with your permission, once the fix ships. If you prefer to stay anonymous, we will honor that.
- We do not operate a paid bug bounty today. If that changes, this page will say so first.
The machine-readable version
The RFC 9116 companion to this policy lives at https://www.trycoily.com/.well-known/security.txt. If the two ever disagree, this page is authoritative.
Thank you for helping keep certificate data safe. Legal questions about this policy go to legal@trycoily.com; reports themselves go to hello@trycoily.com.
