Security Contact Section 01
Purpose
This Security Contact and Responsible Disclosure Portal provides a clear operational entry point for reporting suspected vulnerabilities, security weaknesses, exposed credentials, unauthorized access, data exposure, abuse, or other security concerns involving Kool&Tech-controlled services.
Security Contact Section 02
Relationship to the Vulnerability Disclosure Policy
This portal complements the Kool&Tech Vulnerability Disclosure Policy. The policy defines authorized good-faith research, scope, prohibited testing, confidentiality, safe harbor conditions, and coordinated disclosure expectations. This page explains how to submit and route a report.
Security Contact Section 03
Security reporting channel
Security reports may be submitted to info@koolandtech.com with a clear security-related subject. Do not send passwords, private keys, authentication tokens, complete payment-card data, or unnecessary Personal Data in the initial message.
Security Contact Section 04
Urgent active threats
For an active compromise, exposed credential, ongoing unauthorized access, malicious modification, or immediate risk to Customer operations, clearly mark the report as urgent and describe safe containment information without exploiting or expanding access.
Security Contact Section 05
What to report
Report suspected vulnerabilities in Kool&Tech-controlled websites, applications, APIs, authentication flows, integrations, configuration, source exposure, access controls, data isolation, secrets handling, or other systems expressly covered by the published Vulnerability Disclosure Policy.
Security Contact Section 06
Third-party systems
Issues affecting Odoo, Microsoft, hosting providers, payment services, communications platforms, open-source projects, Customer-controlled systems, or other independent services should normally be reported to the responsible provider unless Kool&Tech-controlled configuration or integration is directly involved.
Security Contact Section 07
Before reporting
Confirm the affected asset, avoid unnecessary testing, preserve the original evidence, remove unrelated sensitive data, distinguish observation from assumption, and review the published scope and prohibited activities.
Security Contact Section 08
Recommended report content
01AssetHostname, page, endpoint, product, workspace, integration, or affected component.
02ObservationWhat occurred, what was expected, and why the behavior may create security impact.
03ReproductionMinimal, safe, repeatable steps that do not cause disruption, persistence, or data extraction.
04ImpactAffected users, data, permissions, confidentiality, integrity, availability, or business process.
05EvidenceRedacted screenshots, request identifiers, timestamps, logs, headers, or sanitized proof.
06ContactReporter contact details and preferred secure method for follow-up.
Security Contact Section 09
Suggested subject and structure
Subject: Security Report - [affected asset] - [short issue title]
Affected asset:
Date and time observed:
Summary:
Expected behavior:
Observed behavior:
Minimal reproduction steps:
Potential impact:
Evidence included:
Testing stopped at:
Preferred contact method:
Security Contact Section 10
Evidence handling
Evidence should be limited to what is necessary to demonstrate the issue. Redact secrets and unrelated Personal Data. Do not place sensitive evidence in public repositories, social media, shared links without access controls, or third-party paste services.
Security Contact Section 11
Secure exchange
If sensitive follow-up material is necessary, request a secure exchange method before transmitting it. Publication of this portal does not represent that a PGP key or another encrypted reporting channel is currently available.
Security Contact Section 12
Good-faith testing
Testing must remain within the Vulnerability Disclosure Policy. Avoid privacy violations, service degradation, destruction or modification of data, persistence, lateral movement, social engineering, denial-of-service, credential attacks, physical testing, or accessing more data than necessary to confirm the issue.
Security Contact Section 13
Stop conditions
Stop testing and report immediately after confirming a vulnerability, encountering sensitive information, gaining unintended access, observing another Customer data, triggering material service impact, or discovering a condition that could worsen through continued testing.
Security Contact Section 14
Exposed credentials
For an exposed key, token, password, certificate, connection string, or secret, provide the location and safe identifying details without reusing, validating, or publishing the credential. Kool&Tech may rotate or revoke the credential as a protective measure.
Security Contact Section 15
Personal Data exposure
Do not download, copy, retain, share, or analyze Personal Data beyond what is strictly necessary to document the existence of exposure. Report the type of information observed and stop access immediately.
Security Contact Section 16
Triage
Kool&Tech may validate scope, reproduce safely, classify impact, identify affected services, preserve evidence, engage providers, apply containment, coordinate remediation, and request additional information. Submission does not confirm that a report is valid or in scope.
Security Contact Section 17
Prioritization factors
Prioritization may consider exploitability, affected data, privilege gained, affected Customers, scope, active exploitation, availability impact, reversibility, dependencies, existing mitigations, and evidence quality. This public portal does not promise a fixed severity label or remediation deadline.
Security Contact Section 18
Reporter communication
Kool&Tech may acknowledge the report, request clarification, provide a case reference, communicate meaningful status changes, coordinate disclosure, or close the report. Communication depth depends on validity, risk, confidentiality, providers, and legal constraints.
Security Contact Section 19
Duplicates and previously known issues
Reports may be closed as duplicates, previously known issues, accepted risks, informational findings, unsupported claims, out-of-scope assets, or behavior operating as designed. Kool&Tech may limit details where disclosure could increase risk.
Security Contact Section 20
Actionable reports
Reports should be accurate, reproducible, concise, and submitted in good faith. Automated scanner output without validation, unsupported claims, excessive duplicate submissions, or reports lacking an affected asset may not be actionable.
Security Contact Section 21
Coordinated disclosure
Do not publicly disclose vulnerability details, exploit code, sensitive evidence, or remediation status before Kool&Tech has had a reasonable opportunity to investigate and coordinate remediation under the Vulnerability Disclosure Policy.
Security Contact Section 22
Authorization and safe-harbor conditions
Any authorization or safe-harbor commitment is limited to good-faith activity that complies with the published Vulnerability Disclosure Policy. This portal alone does not authorize testing beyond that policy.
Security Contact Section 23
No implied bug bounty
Kool&Tech does not operate a public bug bounty through this portal unless a separate written program expressly states otherwise. Submission does not create a right to payment, reward, employment, contract, or public recognition.
Security Contact Section 24
Recognition
Kool&Tech may recognize helpful reporters only with mutual approval and when recognition does not create security, privacy, contractual, or legal risk. Anonymous or confidential reporting preferences will be respected where practical.
Security Contact Section 25
Customer-reported incidents
Customers should use the authorized support or security contacts in the applicable agreement for suspected compromise, account takeover, service incident, or data exposure. Include the affected account or workspace but never send credentials.
Security Contact Section 26
Legal and regulatory matters
Security and privacy notifications are evaluated according to verified facts, contractual roles, affected information, applicable law, provider involvement, and regulatory obligations. A report alone does not establish a reportable breach.
Security Contact Section 27
Report records
Kool&Tech may retain reports, communications, evidence, triage records, remediation notes, provider cases, and closure records for security, legal, operational, contractual, and improvement purposes under applicable retention controls.
Security Contact Section 28
security.txt readiness
Kool&Tech may publish a machine-readable security.txt file to advertise the reporting contact and policy location. The file should be reviewed and updated before its stated expiration.
Security Contact Section 29
Proposed security.txt template
Contact: mailto:info@koolandtech.com
Policy: [publish the canonical Vulnerability Disclosure Policy URL]
Preferred-Languages: en, es
Canonical: [publish the canonical /.well-known/security.txt URL]
Expires: [insert and maintain a future ISO 8601 timestamp]
Security Contact Section 30
No implied permission from security.txt
A security.txt file or contact address makes reporting easier but does not independently authorize testing. Testing authorization continues to be governed by the Vulnerability Disclosure Policy.
Security Contact Section 31
Abusive or harmful submissions
Kool&Tech may restrict communications or escalate reports involving threats, extortion, deliberate harm, unlawful access, fraudulent claims, harassment, malicious attachments, or attempts to force payment or disclosure.
Security Contact Section 32
Portal updates
Kool&Tech may update this portal, reporting channels, scope references, templates, or secure-exchange methods as services and operational capabilities evolve. Reporters should consult the current published policy before testing.
Security Contact Section 33
Security contact
Send security questions and responsible-disclosure reports to info@koolandtech.com with a clear subject. For ordinary technical support, billing, feature requests, or general inquiries, use the applicable non-security support channel.