Ir al contenido
Security Reports · Responsible Disclosure · Coordinated Response

Found a security concern? Report it safely.

This portal provides a clear route for reporting suspected vulnerabilities, exposed credentials, unauthorized access, data exposure, abuse, and other security concerns involving Kool&Tech-controlled services.

Effective: September 19, 2026 Kool&Tech LLC · FL Document L24000173044 info@koolandtech.com
Clear scopeReport Kool&Tech-controlled assets and route third-party issues correctly.
Actionable reportsAsset, observation, safe reproduction, impact, evidence, and contact.
Safe testingStop after confirmation and avoid disruption, persistence, or data extraction.
Coordinated handlingTriage, containment, remediation, provider engagement, and disclosure.
Do not send secrets: Initial reports must not contain passwords, private keys, full tokens, complete payment-card data, or unnecessary Personal Data. Request a secure exchange method if sensitive evidence is necessary.
Security Contact Section 01

Purpose

This Security Contact and Responsible Disclosure Portal provides a clear operational entry point for reporting suspected vulnerabilities, security weaknesses, exposed credentials, unauthorized access, data exposure, abuse, or other security concerns involving Kool&Tech-controlled services.

Security Contact Section 02

Relationship to the Vulnerability Disclosure Policy

This portal complements the Kool&Tech Vulnerability Disclosure Policy. The policy defines authorized good-faith research, scope, prohibited testing, confidentiality, safe harbor conditions, and coordinated disclosure expectations. This page explains how to submit and route a report.

Security Contact Section 03

Security reporting channel

Security reports may be submitted to info@koolandtech.com with a clear security-related subject. Do not send passwords, private keys, authentication tokens, complete payment-card data, or unnecessary Personal Data in the initial message.

Security Contact Section 04

Urgent active threats

For an active compromise, exposed credential, ongoing unauthorized access, malicious modification, or immediate risk to Customer operations, clearly mark the report as urgent and describe safe containment information without exploiting or expanding access.

Security Contact Section 05

What to report

Report suspected vulnerabilities in Kool&Tech-controlled websites, applications, APIs, authentication flows, integrations, configuration, source exposure, access controls, data isolation, secrets handling, or other systems expressly covered by the published Vulnerability Disclosure Policy.

Security Contact Section 06

Third-party systems

Issues affecting Odoo, Microsoft, hosting providers, payment services, communications platforms, open-source projects, Customer-controlled systems, or other independent services should normally be reported to the responsible provider unless Kool&Tech-controlled configuration or integration is directly involved.

Security Contact Section 07

Before reporting

Confirm the affected asset, avoid unnecessary testing, preserve the original evidence, remove unrelated sensitive data, distinguish observation from assumption, and review the published scope and prohibited activities.

Security Contact Section 08

Recommended report content

01
AssetHostname, page, endpoint, product, workspace, integration, or affected component.
02
ObservationWhat occurred, what was expected, and why the behavior may create security impact.
03
ReproductionMinimal, safe, repeatable steps that do not cause disruption, persistence, or data extraction.
04
ImpactAffected users, data, permissions, confidentiality, integrity, availability, or business process.
05
EvidenceRedacted screenshots, request identifiers, timestamps, logs, headers, or sanitized proof.
06
ContactReporter contact details and preferred secure method for follow-up.
Security Contact Section 09

Suggested subject and structure

Subject: Security Report - [affected asset] - [short issue title] Affected asset: Date and time observed: Summary: Expected behavior: Observed behavior: Minimal reproduction steps: Potential impact: Evidence included: Testing stopped at: Preferred contact method:
Security Contact Section 10

Evidence handling

Evidence should be limited to what is necessary to demonstrate the issue. Redact secrets and unrelated Personal Data. Do not place sensitive evidence in public repositories, social media, shared links without access controls, or third-party paste services.

Security Contact Section 11

Secure exchange

If sensitive follow-up material is necessary, request a secure exchange method before transmitting it. Publication of this portal does not represent that a PGP key or another encrypted reporting channel is currently available.

Security Contact Section 12

Good-faith testing

Testing must remain within the Vulnerability Disclosure Policy. Avoid privacy violations, service degradation, destruction or modification of data, persistence, lateral movement, social engineering, denial-of-service, credential attacks, physical testing, or accessing more data than necessary to confirm the issue.

Security Contact Section 13

Stop conditions

Stop testing and report immediately after confirming a vulnerability, encountering sensitive information, gaining unintended access, observing another Customer data, triggering material service impact, or discovering a condition that could worsen through continued testing.

Security Contact Section 14

Exposed credentials

For an exposed key, token, password, certificate, connection string, or secret, provide the location and safe identifying details without reusing, validating, or publishing the credential. Kool&Tech may rotate or revoke the credential as a protective measure.

Security Contact Section 15

Personal Data exposure

Do not download, copy, retain, share, or analyze Personal Data beyond what is strictly necessary to document the existence of exposure. Report the type of information observed and stop access immediately.

Security Contact Section 16

Triage

Kool&Tech may validate scope, reproduce safely, classify impact, identify affected services, preserve evidence, engage providers, apply containment, coordinate remediation, and request additional information. Submission does not confirm that a report is valid or in scope.

Security Contact Section 17

Prioritization factors

Prioritization may consider exploitability, affected data, privilege gained, affected Customers, scope, active exploitation, availability impact, reversibility, dependencies, existing mitigations, and evidence quality. This public portal does not promise a fixed severity label or remediation deadline.

Security Contact Section 18

Reporter communication

Kool&Tech may acknowledge the report, request clarification, provide a case reference, communicate meaningful status changes, coordinate disclosure, or close the report. Communication depth depends on validity, risk, confidentiality, providers, and legal constraints.

Security Contact Section 19

Duplicates and previously known issues

Reports may be closed as duplicates, previously known issues, accepted risks, informational findings, unsupported claims, out-of-scope assets, or behavior operating as designed. Kool&Tech may limit details where disclosure could increase risk.

Security Contact Section 20

Actionable reports

Reports should be accurate, reproducible, concise, and submitted in good faith. Automated scanner output without validation, unsupported claims, excessive duplicate submissions, or reports lacking an affected asset may not be actionable.

Security Contact Section 21

Coordinated disclosure

Do not publicly disclose vulnerability details, exploit code, sensitive evidence, or remediation status before Kool&Tech has had a reasonable opportunity to investigate and coordinate remediation under the Vulnerability Disclosure Policy.

Security Contact Section 22

Authorization and safe-harbor conditions

Any authorization or safe-harbor commitment is limited to good-faith activity that complies with the published Vulnerability Disclosure Policy. This portal alone does not authorize testing beyond that policy.

Security Contact Section 23

No implied bug bounty

Kool&Tech does not operate a public bug bounty through this portal unless a separate written program expressly states otherwise. Submission does not create a right to payment, reward, employment, contract, or public recognition.

Security Contact Section 24

Recognition

Kool&Tech may recognize helpful reporters only with mutual approval and when recognition does not create security, privacy, contractual, or legal risk. Anonymous or confidential reporting preferences will be respected where practical.

Security Contact Section 25

Customer-reported incidents

Customers should use the authorized support or security contacts in the applicable agreement for suspected compromise, account takeover, service incident, or data exposure. Include the affected account or workspace but never send credentials.

Security Contact Section 26

Legal and regulatory matters

Security and privacy notifications are evaluated according to verified facts, contractual roles, affected information, applicable law, provider involvement, and regulatory obligations. A report alone does not establish a reportable breach.

Security Contact Section 27

Report records

Kool&Tech may retain reports, communications, evidence, triage records, remediation notes, provider cases, and closure records for security, legal, operational, contractual, and improvement purposes under applicable retention controls.

Security Contact Section 28

security.txt readiness

Kool&Tech may publish a machine-readable security.txt file to advertise the reporting contact and policy location. The file should be reviewed and updated before its stated expiration.

Security Contact Section 29

Proposed security.txt template

Contact: mailto:info@koolandtech.com Policy: [publish the canonical Vulnerability Disclosure Policy URL] Preferred-Languages: en, es Canonical: [publish the canonical /.well-known/security.txt URL] Expires: [insert and maintain a future ISO 8601 timestamp]
Security Contact Section 30

No implied permission from security.txt

A security.txt file or contact address makes reporting easier but does not independently authorize testing. Testing authorization continues to be governed by the Vulnerability Disclosure Policy.

Security Contact Section 31

Abusive or harmful submissions

Kool&Tech may restrict communications or escalate reports involving threats, extortion, deliberate harm, unlawful access, fraudulent claims, harassment, malicious attachments, or attempts to force payment or disclosure.

Security Contact Section 32

Portal updates

Kool&Tech may update this portal, reporting channels, scope references, templates, or secure-exchange methods as services and operational capabilities evolve. Reporters should consult the current published policy before testing.

Security Contact Section 33

Security contact

Send security questions and responsible-disclosure reports to info@koolandtech.com with a clear subject. For ordinary technical support, billing, feature requests, or general inquiries, use the applicable non-security support channel.

Submit a responsible-disclosure report

Email a concise, safely redacted report describing the affected asset, observed behavior, minimal reproduction steps, potential impact, and preferred contact method.

Back to heading