VDP Section 01
Purpose and commitment
Kool&Tech LLC values good-faith reports that help identify and remediate security weaknesses in Kool&Tech-controlled, public-facing systems. This Vulnerability Disclosure Policy (“VDP”) explains how to report a potential vulnerability and the conditions that apply to authorized research.
The objective is defensive: reduce risk, protect users and Customer information, and provide a coordinated channel for resolving verified issues.
Read before testing: Only systems expressly identified as in scope are authorized for research under this policy. Customer systems, third-party platforms, internal systems, and connected services are excluded unless Kool&Tech gives separate written authorization.
VDP Section 02
Good-faith authorization
If research is conducted in good faith and in material compliance with this policy, Kool&Tech will treat the activity as authorized by Kool&Tech for the limited purpose of vulnerability discovery on in-scope systems.
Kool&Tech will not initiate or recommend legal action solely for compliant good-faith research. This statement does not bind third parties, platform providers, customers, law enforcement, or other rights holders, and does not authorize violations of their rules or rights.
If uncertainty exists about scope or a proposed test, contact Kool&Tech before testing.
VDP Section 03
Systems in scope
Public websitePublicly accessible pages and functions operated by Kool&Tech at its primary website, excluding third-party infrastructure and embedded services.
Public formsKool&Tech-controlled public contact, inquiry, assessment, or scheduling interfaces, only to the minimum extent necessary to confirm a vulnerability.
Future Kool&Tech servicesA service is in scope only when its own documentation or this policy expressly identifies it as covered.
Published codePublic repositories are covered only when expressly identified by Kool&Tech as eligible under this VDP.
Apparent ownership, branding, a shared domain, DNS record, integration, or link does not by itself place a system in scope.
VDP Section 04
Systems excluded from scope
Unless separately authorized in writing, the following are excluded:
- Customer tenants, databases, portals, websites, devices, networks, and environments.
- Odoo, Microsoft, Twilio, Stripe, PayPal, hosting providers, carriers, cloud platforms, and other third-party systems.
- Kool&Tech internal accounts, email, employee devices, administrative consoles, source repositories, development environments, VPNs, and infrastructure not publicly designated in scope.
- Systems belonging to affiliates, vendors, partners, customers, or unrelated organizations.
- Physical offices, personnel, telephone systems, and social channels.
Report a third-party vulnerability directly to the responsible vendor under the vendor's policy.
VDP Section 05
Permitted research
Permitted research is limited to non-destructive testing reasonably necessary to determine whether an in-scope vulnerability exists and to prepare a useful report.
- Use the least intrusive method available.
- Use only accounts and data you own or are authorized to use.
- Limit requests, payloads, proof-of-concept activity, and data access.
- Stop after confirming the issue.
- Preserve relevant evidence without retaining unnecessary data.
VDP Section 06
Prohibited testing
The following activities are not authorized:
- Denial-of-service, distributed denial-of-service, stress, load, volumetric, or resource-exhaustion testing.
- Social engineering, phishing, vishing, smishing, pretexting, impersonation, or targeting personnel.
- Physical testing, onsite access attempts, tailgating, device theft, surveillance, or facility testing.
- Malware, ransomware, destructive payloads, persistence, backdoors, command-and-control, cryptomining, or botnets.
- Brute force, password spraying, credential stuffing, MFA fatigue, token theft, or account takeover.
- Mass scanning, automated exploitation, high-volume requests, spam, or testing that affects availability or reputation.
- Changing, deleting, encrypting, corrupting, or creating production data beyond your own test data.
- Pivoting, lateral movement, privilege escalation beyond what is strictly necessary to demonstrate the initially discovered issue, or accessing additional systems.
- Testing third-party services without their permission.
VDP Section 07
Sensitive data and stop conditions
If testing reveals Personal Data, confidential information, credentials, tokens, payment information, health information, source code, secrets, Customer information, or data belonging to another person, immediately stop testing.
Do not copy, download, modify, retain, transmit, publicly disclose, or use the information beyond the minimum evidence necessary to report the issue. Do not access additional records to determine scale.
Notify Kool&Tech promptly and securely delete any unnecessary local copies after coordinating preservation needs.
VDP Section 08
How to report a vulnerability
Email the report to info@koolandtech.com with the subject Security Vulnerability Report.
Affected assetExact hostname, URL, endpoint, page, feature, application, or version.
Issue descriptionWhat the vulnerability is and why it matters.
ReproductionClear, minimal steps, prerequisites, and sanitized proof of concept.
Potential impactData, users, permissions, confidentiality, integrity, availability, or business function affected.
Testing detailsDate, time, source IP if appropriate, account used, tools, and request identifiers.
Suggested remediationOptional mitigation or correction ideas.
Researcher contactA safe method for follow-up and whether attribution is requested.
VDP Section 09
Secure submission
Do not send active malware, complete credential sets, full database exports, or unnecessary Personal Data by ordinary email. Redact sensitive values and provide the minimum evidence required.
If a report requires encrypted transfer or a safer channel, send an initial message without the sensitive material and request coordinated transfer instructions.
VDP Section 10
What reporters can expect
Kool&Tech may acknowledge the report, request clarification, validate scope, investigate the issue, coordinate with an affected provider or Customer, prioritize remediation, and communicate material status when practical.
Response, validation, remediation, and disclosure timing depend on severity, reproducibility, ownership, third-party involvement, complexity, business impact, and available resources. Kool&Tech does not guarantee a specific response or remediation deadline.
VDP Section 11
Duplicates and report quality
Reports may be closed or deprioritized when they are duplicates, not reproducible, informational only, outside scope, dependent on unsupported configurations, already publicly known, or lack meaningful security impact.
A high quantity of automated, low-quality, speculative, or template-generated reports may be treated as abuse and may not receive individual responses.
VDP Section 12
Generally non-qualifying findings
Unless accompanied by a demonstrated material security impact, the following generally do not qualify:
- Missing headers, cookie attributes, email records, or best-practice settings without an exploitable consequence.
- Technology identification, version banners, public files, directory names, or information intentionally published.
- Self-XSS, clickjacking on pages without sensitive actions, tabnabbing, or open redirects without meaningful impact.
- Rate-limit observations that do not enable abuse.
- Username or email enumeration without demonstrated harm.
- UI defects, accessibility issues, spelling errors, broken links, or general support requests.
- Reports based only on automated scanner output.
- Issues requiring obsolete browsers, unsupported software, or unrealistic user behavior.
VDP Section 13
Coordinated disclosure
Do not publicly disclose, publish, sell, demonstrate, or share a vulnerability or report details before Kool&Tech has had a reasonable opportunity to investigate and remediate the issue.
Coordinate any intended disclosure with Kool&Tech. Remediation may depend on a Customer, vendor, platform provider, release schedule, or migration. Kool&Tech may request additional time where disclosure could create material risk.
No public disclosure is authorized if it would expose Personal Data, credentials, confidential information, exploit code, unsafe operational detail, or another party's system.
VDP Section 14
Recognition and rewards
This VDP is not a bug bounty program. Kool&Tech does not promise payment, compensation, gifts, employment, contracts, public recognition, or reimbursement.
Any recognition is discretionary and requires the reporter's permission. Do not demand payment or threaten disclosure, disruption, or reputational harm.
VDP Section 15
Reporter privacy
Kool&Tech may process reporter contact details, report content, technical evidence, communications, and related logs for triage, investigation, remediation, coordination, fraud prevention, security, and legal compliance.
Reports and communications may be shared with affected Customers, vendors, hosting providers, insurers, advisors, or authorities when reasonably necessary, subject to applicable confidentiality and legal requirements.
VDP Section 16
Third-party and customer issues
If a reported issue affects a Customer or third-party platform, Kool&Tech may refer the report to the responsible party. This policy does not authorize testing of that party's systems and does not override the party's disclosure policy or terms.
Kool&Tech may assist with coordination when Kool&Tech configured or integrated the affected service, but responsibility for remediation depends on ownership and contract scope.
VDP Section 17
Legal boundaries
This policy provides limited authorization only from Kool&Tech for compliant testing of expressly in-scope systems. It does not waive rights unrelated to compliant research, authorize unlawful acts, or protect conduct that is negligent, reckless, extortionate, deceptive, destructive, or outside this policy.
You remain responsible for complying with applicable law and all third-party terms. If your activity creates immediate risk, Kool&Tech may block access, preserve evidence, notify affected parties, or contact authorities.
VDP Section 18
Policy updates
Kool&Tech may update scope, testing conditions, submission methods, and this VDP as services, risks, vendors, and legal requirements evolve.
The version shown on this page applies when research is conducted. Material changes do not retroactively authorize activity that was prohibited when performed.