Ir al contenido
Security Research · Coordinated Disclosure · Defensive Response

Found a security issue? Help us address it responsibly.

This Vulnerability Disclosure Policy provides a clear channel and carefully defined boundaries for good-faith security research involving eligible Kool&Tech-controlled public systems.

Effective: September 19, 2026 Kool&Tech LLC · FL Document L24000173044 Security reports: info@koolandtech.com
Defined scopeOnly expressly identified Kool&Tech-controlled systems are authorized.
Stop on sensitive dataDo not expand access, copy records, or continue testing.
Report clearlyProvide minimal reproduction steps, impact, evidence, and safe contact details.
Coordinate disclosureAllow reasonable investigation and remediation before publication.
Testing authorization is narrow: This policy does not authorize denial-of-service, social engineering, brute force, malware, persistence, data extraction, Customer testing, or testing of third-party platforms.
VDP Section 01

Purpose and commitment

Kool&Tech LLC values good-faith reports that help identify and remediate security weaknesses in Kool&Tech-controlled, public-facing systems. This Vulnerability Disclosure Policy (“VDP”) explains how to report a potential vulnerability and the conditions that apply to authorized research.

The objective is defensive: reduce risk, protect users and Customer information, and provide a coordinated channel for resolving verified issues.

Read before testing: Only systems expressly identified as in scope are authorized for research under this policy. Customer systems, third-party platforms, internal systems, and connected services are excluded unless Kool&Tech gives separate written authorization.
VDP Section 02

Good-faith authorization

If research is conducted in good faith and in material compliance with this policy, Kool&Tech will treat the activity as authorized by Kool&Tech for the limited purpose of vulnerability discovery on in-scope systems.

Kool&Tech will not initiate or recommend legal action solely for compliant good-faith research. This statement does not bind third parties, platform providers, customers, law enforcement, or other rights holders, and does not authorize violations of their rules or rights.

If uncertainty exists about scope or a proposed test, contact Kool&Tech before testing.

VDP Section 03

Systems in scope

Public websitePublicly accessible pages and functions operated by Kool&Tech at its primary website, excluding third-party infrastructure and embedded services.
Public formsKool&Tech-controlled public contact, inquiry, assessment, or scheduling interfaces, only to the minimum extent necessary to confirm a vulnerability.
Future Kool&Tech servicesA service is in scope only when its own documentation or this policy expressly identifies it as covered.
Published codePublic repositories are covered only when expressly identified by Kool&Tech as eligible under this VDP.

Apparent ownership, branding, a shared domain, DNS record, integration, or link does not by itself place a system in scope.

VDP Section 04

Systems excluded from scope

Unless separately authorized in writing, the following are excluded:

  • Customer tenants, databases, portals, websites, devices, networks, and environments.
  • Odoo, Microsoft, Twilio, Stripe, PayPal, hosting providers, carriers, cloud platforms, and other third-party systems.
  • Kool&Tech internal accounts, email, employee devices, administrative consoles, source repositories, development environments, VPNs, and infrastructure not publicly designated in scope.
  • Systems belonging to affiliates, vendors, partners, customers, or unrelated organizations.
  • Physical offices, personnel, telephone systems, and social channels.

Report a third-party vulnerability directly to the responsible vendor under the vendor's policy.

VDP Section 05

Permitted research

Permitted research is limited to non-destructive testing reasonably necessary to determine whether an in-scope vulnerability exists and to prepare a useful report.

  • Use the least intrusive method available.
  • Use only accounts and data you own or are authorized to use.
  • Limit requests, payloads, proof-of-concept activity, and data access.
  • Stop after confirming the issue.
  • Preserve relevant evidence without retaining unnecessary data.
VDP Section 06

Prohibited testing

The following activities are not authorized:

  • Denial-of-service, distributed denial-of-service, stress, load, volumetric, or resource-exhaustion testing.
  • Social engineering, phishing, vishing, smishing, pretexting, impersonation, or targeting personnel.
  • Physical testing, onsite access attempts, tailgating, device theft, surveillance, or facility testing.
  • Malware, ransomware, destructive payloads, persistence, backdoors, command-and-control, cryptomining, or botnets.
  • Brute force, password spraying, credential stuffing, MFA fatigue, token theft, or account takeover.
  • Mass scanning, automated exploitation, high-volume requests, spam, or testing that affects availability or reputation.
  • Changing, deleting, encrypting, corrupting, or creating production data beyond your own test data.
  • Pivoting, lateral movement, privilege escalation beyond what is strictly necessary to demonstrate the initially discovered issue, or accessing additional systems.
  • Testing third-party services without their permission.
VDP Section 07

Sensitive data and stop conditions

If testing reveals Personal Data, confidential information, credentials, tokens, payment information, health information, source code, secrets, Customer information, or data belonging to another person, immediately stop testing.

Do not copy, download, modify, retain, transmit, publicly disclose, or use the information beyond the minimum evidence necessary to report the issue. Do not access additional records to determine scale.

Notify Kool&Tech promptly and securely delete any unnecessary local copies after coordinating preservation needs.

VDP Section 08

How to report a vulnerability

Email the report to info@koolandtech.com with the subject Security Vulnerability Report.

Affected assetExact hostname, URL, endpoint, page, feature, application, or version.
Issue descriptionWhat the vulnerability is and why it matters.
ReproductionClear, minimal steps, prerequisites, and sanitized proof of concept.
Potential impactData, users, permissions, confidentiality, integrity, availability, or business function affected.
Testing detailsDate, time, source IP if appropriate, account used, tools, and request identifiers.
Suggested remediationOptional mitigation or correction ideas.
Researcher contactA safe method for follow-up and whether attribution is requested.
VDP Section 09

Secure submission

Do not send active malware, complete credential sets, full database exports, or unnecessary Personal Data by ordinary email. Redact sensitive values and provide the minimum evidence required.

If a report requires encrypted transfer or a safer channel, send an initial message without the sensitive material and request coordinated transfer instructions.

VDP Section 10

What reporters can expect

Kool&Tech may acknowledge the report, request clarification, validate scope, investigate the issue, coordinate with an affected provider or Customer, prioritize remediation, and communicate material status when practical.

Response, validation, remediation, and disclosure timing depend on severity, reproducibility, ownership, third-party involvement, complexity, business impact, and available resources. Kool&Tech does not guarantee a specific response or remediation deadline.

VDP Section 11

Duplicates and report quality

Reports may be closed or deprioritized when they are duplicates, not reproducible, informational only, outside scope, dependent on unsupported configurations, already publicly known, or lack meaningful security impact.

A high quantity of automated, low-quality, speculative, or template-generated reports may be treated as abuse and may not receive individual responses.

VDP Section 12

Generally non-qualifying findings

Unless accompanied by a demonstrated material security impact, the following generally do not qualify:

  • Missing headers, cookie attributes, email records, or best-practice settings without an exploitable consequence.
  • Technology identification, version banners, public files, directory names, or information intentionally published.
  • Self-XSS, clickjacking on pages without sensitive actions, tabnabbing, or open redirects without meaningful impact.
  • Rate-limit observations that do not enable abuse.
  • Username or email enumeration without demonstrated harm.
  • UI defects, accessibility issues, spelling errors, broken links, or general support requests.
  • Reports based only on automated scanner output.
  • Issues requiring obsolete browsers, unsupported software, or unrealistic user behavior.
VDP Section 13

Coordinated disclosure

Do not publicly disclose, publish, sell, demonstrate, or share a vulnerability or report details before Kool&Tech has had a reasonable opportunity to investigate and remediate the issue.

Coordinate any intended disclosure with Kool&Tech. Remediation may depend on a Customer, vendor, platform provider, release schedule, or migration. Kool&Tech may request additional time where disclosure could create material risk.

No public disclosure is authorized if it would expose Personal Data, credentials, confidential information, exploit code, unsafe operational detail, or another party's system.

VDP Section 14

Recognition and rewards

This VDP is not a bug bounty program. Kool&Tech does not promise payment, compensation, gifts, employment, contracts, public recognition, or reimbursement.

Any recognition is discretionary and requires the reporter's permission. Do not demand payment or threaten disclosure, disruption, or reputational harm.

VDP Section 15

Reporter privacy

Kool&Tech may process reporter contact details, report content, technical evidence, communications, and related logs for triage, investigation, remediation, coordination, fraud prevention, security, and legal compliance.

Reports and communications may be shared with affected Customers, vendors, hosting providers, insurers, advisors, or authorities when reasonably necessary, subject to applicable confidentiality and legal requirements.

VDP Section 16

Third-party and customer issues

If a reported issue affects a Customer or third-party platform, Kool&Tech may refer the report to the responsible party. This policy does not authorize testing of that party's systems and does not override the party's disclosure policy or terms.

Kool&Tech may assist with coordination when Kool&Tech configured or integrated the affected service, but responsibility for remediation depends on ownership and contract scope.

VDP Section 18

Policy updates

Kool&Tech may update scope, testing conditions, submission methods, and this VDP as services, risks, vendors, and legal requirements evolve.

The version shown on this page applies when research is conducted. Material changes do not retroactively authorize activity that was prohibited when performed.

Report a potential vulnerability

Email a clear, minimally invasive report with the affected asset, issue, reproduction steps, potential impact, and safe contact information. Do not send unnecessary sensitive data.

Kool&Tech LLC · Florida Limited Liability Company · United States

  Back to policy heading